Everyday I learn something and one such thing is this; Think of a scenario where you have to build site-to-site VPN between 2 PIXs. Adding interest to this is, the outside interfaces of both the pixes are connected to each other directly like this;

Internal—–PIX1–Outside———-Outside–PIX2—–Internal

With all configuration options as mentioned at cisco site (Click here to Cisco config sample for this), the tunnel still doesn’t come up!!! A point where I started scratching my head :-) Then one of my friend at Experts-Exchange came along and said like ‘even though the outside interfaces are connected directly, still you need to have a default route (or route) configured on the PIX to have this get it working’. It was great and was right above all.

Check out the link to see the whole discussion at the forum;

http://www.experts-exchange.com/Security/Q_21934020.html