Cisco MCU 5320 and Polycom vsx

Hello!

I have the problem with these devices. Content does not work properly. MCU push content to the same protocol with video endpoint vsx h.261. If the quality of the content are very poor. Is - this intraoperative problem or a software problem?  any other point endpoint it works very well.

Hello

You have basic Mode activate on your Polycom endpoint?

Try to do either disable or enable basic Mode in your devices of Polycom, just to see if you get different behavior. You can find the slot configuration system > admin settings > network > call preferably.

In addition, the date of issue for MCU version 4.4 indicates some interoperability issues with Polycom HDX endpoints when using content with H261 Protocol, do not know if this limitation also applies to the VSX series.

In addition, I suggest you check the documentation for Polycom to check if the VSX endpoints are able to share content using protocols H263 or H264 instead of H261, also check if there is some version or configuration required to enable it.

Concerning

Paulo Souza

My answer was helpful? Please note the useful answers and do not forget to mark questions resolved as "responded."

Tags: Cisco Support

Similar Questions

  • TMS and Polycom VSX

    Hello

    One of our customers uses some VSXes Polycom and Cisco VC systems. They have created a directory on Cisco TMS. This directory includes also a few records. C20s, they can see the files on the phone book. But on the Polycom VSXes, they can not see the records. They see all the addresses in the same directory in order from A to Z. Don't you know that it is possible to separate with VSX records or not? If so, how?

    Best regards

    Chambers oumar

    Hello

    Polycom units does not support this unless they were included in a new software at least they did not support this before. Only a directory flat as we see. Use cisco endpoints

    Sent by Cisco Support technique iPhone App

  • Cisco MCU 5320 customize background image

    Dear all,

    I need change the image (attached) by default that appear by joining any MCU and must insert my company Logo/image...

    How can I do...?

    Kindly help.

    Maybe not what you want, but the only thing you can change is the MCU auto attendant banner, he would replace the white Cisco logo appearing in the upper left corner.  You don't mention what model MCU, you have, but as all microcontrollers Cisco use the same software, I will use the series 5300 MCU for example.  See the section 'Adding a banner of auto attendant custom' help MCU 5300 Series Guide on pg 100.

  • Cisco Telepresence 5320 MCU

    Hello..

    We have integrated Cisco MCU 5320 CUCM Version 10.x and we are able to make calls to endpoints registered CUCM (SX20) to MCU with the ID of the meeting in addition to this, we use also VCS-control and have endpoints registered Polycom on to him but we are not able to make calls to MCUS using endpoints of Polycom recorded on VCS - C.

    Please suggest a guide too which can support on the rules of numbering as well.

    Rgds,

    Vika

    I am not able to give a precise any comparison between the differences of a MCU which is on CUCM or VCS, as I do not have a background in call manager.

    What is the problem you are having with TMS scheduling?  Can you elaborate and explain that you have problems with, I can try to help.

  • Configuration of the firewall Cisco Telepresence MCU 5320

    Hi all.

    I searched all the documents of the MCU again, but I found nothing on the ports it uses.

    Help me

    HI Sandra.  The 5320 MCU is the same as 4500 MCU.

    Incoming ports
    • FTP - TCP:21 + transient (dynamic rather than fixed) used TCP ports for passive mode
    • HTTP - TCP:80
    • HTTPS - TCP:443
    • H.323 - TCP:1720 + ephemeral TCP ports for incoming calls
    • SNMP - UDP:161
    • Outgoing calls to H.323 involve ephemeral ports TCP connections TCP TCP:1720 and a certain number of ephemeral TCP ports
    • Outgoing SIP TCP calls involve connections between the TCP ephemeral ports and TCP:5060
    • Outgoing SIP TCP calls involve connections between the TCP ephemeral ports and TCP:5061
    • Outgoing interruptions SNMP are sent the ephemeral ports UDP Port 162
    • Media (including audio and video, FECC messages) are ephemeral ports from ephemeral ports UDP.
    • The products acquired Cisco TANDBERG/Codian and gateway series series Cisco TelePresence allocate the ephemeral ports between 49152 to 65535 *. It is possible to change the ports on which these products receive and establish connections. For example, by default the Codian products Cisco acquired listen port 1720 H.323 calls and connections to port 80 web browser, but these can be modified (go to network > Services).

    Keep in mind this MCU does not support the streaming or conference me and have either the GK aboard.  If these ports are listed.

    The link to the Article can be found here:

    http://www.Cisco.com/en/us/docs/Telepresence/infrastructure/articles/conferencing_products_conferenceme_ports_used_kb_3.shtml

    VR

    Patrick

  • External Audio calls to Cisco MCU

    I have a requirement for an external audio channel to access the shared meeting room that is hosted on the MCU 5320 Cisco.

    This can be achieved directly through the MCU or is it a requirment for another audio bridge

    Well, you can integrated MCU with VCS using SIP Trunk, even if the common deployment is to have registered in VCS, MCU or by using SIP, H323, or both. You can also integrate the MCU with CUCM, but in this case, MCU will be a multimedia resource of CUCM, thats why it is only recommended to the ad hoc conferences. You can also integrate the MCU with the driver of telepresence using the API, but it is often only when you have several MCU pools to manage.

    To integrate the Cisco MCU with VCS, you can consult this document:

    http://www.Cisco.com/en/us/docs/Telepresence/infrastructure/MCU/Install_Guide/Cisco_TelePresence_MCU_Deployment_guide_1-31.PDF

    To learn more about how to work with auxiliary self on Cisco MCU, take a look at this guide:

    Page 88 - http://www.cisco.com/en/US/docs/telepresence/infrastructure/mcu/admin_guide/Cisco_Telepresence_MCU_5300_Series_4-4_Product_administration_guide.pdf

    If you want to integrate MCU with control systems third call, I can't say that it will work, because I still have my suggestions on basis Cisco official documentation, and there is little in the literature on integration of MCU with control systems third call.

    If you think that your question has been resolved, please mark the right answer.  =)

    Concerning

    Paulo Souza

    Please note the answers and mark it as "answered" as appropriate.

  • MCU4500 series and Polycom HDX broadband bandwidth interop

    Hello!

    A customer brought it to my attention and I was not able to determine a good reason for it yet.  First of all, here are the settings;

    -MCU4515 4.4 (3.49) running

    -Polycom HDX (a 7000 and a 8000) running 3.03

    -MCU and endpoints registered to a Porter, no bandwidth restrictions (they say)

    -calls to 1.2 M

    -MCU call termination points, H323

    When connecting endpoints HDX, the incoming bandwidth for the MCU is half of the outgoing bandwidth to the HDX.  I can't find any setting in the MCU which has an effect any on this.  By default the settings of bandwidth on the MCU (inbound and outbound) are set more than the real call rate.

    I tried to test with a 4.4 (3.49) running of the MCU4510 and two Cisco endpoints (EX90 C90), endpoint and saved for a VCS and the MCU points not saved.  The incoming and outgoing call, rate stays.

    Y at - it no unpublished data of interop MCU which has a reference to this issue?  The customer said that wasn't a problem when the MCU was at 4.2 (1.50).

    Thank you!

    Thanks Bob.  The reason why this is happening now is that MCU had some previous issues by honoring the bitrates etc..  This problem has been fixed in MCU 4.4 under CSCuh81255.

    When HDX calls, it always opens LC for ExtendedVideoCapability at the beginning of every call.  This leaves MCU to split the BW cut in two for hand and when the system wants to send the contents of the content.  Given that the already contained open HDX channel to MCU, MCU must reserve the quantity of bioweapons for content when the HDX decides to send and do not exceed 1.25 meg in your case.

    I hope that makes sense to you...

    Let me know if it doesn't.

    VR

    P2

  • What is the difference bewteen MCU, VCS, and SRI (DSP-3)

    Hi all

    We lack CUCM 9.X. I want to integrate Cisco 9971, 8945 with TP Endpoint (EX60 and Tandberg C40). I read this wonderful document (https://supportforums.cisco.com/docs/DOC-30750), but I still have some doubts.

    What is the difference bewteen MCU, VCS, and SRI (DSP-3). For all I know, ISR running DSP3 is the chepaiest option but I don't know if the HD video is supported.

    Thanks regarding

    Remember messages useful rate by clicking on the stars below.
    Favor calificar todos las responses useful dando click in las estrellas mas abajo.
    ___________________________________________
    LinkedIn profile: do.linkedin.com/in/leosalcie

    Hello

    According to the document, you are referring to which I posted previously

    VCS is a call control system call manager but for video end points only, then CUCM is for voice and video, and now it becomes control system of very mature appeal for video communications with native support for video of many recordings of points

    MCU is a material that can be used to host the multi point/party video calls that can be registered to CUCM or VCS according to design

    SRI with DSP/PVDM 3 is the concept of the MCU, but can be used for small multi-point calls and normally remote sites that need local accommodation to a call to reduce the load on the WAN link when most of the participant in the same place for example! and it dose taken support HD but limited features compared to MCU

    for example PVDM3 doe does not support HD when participants are expected to use different video formats

    hope this helps

  • No free sessions in cisco MCU errors

    just by connecting to the web interface of the joint cisco MCU, am getting error no. FREE SESSIONS, screenshot, please help

    Hi Eric,.

    Allow me to pass this message to the community of telepresence, so that you get the attention of the TP experts. This community is for Cisco WebEx and Cisco Unified MeetingPlace meeting server products and is not normally observed by TP experts.

    I hope that you will get the answers you need faster.

    Kind regards

    -Dejan

  • Cisco Catalyst 6509 and 6513 goes into config race disk0: / Backup Script

    We use a Cisco Catalyst 6509 and 6513 switches in our network LAN and Man.

    Please help me and share the script to take backup of all respective running to their disk0 configuration switches: / per week.

    Double post.

  • Cisco Catalyst 6509 and 6513 running config backup to their respective disk0: / Script

    We use a Cisco Catalyst 6509 and 6513 switches in our network LAN and Man.

    Please help me and share the script to take backup of all respective running to their disk0 configuration switches: / per week.

    Kind regards

    Vinay

    Double post.

  • difference between cisco NAC agent and cisco Clean Access Agent

    Hi all

    If anyone has the idea on different between cisco NAC agent and cisco Clean Access Agent, please let us know your ideas.

    Thank you

    In 4.6, the agent has been revised and is now called the NAC agent.  Previous versions were called the clean access Agent.  So roughly, 4.5 and 4.1.3.2 agent are own access agents, and agents 4.6.x and 4.7.x are called NAC agents.

    Some of the changes are moving a lot of the agent configuration in an XML file, redesign of the GUI, adding a service portion (of the sort that the agent of heel is no longer necessary) and the best journaling agent.

  • Cisco VPN Client and Windows XP VPN Client IPSec to ASA

    I configured ASA for IPSec VPN via Cisco VPN Client and XP VPN client communications. I can connect successfully with Cisco VPN Client, but I get an error when connecting with the XP client. Debugging said "misconfigured groups and transport/tunneling mode" I know, they use different methods of transport and tunneling, and I think that I have configured both. Take a look at the config.

    PS a funny thing - when I connect with client VPN in Windows Server 2003, I have no error. The only difference is that client XP is behind an ADSL router and client server is directly connected to the Internet on one of its public IP of interfaces. NAT in the case of XP can cause problems?

    Config is:

    !

    interface GigabitEthernet0/2.30

    Description remote access

    VLAN 30

    nameif remote access

    security-level 0

    IP 85.*. *. 1 255.255.255.0

    !

    access-list 110 scope ip allow a whole

    NAT list extended access permit tcp any host 10.254.17.10 eq ssh

    NAT list extended access permit tcp any host 10.254.17.26 eq ssh

    access-list extended ip allowed any one sheep

    access list nat-ganja extended permit tcp any host 10.254.17.18 eq ssh

    sheep-vpn access-list extended permits all ip 192.168.121.0 255.255.255.0

    tunnel of splitting allowed access list standard 192.168.121.0 255.255.255.0

    flow-export destination inside-Bct 192.168.1.27 9996

    IP local pool raccess 192.168.121.60 - 192.168.121.120 mask 255.255.255.0

    ARP timeout 14400

    global (outside-Baku) 1 interface

    global (outside-Ganja) interface 2

    NAT (inside-Bct) 0 access-list sheep-vpn

    NAT (inside-Bct) 1 access list nat

    NAT (inside-Bct) 2-nat-ganja access list

    Access-group rdp on interface outside-Ganja

    !

    Access remote 0.0.0.0 0.0.0.0 85.*. *. 1 2

    Route outside Baku 10.254.17.24 255.255.255.248 10.254.17.10 1

    Route outside Baku 192.1.1.0 255.255.255.0 10.254.17.10 1

    Outside-Baku route 192.168.39.0 255.255.255.0 10.254.17.10 1

    Route outside-Ganja 192.168.45.0 255.255.255.0 10.254.17.18 1

    Route outside-Ganja 192.168.69.0 255.255.255.0 10.254.17.18 1

    Route outside-Ganja 192.168.184.0 255.255.255.0 10.254.17.18 1

    Route outside Baku 192.168.208.16 255.255.255.240 10.254.17.10 1

    Route outside-Ganja 192.168.208.112 255.255.255.240 10.254.17.18 1

    dynamic-access-policy-registration DfltAccessPolicy

    Crypto ipsec transform-set esp-3des esp-md5-hmac RIGHT

    Crypto ipsec transform-set newset aes - esp esp-md5-hmac

    Crypto ipsec transform-set esp-3des esp-md5-hmac vpnclienttrans

    Crypto ipsec transform-set vpnclienttrans transport mode

    Crypto ipsec transform-set esp-3des esp-md5-hmac raccess

    life crypto ipsec security association seconds 214748364

    Crypto ipsec kilobytes of life security-association 214748364

    raccess 1 set transform-set vpnclienttrans crypto dyn1 dynamic-map

    vpnclientmap 30 card crypto ipsec-isakmp dynamic dyn1

    card crypto interface for remote access vpnclientmap

    crypto isakmp identity address

    ISAKMP crypto enable vpntest

    ISAKMP crypto enable outside-Baku

    ISAKMP crypto enable outside-Ganja

    crypto ISAKMP enable remote access

    ISAKMP crypto enable Interior-Bct

    crypto ISAKMP policy 30

    preshared authentication

    3des encryption

    md5 hash

    Group 2

    life 86400

    No encryption isakmp nat-traversal

    No vpn-addr-assign aaa

    Telnet timeout 5

    SSH 192.168.1.0 255.255.255.192 outside Baku

    SSH 10.254.17.26 255.255.255.255 outside Baku

    SSH 10.254.17.18 255.255.255.255 outside Baku

    SSH 10.254.17.10 255.255.255.255 outside Baku

    SSH 10.254.17.26 255.255.255.255 outside-Ganja

    SSH 10.254.17.18 255.255.255.255 outside-Ganja

    SSH 10.254.17.10 255.255.255.255 outside-Ganja

    SSH 192.168.1.0 255.255.255.192 Interior-Bct

    internal vpn group policy

    attributes of vpn group policy

    value of DNS-server 192.168.1.3

    Protocol-tunnel-VPN IPSec l2tp ipsec

    Split-tunnel-policy tunnelspecified

    Split-tunnel-network-list value split tunnel

    BCT.AZ value by default-field

    attributes global-tunnel-group DefaultRAGroup

    raccess address pool

    Group-RADIUS authentication server

    Group Policy - by default-vpn

    IPSec-attributes tunnel-group DefaultRAGroup

    pre-shared-key *.

    Hello

    For the Cisco VPN client, you would need a tunnel-group name configured on the ASA with a pre-shared key.

    Please see configuration below:

    http://www.Cisco.com/en/us/products/ps6120/products_configuration_example09186a00805734ae.shtml

    or

    http://tinyurl.com/5t67hd

    Please see the section of tunnel-group config of the SAA.

    There is a tunnel-group called "rtptacvpn" and a pre-shared key associated with it. This group name is used by the VPN Client Group name.

    So, you would need a specific tunnel-group name configured with a pre-shared key and use it on the Cisco VPN Client.

    Secondly, because you are behind a router ADSL, I'm sure that's configured for NAT. can you please activate NAT - T on your ASA.

    "crypto isakmp nat-traversal.

    Thirdly, change the transformation of the value

    raccess 1 set transform-set vpnclienttrans crypto dyn1 dynamic-map

    Let me know the result.

    Thank you

    Gilbert

  • Cisco Telepresence SX20 and Touch 8 Configuration after paired

    Hello

    I successfully connected and combined the SX20 Cisco's Telepresence and Cisco Telepresence Touch 8. Before using the 8 key, we used the remote control instead. As a result, I have two questions about this.

    1. as far as I know, when I use the 8 key, the remote control cannot be used. Is it possible to use both of them?

    2. How can I change the background of my SX20 touch 8? Previously, the remote I can easily choose the background for my SX20. But after pairing with Touch 8, background in my SX20 become a blue large clock. I really want to have a different background but cannot find the way how to change.

    Any help would be appreciated.

    Thank you.

    Sincerely,

    Bagus Hanindhito

    After you connect the 8 Touch, you can still use the remote control, you will need to put on the SX20:

    SystemUnit MenuType experimental configuration: full

    I think that the standard background when using a touchscreen device is what you see, blue with large clock.  However, after the MenuType return in full which will give you the full OSD which is used with the remote and not that of the button, you may be able to change the background then.

  • Site to Site VPN between Cisco ASA 5505 and Sonicwall TZ170

    I'm trying to implement a VPN site-to site between our data center and office.  The data center has a Cisco ASA 5505 and the Office has a Sonicwall TZ170.  I managed to configure the two so that the vpn connects.  Each of the firewall I ping the IP Address of the internet firewall on the other side and a desktop computer I can ping the IP Address of the firewall internal datacenter but I can't carry traffic between private subnets datacenter and desktop.  Can anyone help?

    The config below has had IPs/passwords has changed.

    External Datacenter: 1.1.1.4

    External office: 1.1.1.1

    Internal data center: 10.5.0.1/24

    Internal office: 10.10.0.1/24

    : Saved
    :
    ASA Version 8.2 (1)
    !
    hostname datacenterfirewall
    mydomain.tld domain name
    activate the password encrypted
    passwd encrypted
    names of
    name 10.10.0.0 OfficeNetwork
    10.5.0.0 DatacenterNetwork name
    !
    interface Vlan1
    nameif inside
    security-level 100
    10.5.0.1 IP address 255.255.255.0
    !
    interface Vlan2
    nameif outside
    security-level 0
    1.1.1.4 IP address 255.255.255.0
    !
    interface Ethernet0/0
    switchport access vlan 2
    !
    interface Ethernet0/1
    !
    interface Ethernet0/2
    !
    interface Ethernet0/3
    !
    interface Ethernet0/4
    !
    interface Ethernet0/5
    !
    interface Ethernet0/6
    !
    interface Ethernet0/7
    !
    passive FTP mode
    clock timezone IS - 5
    clock to summer time EDT recurring
    DNS server-group DefaultDNS
    buydomains.com domain name
    permit same-security-traffic inter-interface
    permit same-security-traffic intra-interface
    inside_access_in list extended access permit icmp any one
    inside_access_in list extended access permitted tcp a whole
    inside_access_in list extended access udp allowed a whole
    inside_access_in of access allowed any ip an extended list
    outside_access_in list extended access permit icmp any one
    outside_access_in list extended access udp allowed any any eq isakmp
    IP DatacenterNetwork 255.255.255.0 OfficeNetwork 255.255.255.0 allow Access-list extended pixtosw
    pixtosw list extended access allow icmp DatacenterNetwork 255.255.255.0 OfficeNetwork 255.255.255.0
    IP OfficeNetwork 255.255.255.0 DatacenterNetwork 255.255.255.0 allow Access-list extended pixtosw
    pixtosw list extended access allow icmp OfficeNetwork 255.255.255.0 DatacenterNetwork 255.255.255.0
    outside_cryptomap_66.1 list of allowed ip extended access all OfficeNetwork 255.255.255.0
    outside_cryptomap_66.1 ip OfficeNetwork 255.255.255.0 allowed extended access list all
    outside_cryptomap_66.1 list extended access permit icmp any OfficeNetwork 255.255.255.0
    outside_cryptomap_66.1 list extended access allowed icmp OfficeNetwork 255.255.255.0 everything
    pager lines 24
    Enable logging
    asdm of logging of information
    Within 1500 MTU
    Outside 1500 MTU
    IP verify reverse path to the outside interface
    ICMP unreachable rate-limit 1 burst-size 1
    ASDM image disk0: / asdm - 623.bin
    don't allow no asdm history
    ARP timeout 14400
    NAT-control
    Global 1 interface (outside)
    NAT (inside) 1 0.0.0.0 0.0.0.0
    inside_access_in access to the interface inside group
    Access-group outside_access_in in interface outside
    Route inside 0.0.0.0 0.0.0.0 1.1.1.1 1
    Route OfficeNetwork 255.255.255.0 outside 1.1.1.1 1
    Timeout xlate 03:00
    Timeout conn 01:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
    Sunrpc timeout 0:10:00 h323 0:05:00 h225 mgcp from 01:00 0:05:00 mgcp-pat 0:05:00
    Sip timeout 0:30:00 sip_media 0:02:00 prompt Protocol sip-0: 03:00 sip - disconnect 0:02:00
    Timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
    timeout tcp-proxy-reassembly 0:01:00
    dynamic-access-policy-registration DfltAccessPolicy
    Enable http server
    http 10.5.0.0 255.255.255.0 inside
    No snmp server location
    No snmp Server contact
    Server enable SNMP traps snmp authentication linkup, linkdown cold start
    Crypto ipsec transform-set esp-SHA-ESP-3DES-3des esp-sha-hmac
    Crypto ipsec transform-set ESP-AES-256-SHA 256 - aes - esp esp-sha-hmac
    Crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac
    Crypto ipsec transform-set ESP-DES-SHA esp - esp-sha-hmac

    Crypto ipsec transform-set ESP-DES-MD5 esp - esp-md5-hmac
    Crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac
    Crypto ipsec transform-set ESP-3DES-MD5-esp-3des esp-md5-hmac
    Crypto ipsec transform-set ESP-AES-128-SHA aes - esp esp-sha-hmac
    Crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac
    Crypto ipsec transform-set ESP-AES-128-MD5-esp - aes esp-md5-hmac
    Crypto ipsec transform-set esp-aes-256 walthamoffice, esp-sha-hmac
    life crypto ipsec security association seconds 28800
    Crypto ipsec kilobytes of life - safety 4608000 association
    Crypto dynamic-map ciscopix 1 corresponds to the address outside_cryptomap_66.1
    Crypto dynamic-map ciscopix 1 transform-set walthamoffice
    Crypto dynamic-map ciscopix 1 the value reverse-road
    map dynmaptosw 66-isakmp ipsec crypto dynamic ciscopix
    dynmaptosw interface card crypto outside
    crypto isakmp identity address
    crypto ISAKMP allow outside
    crypto ISAKMP policy 10
    preshared authentication
    3des encryption
    sha hash
    Group 2
    life 86400
    crypto ISAKMP policy 13
    preshared authentication
    aes-256 encryption
    sha hash
    Group 2
    lifetime 28800
    crypto ISAKMP policy 30
    preshared authentication
    aes-256 encryption
    sha hash
    Group 2
    life 86400
    No encryption isakmp nat-traversal
    Telnet 10.5.0.0 255.255.255.0 inside
    Telnet timeout 5
    SSH 10.5.0.0 255.255.255.0 inside
    SSH timeout 5
    Console timeout 0
    management-access inside
    dhcpd address 10.5.0.2 - 10.5.0.254 inside
    dhcpd allow inside
    !

    a basic threat threat detection
    Statistics-list of access threat detection
    no statistical threat detection tcp-interception
    NTP server 66.250.45.2 source outdoors
    NTP server 72.18.205.157 source outdoors
    NTP server 208.53.158.34 source outdoors
    WebVPN
    attributes of Group Policy DfltGrpPolicy
    VPN-idle-timeout no
    username admin password encrypted
    tunnel-group 1.1.1.1 type ipsec-l2l
    tunnel-group 1.1.1.1 ipsec-attributes
    pre-shared-key *.
    !
    !
    !
    type of policy-card inspect dns preset_dns_map
    parameters
    message-length maximum 512
    !
    context of prompt hostname
    Cryptochecksum:7f319172e5de9c0e550804a263f8e49e
    : end

    Mattew, obvious lack of education is the rule exempt from nat for your tunnel, your access list pixtosw is similar on this example, I assume that you have gone through this link, if it does not see the configs on both sides.

    Add the statement of rule sheep in asa and try again.

    NAT (inside) 0-list of access pixtosw

    http://www.Cisco.com/en/us/products/HW/vpndevc/ps2030/products_configuration_example09186a008052c9d4.shtml

    Concerning

Maybe you are looking for