I had to turn protocol analysis off to use the Cisco VPN (version 4.8) when I used a certificate rather than a password for authentication. The size of the certificate would generate packet fragments, but CPF also claimed the UDP packets were malformed.
Bob