Question

Set up Netgear FVS318v3 VPN Client Connection to Netgear Prosafe VPN Client

Asked by: runningmanms3

I have used every single bit of information on the web to try and make this seemingly simple connection, but between conflicting information and not actually explaining a lot of the settings, I have been unable to successfully create a VPN connection.

Some details.  My VPN router is the FVS318v3.  It's IP address is 192.168.15.1.  It automatically assigns all computers on the network an IP address.  The WAN IP of the router isn't static, as a cable modem is connected to it.  We use creativethermalsolutions.dyndns.org as our dynamic dns name.  The only ports that are currently specifically open on the router are for FTP, which is currently used to make a simple FTP server, and it works.

I have attached pictures of all pertinent menus for the VPN and IKE policies, both overview and details, and also a walkthrough of all the screens within my VPN client program.  I will be extremely diligent and quick with follow up information if necessary. Currently, I believe my largest confusion is with what IPs need to be referenced with the connection.  We also do not use any type of domain name on our network, it's just simple workgroups.  Thank you for your help.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-04-07 at 14:17:52ID24303772
Tags

Netgear

,

VPN

,

VPN Client

,

Prosafe

,

FVS318v3

,

Tunnel

Topics

Network Routers

,

Networking Hardware Firewalls

,

IPSec Security Protocol

Participating Experts
2
Points
400
Comments
11

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Netgear VPNs and DynDNS = Disconnection!
    Hey Experts, Im trying to establish a VPN connection using netgear routers and I am having one difficult time with it. Here is what I have: I have a Netgear FWG114P Router at one office with a dynamic IP address, but I have a dyndns account with a Dynamic DNS name fo...
  2. Allowing VPN Access into network with Netgear FVS318
    Hello, My goal is allow VPN access into our network with a Netgear FVS318 using the simple Windows XP Pro SP2 VPN client that comes with the O/S (I do not want to use special VPN clients for the simplicity sake. The users are employees that have DSL/cable connections from th...
  3. Netgear VPN
    I have the Netgear FWG114P router and would like to setup VPN access on this. Is their a guide that I could follow? I do not know where to start or what software I would need.
  4. Netgear Routers & IKE Keep Alive
    Okay, Two Netgear DG834G Routers running a VPN tunnel between them. Tunnel works without (many) problems but I have a question about IKE keep alive. (This post may well be better on the Netgear forums but I had no luck whatsoever on there!) The tunnel goes down without wa...
  5. Netgear VPN
    Afternoon, I wanted to know what was the best way to setup a VPN using Netgear routers. We have 3 sites that all have a netgear router in place with static IP address. We also have a factory that has a netgear router in place with a static IP address also. Next week we are ...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: dpk_walPosted on 2009-04-08 at 07:49:04ID: 24097861

On router for Local fully qualified domain name specify creativethermalsolutions.dyndns.org.

On client unser remote part identity and addresing, select domain name and specify creativethermalsolutions.dyndns.org as value; then gateway IP and specify the internal IP of Netgear router.

Under My identity; select Email address as ID type, specify employee [or user as configured on router] click Pre-shared key and specify the password as configured on router.

If you still cannot establish VPN, please post some sanitized logs from router/client which would help with troubleshooting.

Thank you.

 

by: runningmanms3Posted on 2009-04-08 at 12:59:05ID: 24101097

I have attached both the code from the log viewer on my newly failed attempt to connect, and all of the original pictures that were edited since you last helped me. If I did not include a picture, the settings present in the old pictures did not change.

I was not sure on your first comment, "On router for Local fully qualified domain name specify creativethermalsolutions.dyndns.org"  what you wanted me to do.  Would you like me to change a setting on the VPN router, because I didn't do that.

I had already entered in my pre-shared key in the correct place, so that's not the failure.

In the email space, I entered "employee" since that is the remote ID i specified on my router.  Is that still correct? There is also a local ID which is netgear.  I'm not terrible sure on what the need for those two ID is.

This wouldn't be hindered because I'm doing this already within the network I'm on, would it?  Do I have to find an outside network to test this on?

Also, on my last picture from my first post, I have seen places change the retransmit interval and enable other logs and things in that menu.  Anything in there I should be worried about?

Thanks again for all your help.

This is the code from the router.

[2009-04-08 14:43:39][==== IKE PHASE 1(from 192.168.15.100) START (responder) ====]
[2009-04-08 14:43:39]**** RECEIVED  FIRST MESSAGE OF AGGR MODE ****
[2009-04-08 14:43:39]<POLICY: > PAYLOADS: SA,PROP,TRANS,KE,NONCE,ID,VID,VID,VID,VID,VID
[2009-04-08 14:43:39]SENDING NOTIFY MSG:
[2009-04-08 14:43:39]INVALID_ID_INFORMATION
[2009-04-08 14:43:39]**** SENT OUT INFORMATIONAL EXCHANGE MESSAGE ****
[2009-04-08 14:43:39]<POLICY: > PAYLOADS: NOTIFY
[2009-04-08 14:45:25][==== IKE PHASE 1(from 192.168.15.100) START (responder) ====]
[2009-04-08 14:45:25]**** RECEIVED  FIRST MESSAGE OF AGGR MODE ****
[2009-04-08 14:45:25]<POLICY: > PAYLOADS: SA,PROP,TRANS,KE,NONCE,ID,VID,VID,VID,VID,VID
[2009-04-08 14:45:25]SENDING NOTIFY MSG:
[2009-04-08 14:45:25]INVALID_ID_INFORMATION
[2009-04-08 14:45:25]**** SENT OUT INFORMATIONAL EXCHANGE MESSAGE ****
[2009-04-08 14:45:25]<POLICY: > PAYLOADS: NOTIFY

This is the code from the client side.

 4-08: 14:43:22.578 Filter table loaded.
4-08: 14:43:36.625
 4-08: 14:43:36.718 My Connections\Employee - Initiating IKE Phase 1 (IP ADDR=192.168.15.1)
4-08: 14:43:36.953 My Connections\Employee - SENDING>>>> ISAKMP OAK AG (SA, KE, NON, ID, VID 5x)
4-08: 14:43:36.968 My Connections\Employee - RECEIVED<<< ISAKMP OAK INFO (NOTIFY:INVALID_ID_INFO)
4-08: 14:43:36.968 My Connections\Employee - Discarding SA negotiation
4-08: 14:44:25.296 Filter table loaded.
4-08: 14:44:25.296 My Connections\Employee - Filter record 1 updated.
4-08: 14:44:37.359 Filter table loaded.
4-08: 14:44:37.359 My Connections\Employee - Filter record 1 updated.
4-08: 14:44:48.593 Filter table loaded.
4-08: 14:45:18.765 Filter table loaded.
4-08: 14:45:18.765 My Connections\Employee - Filter record 1 updated.
4-08: 14:45:23.640
 4-08: 14:45:23.640 My Connections\Employee - Initiating IKE Phase 1 (IP ADDR=192.168.15.1)
4-08: 14:45:23.734 My Connections\Employee - SENDING>>>> ISAKMP OAK AG (SA, KE, NON, ID, VID 5x)
4-08: 14:45:23.750 My Connections\Employee - RECEIVED<<< ISAKMP OAK INFO (NOTIFY:INVALID_ID_INFO)
4-08: 14:45:23.750 My Connections\Employee - Discarding SA negotiation

 

by: dpk_walPosted on 2009-04-09 at 02:24:28ID: 24105471

Phase I is not going through; by router settings I meant:
Under ike-policy-detail.jpg, under Local you have mentioned netgear; instead mention the dynDNS name.

Yes, for testing VPN client must be coming in from a different internet connection, not from behind the router.

This should take care of things.

Thank you.

 

by: runningmanms3Posted on 2009-04-09 at 14:04:58ID: 24111628

I tried today to connect to my network from an outside connection, and it did not work.  I am wondering now if my router is the offending agent in all this.  I downloaded a trial version of TheGreenBow since the Netgear client I have been referencing doesn't work with Vista.  From my outside connection, I was able to connect to thegreenbow test vpn flawlessly, but now when I am inside my network, I don't even think VPN pass through is set up.  I tried to open the correct ports, but then the router tells me that IKE policies are using those ports and if I change them, I will effect my ability to use VPN tunneling.  I'm about ready to give up on this problem and accept it can't be done.

 

by: mycroftxPosted on 2009-04-09 at 19:24:33ID: 24113108

not to discount anything posted erlier, there is great advice in there, but...

I install a lot of Netgear routers, and I have to say the Netgear branded VPN client is crap.  Use the Shrew client @ http://www.shrew.net/download and follow the steps at http://www.shrew.net/support/wiki/HowtoNetgear.  This tutorial is for the FVX538 or FVS338 but it should be pretty easy to match up with the 318.

 

by: runningmanms3Posted on 2009-04-09 at 19:32:46ID: 24113129

I will definitely take a look at that Shrew client.  I have been looking for a good, free VPN client and this just may fit the bill.  Any ideas on why the router is not seemingly responding to outside clients?  Also, should I start a new thread about the inability to do a VPN passthrough on my current router?

 

by: mycroftxPosted on 2009-04-09 at 19:44:07ID: 24113160

I would guess the lack of router response is because of the Firewall setup and that you are using Dynamic DNS.  Ma sure that TCP & UDP 500 are open and pointed to your gateway (192.168.15.1) and log into DynDNS.org and check what the host table shows your IP to be, then go to ipchicken.com and verify its the same.  If not, there's you problem.  If so, could be a thousand different things, but I'd start with with services and rules.  

If you want, set the router password and your DynDNS account info to something other than what you use now, save the config and email it to me, then set the password back.  I have a 318 sitting around that I can throw the config on and do some testing.  Might take me a couple of days to get to it (depending on what tomorow is like) but if you dont get it runnign soon I'd be glad to.

 

by: runningmanms3Posted on 2009-04-10 at 14:06:07ID: 24119158

I checked my DynDNS login and IP's and that all checks out.  I have been able to use that for an FTP server on my network, which you'll be able to see in my attached Router Rule screenshot.  The problem is I am unable to open those two TCP and UDP ports on 500 because it says it interferes with an IKE policy in place.  Should I still force that to open and "break" the supposed IKE policy that is already running?  I'm going to attempt to use the Shrew Client now, and maybe that will fix this.  Any insight on my rules configuration would be amazing though.  Thanks again for all the help.

 

by: mycroftxPosted on 2009-04-10 at 15:14:59ID: 24119810

hmmm. on a 338 or a 538 I would begin by opening TCP & UDP 500 and then create the VPN Tunnells.  But a 318 is using different software, so I cannot say for sure.  I would delete the IKE & VPN Policies, creat the rule, then recreate the VPN & IKE Policies.  

Also you may want to diable the default 'Block Always' rule and see if the VPN works.  That will at least isolate if its a firewall or other issue.

I would advise you to continue with the Shrew VPN Client, it is way better and at the very least it's just as secure.  

Uou can email me the config and I will roll it out in the lab and get it operational, then send it back to you.  Just make sure you NEVER send anyone you passwords or static ip's as they can be used to break into your network.

...I feel a bit obligated to say this as well.  Netgear makes some great products, but I wouldnt use the 318 for anything more than a few PC's on a small network and I would never use it as the VPN endpoint.  It's kinda slow, not very many patches and the backplane is tine.  An FVS338 is faily inexpensive and does a great job.  Not that Im saying throw the 318 away, just next time go for the 338 or 538 if you want dual wan ports with roll-ver or protocol binding.  If you want any advice on future purchases, let me know and I will outline what I use regulary for my customers.

http://www.netgear.com/Products/VPNandSSL/WiredVPNFirewallRouters/FVS338.aspx

http://www.amazon.com/Netgear-FVS338-ProSafe-VPN-Firewall/dp/B0006OCZGW

 

by: runningmanms3Posted on 2009-04-12 at 12:43:24ID: 24126689

Thank you for all of your insight.  Everyone helped a lot in diagnosing the problems we have.  In the end, I believe it comes down to the router itself and it's inability to do what it advertises.  I have played with enough things like this in my day, and after all of this, it just comes down to a poorly implemented hardware router.  Thank you for both configuration help and, in the end, the knowledge that can only come with experience, and that is that some things just aren't designed well and will never do what you want.  I have decided to purchase an FVS338 and I will reference this along with the many other tutorials that exist for this router as opposed to the 318.  Thanks again. This was extremely helpful.

 

by: runningmanms3Posted on 2009-04-12 at 12:45:12ID: 31567775

I just want to say thanks for the help.  I left a comment with the final resolution, and it really came down a lot to understanding this router just will not function the way I want it.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...