[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details

SecuRemote, tightVNC, Juniper Networks SSG5 connection slow and works intermittenly

Asked by dirque in Miscellaneous Networking, Virtual Private Networking (VPN), Network Routers

Tags: SecuRemote, tightVNC, Juniper Networks SSG5, VNC, network

The problem is I can not get a consistent connection through TightVNC while the computer is inside our firewall. If it is outside the firewall we get a connection unless there is a problem with the computer on the clients end.

I have a network behind a Juniper Networks SSG5-serial-WLAN router/firewall/switch. It consists of WindowXP Pro boxes and a couple of linux servers. One of our clients has a Windows XP Pro computer behind a firewall with TighVNC Server running on it. I have a high speed (22M/5M) connection to the internet and I do not have a problem with any of my other VPN (out) connections (cisco/citrix/juniper). I believe they are using a cisco gateway/firewall.

The client has set up SecuRemote. We make that connection and then use tightVNC to get through to the computer. If I put our computer outside our firewall (directly on the Comcast router) the connection is made all the time. If I put inside our firewall (SSG5) the connection works 25% of the time. For example, yesterday, 11-5, it was inside our firewall and functioning fine all day. This afternoon (the first time they tried it since yesterday) it would not connect until I moved the computer outside the firewall. I have two computers set up to make this connection and the behavior is the same so It is not dependent on the computer. The securemote is on for only one computer at a time.

The client has been no help as, according to them, it works all the time for all their employees doing the same thing from home.

The SecuRemote (Checkpoint) is always on when the computer is on. Our staff will start TightVNC and click on connect. This causes SecuRemote to pop up asking for authentication. This happens 90% of the time whether it is inside the firewall and not. Then either the tightVNC fails or it connects. If it fails, sometimes it will work if they launch TightVNC again after authentication. If it fails the second time it fails until I move the computer outside the firewall.

I've checked the logs on the SSG5 and there is nothing in them about this or the VNC routing or ports or anything abnormal.

I have rebooted everything on my side approximately a zillion times since we got this client. I have tried RealVNC and it didn't make a difference.

The other issue is that the screen updates are crazy slow inside or out side our firewall. Again the client claims it's not for their employees. You can see the screen update in sections.

If it didn't work at all when inside the firewall that would make it easier. It's this working sometimes without any clue why it works or doesn't. I've turned on the TightVNC logging to the highest level and updated to the latest version and there is never a log generated. Just an empty file.

Ports 5800/5900 are forwarded, obviously since VNC works some of the time.

I do not want this computer to be outside our firewall. It makes everything harder (the staff can't easily access files on the common server). I would have to move other clients off of it and put a firewall on it. This just adds to my maintenance nightmares.

I need some clues on what to do to get it to work inside the firewall. Any ideas?
[+][-]11/07/09 10:53 AM, ID: 25767541Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]11/09/09 04:05 PM, ID: 25781361Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]11/09/09 04:25 PM, ID: 25781462Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]11/09/09 04:28 PM, ID: 25781473Administrative Comment

Experts Exchange has a courteous staff of administrators who help members get the most out of the website by means of administrative comments like this one.

Start your 30-day free trial to view this Administrative Comment or ask the Experts your question.

 
[+][-]11/09/09 04:31 PM, ID: 25781487Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]11/10/09 06:24 PM, ID: 25791880Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]11/11/09 05:05 AM, ID: 25794653Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]11/12/09 11:46 AM, ID: 25808115Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091118-EE-VQP-93 - Hierarchy / EE_QW_3_20080625