Solved

VPN Client!!!

Posted on 2003-10-21
3
206 Views
Last Modified: 2013-11-16
Hi there,

I'm using a VPN Client to connect into my school's server. I can get connected without any problem. However when i check the statistics for the incoming packets decrypted it says 0. I believe something is blocking the packets. I have a pix 501 at my house. Do you think this could be the reason? Do you have any suggestions?

Thanks for your help.
0
Comment
Question by:mdiez
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 1

Accepted Solution

by:
birksy earned 125 total points
ID: 9595053
Hi,

Given that you've a 501 at home I'm assuming that as you traverse your firewalls interfaces you're going through a private/public address boundary and hence the VPN server at the other end has to support client NAT.

Cisco typically use port 10000/UDP to create the network transport when your client is on a private address, but without knowing what sort of VPN server you're connecting to (e.g. Nortel, Symantec, Cisco) or for that matter whether you're using PPtP or IPSEC (or even an SSL VPN) it's immaterial. Let us know what sort of device you're connecting to and we'll go from there.

In the meantime here's a good place to start looking in terms of passing IPSEC VPN traffic through your firewall:

http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a008009486e.shtml

R.
0
 

Author Comment

by:mdiez
ID: 9595630
Hi there,

Thanks for youe response. My school is running a VPN Cisco Server. And they are using IPSEC. Does this help, or you need more information.

Thanks for your help
0
 
LVL 1

Expert Comment

by:birksy
ID: 9603984
Since you're connecting to another Cisco box things become slightly more simple.

You need to consider opening the following on your Pix:

ESP (50/IP)
ISAKMP (500/UDP)
10000/UDP

You'll also need to configure your Cisco client to do NAT traversal using a UDP transport. The link that I posted above explains how to do the firewall side of this in some detail.

Let me know how you get on, any if you have further problems.

R.
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question