[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Connect to Linksys BEFVP41 from work...

Posted on 2004-09-27
3
Medium Priority
?
760 Views
Last Modified: 2008-01-09
I have recently purchased a vpn router so I can access my files at home from abroad. I an having a problem connecting to my router from work. I followed the instructions on the linksys website (configuring IPSec policies on XP and 2000 machinces), but had to make revisions due to the fact that my ip address at work is DHCP assigned and our internet access comes from a NAT pool. Of course it did not work :-
(...  I think the lack of a static ip address is the problem.

I want to configure my router (which has a static ip) to accept connections from anywhere that has been configured with the PreShared Key (Which I'm pretty sure I have already configured correctly)

And I want to be able to configure a workstation (of which the ip address is unknown and my be behind a NAT firewall) to connect to my vpn router (with the correct PreShared Key).

So my question(s)

Is it possible to create a tunnel where one end has a dynamic ip address (without the use of dyndns due to nat pool usage)?
Is there a way to configure said tunnel without the use of VPN Client Software (which would be prefferable)?
Does the NAT-Traversal feature listed on various VPN clients refer to the programs ability connect to a VPN server from behind a NAT firewall?
Can the Cisco VPN Client software be configured to us a IKE PreShared Key instead of the username and password that can't be configured on BEFVP41 (unlike the Linksys Wireless-G VPN endpoint :-< )
0
Comment
Question by:MamboDee
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 5

Accepted Solution

by:
netspec01 earned 2000 total points
ID: 12200202
> Is it possible to create a tunnel where one end has a dynamic ip address (without the use of dyndns due to nat pool usage)?

Yes.  The "host" end has to be static.  The IPSEC must be in "aggressive mode".

> Is there a way to configure said tunnel without the use of VPN Client Software (which would be prefferable)?

Yes.  Many hardware devices are capable of doing aggressive mode.  Cisco introduced aggressive mode ISKMP with IOS version  12.2(8)T.  Many SOHO devices that are VPN-capable support aggressive mode for establishment of IPSEC tunnels.

> Does the NAT-Traversal feature listed on various VPN clients refer to the programs ability connect to a VPN server from behind a NAT firewall?

Yes, NAT traversal was developed to overcome NAT firewall issues.  If you have multiple VPN clients behind a NAT/PAT firewall connecting to a remote VPN device, NAT traversal must be implemented.

Hope this helps get you started.

> Can the Cisco VPN Client software be configured to us a IKE PreShared Key instead of the username and password that can't be configured on BEFVP41 (unlike the Linksys Wireless-G VPN endpoint :-< )

I have never heard of anyone successfully using the Cisco VPN client with any non-Cisco product.
0

Featured Post

Are You Ready for GDPR?

With the GDPR deadline set for May 25, 2018, many organizations are ill-prepared due to uncertainty about the criteria for compliance. According to a recent WatchGuard survey, a staggering 37% of respondents don't even know if their organization needs to comply with GDPR. Do you?

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes, you want your microsoft VPN to route all the traffic to the remote network. Usually your employer network. This makes it possible to access all the nodes inside this remote LAN, even if they have no "public DNS" entries. To do so, you wo…
For a while, I have wanted to connect my HTC Incredible to my corporate network to take advantage of the phone's powerful capabilities. I searched online and came up with varied answers from "it won't work" to super complicated statements that I did…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question