SonicWALL SOHO3 and GVC (Global VPN Client) connections from hotels!

Posted on 2005-04-19
Last Modified: 2012-08-13
We are using a SonicWALL SOHO3 with I believe 16 GVC's.  The issue we have is intermittent when connecting from a GVC (Global VPN Client).  For example:  EarthlinkDSL connects without any problems, but some hotels will not allow the GVC to connect to the SOHO3 device.

I am being told that the hotels need to have the UDP port 500 and IPSEC 50 service enabled on the upstream devices in order for the VPN connection to get established.  Is there anything that I can change on the SonicWALL SOHO3 device so we do not have to ask hotels to open ports?
Question by:JWFreedom

    Expert Comment

    IPsec-based VPN's need UDP port 500 opened for ISAKMP key negotiations, IP protocol 51 for Authentication Header traffic (not always used), and IP protocol 50 for the "encapsulated data itself. The only "forwardable" item here is UDP port 500.  If the hotels ACLs do not allow outbound UDP port 500 (usually configured by opening a service called IPSEC on the firewall) then you will not be able to connect your client VPN to your SonicWall.  You cannot change the ports the IPSEC VPN uses.

    Summary:  You are being told correctly.
    LVL 18

    Accepted Solution

    Note...we have no trouble connecting our gvn's with all of the major hotel chains.  It would be very odd to find a hotel offering internet connections these days that do not allow vpn traffic.

    It is more likely that what you have is a DNS problem.  When you connect at a hotel, either cat5 or wireless, your lan or wireless adapter will pick up an ip address, gateway and dns setings from the hotel lan......that's as it should be for internet connectivity......and I think that probably none of your users have any trouble connecting to the Internet.  The VPN problem arises because the Sonicwall VPN adapter (which you will find, along with your lan and wireless connections, in "MY Network Places" properties) also needs an ip address, a gateway and dns info...from your lan........and , if you have it set to dynamic rather than static, it is probably picking up the hotel lan information rather than your lan info.....we had this problem at Hiltons until I figured it out......while connected at one of the problem hotels, have your user do an "ipconfig /all" and comjpare the infor between the lan connection and the Sonicwall virtual adapter.  

    To solve the problem, you can either configure the virtual adapter  manually, just as you would  for any other static connection....or you can leave it as dynamic and set your Sonicwall to hand out DHCP info to VPN clients.  Here is the link to SonicWalls paper on configuring DHCP over VPN:


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Do You Know the 4 Main Threat Actor Types?

    Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

    Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
    To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
    how to add IIS SMTP to handle application/Scanner relays into office 365.
    In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

    779 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    14 Experts available now in Live!

    Get 1:1 Help Now