Cisco VPN client through watchgaurd firewall

Posted on 2006-04-11
Last Modified: 2013-11-16
   I have a user that wants to access my network through a watchgaurd firewall xcore 700. I created a ipsec policy and the VPN client connects and will authenticate successfully. The computer with the VPN client even retains a IP address from my network but he can't remote desktop into his pc nor my network. He also is not able to connect or ping any computer, gateway or domain controller on my network. He still retains a ip though from my network.

     The Cisco VPN client works on any other outside network not protected by a watchgaurd firewall. They are able to communicate with any host on my network.

What can I do to get this person to use remote desktop in my network.
Question by:Fubyou
    LVL 32

    Expert Comment

    To use a Cisco VPN Client to connect to a non-Cisco device would be a violation of their agreement.


    Author Comment

    im not connecting to the watchgaurd. I am on the inside connecting THROUGH the watch gaurd not TO the watch gaurd.

    important word is THROUGH

    Your in violation of not being able to read.
    LVL 18

    Accepted Solution

    you kill me

    on the watchgaurd perhaps there is another user using a software VPN client to communcate somewhere else.  sometimes the NAT on a firewall router can only process the first connection that is really a tunnel, and later attempts fail.  

    the configs of the watchguard need to be looked at (which I suppose would be difficult?) to see if there is an obvious switch like linksys or netgear has 'allow ipsec on WAN' or somesuch passthrough terminology

    Author Comment

    In addition I kind of wonder if the cisco vpn client uses certain ports to initially authenticate but then to maintain the connection uses another set of (non-administrative ports) that maybe blocked. Ive ony recently learned this from a cisco pix course I took last week.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Maximize Your Threat Intelligence Reporting

    Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

    Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
    If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
    Need more eyes on your posted question? Go ahead and follow the quick steps in this video to learn how to Request Attention to your question. *Log into your Experts Exchange account *Find the question you want to Request Attention for *Go to the e…
    Hi everyone! This is Experts Exchange customer support.  This quick video will show you how to change your primary email address.  If you have any questions, then please Write a Comment below!

    759 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    11 Experts available now in Live!

    Get 1:1 Help Now