Solved

Unable to connect to VPN via G3

Posted on 2006-06-27
7
410 Views
Last Modified: 2012-05-05
I am trying to connect to our corporate VPN using Cisco VPN Dialer on a laptop with a Vodafone Mobile Connect G3 Card.  The connection works fine when using a normal broadband connection, however when using the G3 connection I can’t connect    

The connection history reads as follows

“initializing connection
Contacting the gateway at (ip address)    (this lasts for about a minute)
Remote Peer is no longer responding”

Does anyone know if we need to have a GPRS Inspection License on the Pix for this to work? or does anyone have any other ideas that the problem might be?

Many thanks for any assistance
0
Comment
Question by:Birdsemple
7 Comments
 
LVL 4

Expert Comment

by:johanvz1
Comment Utility
Hi,

Dont know about your country. But in my country I have to phone my cellular service provider tell them that I want vpn to be opened on that 3g card and you will have to give them your number and details. By default they have VPN blocked on the network side. Contact them and let me know.

Kind Regads,

Johan Van Zyl
0
 
LVL 10

Expert Comment

by:snerkel
Comment Utility
Check the IP address being assigned to the 3G card when connected to the Internet, you may find it starts 10.x.x.x if it does then check the network you are trying to VPN to, if it too starts 10.x.x.x then that may well be the problem.

Only answer if they do match is to change one of the subnets, esentially this would mean changing the network you are VPNing too.
0
 

Author Comment

by:Birdsemple
Comment Utility
I will check with Vodafone, however their G3 card does say it supports VPN so I assume this should be opened by default.  

The network I am trying to connect to starts 62.x.x.x I will check to see what IP address the card has but don't think that is the problem.  Checking the logs on the Pix it doesn't even look as though the card is trying to connect, although the internet works fine.  
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:Birdsemple
Comment Utility
Thanks for your suggestions.  As it turns out our Pix Software will need to be updated before we can use the 3G Card to connect to it.
0
 

Author Comment

by:Birdsemple
Comment Utility
Just in case anyone else has the same problem I thought it might be helpful to post this advice from Cisco/Vodafone


Cisco PIX VPN Configuration Guide

Cisco advises the following PIX configuration for use with data cards.
A couple of points to note:
> Upgrade Client – Client version should be 4.01 (or above)
> Upgrade PIX – PIX version should be 6.3 (or above)
> Use MyLAN APN – Internet APN has some difficulty with the PIX.
Procedure:
STOP All VPN’s going to the server, then add the following settings in order. Finally, restart everything back
up.
NOTE: Downside is the VPN server note being able to allow clients during procedure.
On the PIX config. set the following:
> NO VPDN ENABLE INSIDE
> NO CRYPTO MAP (CRYPTO MAP NAME) INTERFACE OUTSIDE ********
(Do this if you have crypto maps enabled – these commands will disable VPN connections).
> ISAKMP NAT-TRAVERSAL
> CRYPTO MAP (CRYPTO MAP NAME) INTERFACE OUTSIDE ********
(Do this if you have crypto maps enabled)
> ISAKMP ENABLE OUTSIDE
On the client:
> UPGRADE TO 4.01

Anyone trying to use a G3 Datacard will also need to have a Firewall and client that supports UDP/TCP encapsulation as well as Nat-Traversal. The firewall will also need ports 500 and protocol 50 & 51 open.
0
 
LVL 1

Accepted Solution

by:
GhostMod earned 0 total points
Comment Utility
Closed, 500 points refunded.

GhostMod
Community Support Moderator
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now