Solved

VPN Routing problem, new Router

Posted on 2009-04-09
7
288 Views
Last Modified: 2012-05-06
I am trying to replace our SonicWall Pro 3060 Router with an Endian Firewall as router.  Here is the layout:

192.168.10.210 - Sonicwall Router
192.168.10.220 - Endian Firewall   (2.2RC3)
192.168.10.230 - 3000 Series Concentrator
192.168.15.x - Remote software VPN clients  (connects to concentrator)
192.168.20.x - Remote Office A (connects  to concentrator)
192.168.30.x - Remote Office B (connects to concentrator)

User in 15.x / 20.x /30.x cannot access servers in 10.x if I change them to have the Endian firewall as default gateway (meaning I can't through that SonicWall in the trash where it belongs).   I have default routes setup in the Endian GUI.   Maybe they are not working?   Something else?
0
Comment
Question by:zreisman
  • 4
  • 3
7 Comments
 
LVL 28

Accepted Solution

by:
asavener earned 500 total points
ID: 24108502
You need static routes on the servers pointing to the VPN concentrator.

I've frequently seen the same problem with Cisco PIX/ASA devices; the firewall wants all traffic to be stateful.  Since it only sees 1/2 of the traffic, it blocks it because it's not part of an established session.
0
 
LVL 1

Author Comment

by:zreisman
ID: 24108572
The remote sites are connecting through PIX 515s.   I'm confused on why it only sees half the traffic?   Which firewall wants all traffic to be stateful?  If I am setting up static routes on every server (or client if they are accessing resources in the remote sites) that kind of defeats the purpose of a "router".
0
 
LVL 1

Author Comment

by:zreisman
ID: 24108593
To elaborate.   The problem is...    Any host in 192.168.10.x when setup with a default gateway of 192.168.10.220 (Endian),  cannot access resources in the remote domains, and remote domains cannot access that host.  
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 28

Assisted Solution

by:asavener
asavener earned 500 total points
ID: 24108621
The Endian Firewall is the one blocking the traffic:


Session initiated (SYN):  Remote site->VPN->VPN Concentrator->Server
Server responds (SYN/ACK):  Server->(Default route) ->Endian Firewall (Blocks traffic)

Once you add a static route:

Session initiated (SYN):  Remote site->VPN->VPN Concentrator->Server
 Server responds (SYN/ACK):  Server->(Static Route)->VPN Concentrator->VPN->Remote site
Client responds (ACK)

 
0
 
LVL 1

Author Comment

by:zreisman
ID: 24108741
Thanks.  I get it now.   IPTables just handles traffic differently than the Sonicwall.   I guess the easiest thing to do is do route add in a startup script?
0
 
LVL 28

Assisted Solution

by:asavener
asavener earned 500 total points
ID: 24108792
Depends on the OS.

With windows, you can add a persistent route by appending the "-p" switch to your "route add" statement so that the route is retained after a reboot.
0
 
LVL 1

Author Closing Comment

by:zreisman
ID: 31568589
Thanks.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Calyptix AE1200 VLAN Question 3 39
Quality settings for cisco routers 8 52
Possible RST Flood on IF X0 Sonicwall 6 131
VIRTUAL NETWORKING 3 24
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

929 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now