Solved

Escapsulation and Encryption on the Cisco VPN Concentrator 3060

Posted on 2011-09-13
2
432 Views
Last Modified: 2012-05-12
My remote customers connect to the Cisco VPN Concentrator to access hosted applications. I  have one customer who is giving me a lot of trouble.   He says that his firewall and VPN Client (not sure what brand he's using at the moment) at his location will have problems connecting to a Cisco VPN because of encapsulation.  He wants to know if we use full encapsulation or partial encapsulation.  I know the VPN Concentrator uses IPSEC, which encapsulates a packet by wrapping another packet around it and then encrypts the entire packet.  So it my eyes that would be full encapsulation.  Would you agree?   I'm not sure what type of firewall or VPN client they are using, I just left them a message to find out.  They swear its a problem with Cisco devices:)  What do you think?
0
Comment
Question by:denver218
2 Comments
 
LVL 4

Accepted Solution

by:
artsec earned 500 total points
ID: 36532756
Hello, you are right about encapsulation.

Please check the following ports on your client firewall:

PPTP Control Connection, Protocol Number       6 (TCP), Source Port 1023, Destination Port:1723
PPTP Tunnel Encapsulation: Protocol Number 47 (GRE) Source Port: N/A, Destination Port:N/A
ISAKMP/IPSec Key Management: Protocol Number 17 (UDP) Source Port: 500, Destination Port:500
IPSec Tunnel Encapsulation: Protocol Number 50 (ESP) Source Port: N/A, Destination Port: N/A
IPSec NAT Transparency: Protocol Number 17 (UDP) Source Port: 10000 (default) Destination Port:10000 (default)

It might be a conflict in IP address. The client's remote network is using the same IP address range as the VPN server's local network.

Please check your Cisco VPN Concentrator logs as well. The logs would help us to identify authentication problems.
0
 
LVL 4

Author Closing Comment

by:denver218
ID: 36537883
Thanks.  This client made some changes on their network and can now connect to the VPN.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Explore the encryption capabilities built into Google Apps and how these features can help you meet privacy policy and regulatory compliance, but are not a full solution. Understand and compare the most popular email encryption services for Google A…
As a financial services provider, your business is impacted by two of the strictest federal regulations on record: the Sarbanes-Oxley Act and the Gramm-Leach-Bliley Act. Correctly implementing faxing into your organization to provide secure, real-ti…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

825 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question