Technical Discussion
  >> Home Networking, Internet Connection Sharing, etc.


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
Pages in this thread: 1 | 2 | (show all)   Print Thread
Standard User deleted
(deleted) Sat 12-May-07 16:29:56
Print Post

Setting up VPN


[link to this post]
 
Hi,

I'm trying to set up a VPN to my companies e-mail system but struggling with it. The instructions I have say that my router should support ISAKMP - its a d-link G604T. D-link support advise that just opening port 500 will do the trick which I've done - however I'm still not able to connect.

My router docs do not mention the ISAKMP protocol so I'm wondering if d-link are correct in saying just open port 500. Anyone know about the ISAKMP protocol and is it critical for what I'm trying to do please?

Any advice appreciated

Thanks
Dave
Standard User JonRennie
(knowledge is power) Sat 12-May-07 17:20:15
Print Post

Re: Setting up VPN


[re: deleted] [link to this post]
 
ISAKMP uses UDP port 500 - could you have set TCP 500?

Depending on the VPN client you may also need to open up the firewall for ESP traffic.

Comms is hard
Standard User deleted
(deleted) Sat 12-May-07 17:52:18
Print Post

Re: Setting up VPN


[re: JonRennie] [link to this post]
 
Hi,

In my router, there is an option to enable IPSEC - the detail for this shows that it opens port 500 for UDP and also enables ESP. However, I still can't connect with this option selected.

Is ISAKMP part of "IPSEC" or is this an "add-on" protocol that maybe my router doesn't support please?

Thanks again,
Dave


Register (or login) on our website and you will not see this ad.

Standard User JonRennie
(knowledge is power) Sat 12-May-07 18:44:36
Print Post

Re: Setting up VPN


[re: deleted] [link to this post]
 

ISAKMP and IPSec are different protocols - however they work together in that ISAKMP is used for the key exchange, then IPSec is used to encrypt the traffic flow.

If your IPSec option opens UDP 500 then you should have enough open for an IPSec session to be established.

What VPN solution are you using and are you trying to do a router-router connection or are you trying to use a software VPN client through the router?

Comms is hard
Standard User deleted
(deleted) Sat 12-May-07 19:07:41
Print Post

Re: Setting up VPN


[re: JonRennie] [link to this post]
 
Hi,

I'm worried that although I have an IPSEC session open, the possible lack of ISAKMP does not allow the key exchange.

There is a vpn prog on the lap-top that tries to connect with the company server (I assume). The lap-top client is "Contivity VPN V06_01.102" - Nortel Networks (but seems to be badged as an Orange product - IPSec VPN Client)

Thanks
Dave
Standard User JonRennie
(knowledge is power) Sat 12-May-07 19:33:35
Print Post

Re: Setting up VPN


[re: deleted] [link to this post]
 

IPSec won't come up until the ISAKMP key exchange is complete - therefore if your IPSec session is up you don't have a problem with ISAKMP.

A quick Google shows that UDP 500 is all that is required.

What error messages do you see?

Comms is hard
Standard User deleted
(deleted) Sat 12-May-07 20:00:20
Print Post

Re: Setting up VPN


[re: JonRennie] [link to this post]
 
Hmmm, maybe I'm being a bit optimisitic that the IPSEC session is actually established - to be honest I'm not sure now.

The VPN client tries to connect three or four times and then fails - the only error that pops up is something like "connection failed, check the switch logs" - I don't see anything useful in the router logs.

During the connection its as though the VPN client "sees" the other server (it reports as trying to connect to blah.bigcompany.com then fails. Before I enabled the IPSEC option in the router it just said failed to resolve ip address or something like that - as though there was no connection through the router. Now it appears I'm getting past the router but not authenticating at the other end.

I can't find anything on the web that specifically states my router supports ISAKMP but I'm not sure if this is an issue or not.

I'll have a chat with the IT bods on Monday unless you can think of anything else to try.

One last thing, is there an easy way to see if I have actually opened port 500 correctly?

Thanks again,
Dave
Standard User deleted
(deleted) Sat 12-May-07 22:03:42
Print Post

Re: Setting up VPN


[re: deleted] [link to this post]
 
The client you have on your laptop is the Nortel Contivity IPSec client. It is similar to the Cisco IPSec VPN client.

You shouldn't need to open any ports on your router BUT if you have a personal firewall running on the laptop, this needs to be configured to allow the connection. I use the Cisco VPN client and I didn't change my router or it's firewall at all, it "just worked". However I did need to configure my personal firewall to allow the VPN client to communicate.
In reply to:

The VPN client tries to connect three or four times and then fails - the only error that pops up is something like "connection failed, check the switch logs" - I don't see anything useful in the router logs.


The "switch" mentioned here is the Contivity VPN device, not your router - so you'll need to speak to your company's network admin to see what the exact cause of the failure was.

It's a while since I've looked at how the Contivity boxes and clients are setup, but if I think of anything before Monday I'll post suggestions here.
Standard User deleted
(deleted) Sun 13-May-07 11:03:47
Print Post

Re: Setting up VPN


[re: deleted] [link to this post]
 
Thanks guys - I'll check out the local firewall situation.

I'm running NAT on the router - will that make any difference? Also that question about checking for open ports - is it the NETSTAT command or maybe try grc.com?

Dave
Standard User deleted
(deleted) Sun 13-May-07 20:10:17
Print Post

Re: Setting up VPN


[re: deleted] [link to this post]
 
NAT shouldn't make any difference, I use the same on my VPN setup.
Pages in this thread: 1 | 2 | (show all)   Print Thread

Jump to