RE: [fw-wiz] Clients cant access pix w/ vpn from behind nat devices using the newest cisco client.

From: Wes Noonan (mailinglists_at_wjnconsulting.com)
Date: 10/22/03

  • Next message: Wes Noonan: "RE: [fw-wiz] Cisco PIX DHCP relay via IPSEC"
    To: "'Vincent Martin'" <VMartin@4service.net>, <firewall-wizards@honor.icsalabs.com>
    Date: Wed, 22 Oct 2003 11:05:33 -0500
    
    

    NAT Traversal is pretty much required. In addition, the NAT device needs to
    support NAT traversal. Had an issue yesterday with someone using a Sonicwall
    firewall and they couldn't get the Cisco VPN to work through it because the
    Sonicwall was killing the traffic (never saw it hitting the PIX). Never
    found a resolution as we went with a different solution to address the
    connectivity needs.

    HTH

    Wes

    > -----Original Message-----
    > From: firewall-wizards-admin@honor.icsalabs.com [mailto:firewall-wizards-
    > admin@honor.icsalabs.com] On Behalf Of Vincent Martin
    > Sent: Wednesday, October 22, 2003 08:01
    > To: 'firewall-wizards@honor.icsalabs.com'
    > Subject: [fw-wiz] Clients cant access pix w/ vpn from behind nat devices
    > using the newest cisco client.
    >
    > I am having some problems connecting to a pix firewall vpn connection
    > using
    > the cisco client when the clients are behind a nat device to the internet.
    > Is there a way to let them connect without giving them a routable ip
    > address
    > or modifying there routers at all? Have any of you ever had to get past
    > this problem? Is it possible to get past this problem? I am new to pix
    > but
    > I have done some research. It seems that we need version 6.3 of the OS
    > and
    > that possibly doing nat traversal would help. All this is configured
    > though. Any help would be great. Thanks a lot.
    > _______________________________________________
    > firewall-wizards mailing list
    > firewall-wizards@honor.icsalabs.com
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Wes Noonan: "RE: [fw-wiz] Cisco PIX DHCP relay via IPSEC"

    Relevant Pages

    • Re: SonicWall firewall question
      ... >> 6300 concurrent connections is a significant chunk of traffic.. ... >> especially for someone considering hosting "a few internet servers... ... you miss my original point in that a firewall is not the only ... >I was talking about the original SonicWall Pro now called the SonicWall Pro ...
      (comp.security.firewalls)
    • Re: VNC thru VPN from Sonicwall to Netopia
      ... > client, if you believe the points below. ... >>> At my office I have a sonicwall soho firewall connected to the ... At home I have a Netopia R9100 firewall connected ... >>> From home I can use VNC to remotely control office computers. ...
      (comp.security.firewalls)
    • Re: Unable to reach POP server
      ... I am not familiar with SonicWall so you will have to check it's ... internal IP of your e-mail server. ... to your company) and redirect any TCP port 25 request to internal SMTP ... > to the firewall device itself, ...
      (microsoft.public.windows.server.networking)
    • Re: Firewall recommendation
      ... consumer-grade routers could be an alternative possibility (in his opinion). ... I am aware that you did not suggest the SonicWALL. ... You said, "That's what I mean about getting a firewall, not some ...
      (microsoft.public.windows.server.sbs)
    • Re: Comparison of Linksys BEFSR41 to Sonicwall
      ... My Sonicwall would always test out ... The Linksys shows one port closed and reports that we ... >> good is the firewall in the Linksys ... > any more of a firewall than other NAT devices. ...
      (comp.security.firewalls)