Re: [fw-wiz] Cisco VPN client behind a Netscreen

From: Luigi Mori (lm_at_symbolic.it)
Date: 11/06/03

  • Next message: List Account: "RE: [fw-wiz] Cisco VPN client behind a Netscreen"
    To: <firewall-wizards@honor.icsalabs.com>
    Date: Thu, 6 Nov 2003 10:10:46 +0100
    
    

    >I have recently implemented a Netscreen 50 and I have users behind
    >it that use a Cisco VPN client to connect to a Cisco Pix which I
    >have no control over. Their VPN client is not functioning properly.
    >Currently I have a policy allowing outbound traffic any from all
    >inside. Does anyone know if I also need to create an IPSEC policy
    >for inbound traffic? Thanks, Aram Smith

    Is the NetScreen doing some network address translation on your traffic ?
    You need a NAT-T enabled IPSec to establish a tunnel trough a NAT device.

    -- 
    Luigi Mori
    Network Security Manager
    SYMBOLIC S.p.A.
    W: http://www.symbolic.it
    T: +39 0521 776180
    F: +39 0521 776190
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: List Account: "RE: [fw-wiz] Cisco VPN client behind a Netscreen"

    Relevant Pages

    • Re: Cico 800 (836) VPN to Internet NAT
      ... I have this cisco 836 providing NAT for all the internal networks. ... Router and VPN Client for Public Internet on a Stick Configuration ... I also wanted to avoid using the Cisco VPN client. ... It can also be used to open a session (to be exhaustive, there might be means to open a session with pptp as well, therefore you could think of launching an open session batch under 2K or XP) ...
      (comp.dcom.sys.cisco)
    • VPN Client not connecting....
      ... Laptop:WIN XP sp 2 Cisco VPN client V3.5 ... I've snipped the log of information that isn't needed, it shows that the connection was made, but an error prevented the VPN from staying up. ... The Client was unable to enable the Virtual Adapter because it could not set the IP configuration into the registry. ...
      (comp.dcom.sys.cisco)
    • Re: Cisco VPN - Keeping it IPSEC only or using PPTP
      ... > We have millions of users using Microsoft VPN client out there. ... > VPN server and password would be security boundary there. ... > disadvantage when compared to the specific Cisco VPN client, ...
      (microsoft.public.security)
    • Re: Cisco VPN Client (WAS: Re: [opensuse] Re: Checkinstall dropped from Opensuse )
      ... reasons I use suse -- almost everything imaginable is available ... I'd like to use the Cisco vpn client to work from home ... VPN client is tied into the kernel version. ...
      (SuSE)