[fw-wiz] Problem with Cisco VPN client behind a NATed Netscreen

From: Richard (dervari_at_yahoo.com)
Date: 05/25/04

  • Next message: Martin Mačok: "Re: [fw-wiz] PIX dropping packets with source port 80"
    To: <firewall-wizards@honor.icsalabs.com>
    Date: Tue, 25 May 2004 13:07:41 -0400
    
    

    I'm having a problem connecting to my corporate VPN using the Cisco
    client when I'm at home behind a Netscreen 5XP (4.0.0r1.0) on a NATed
    PPPoE connection. The Netscreen session log shows an outgoing
    connection to port 500 on the remote server and an incoming session to
    port 500 on my public IP. However, it seems that the incoming traffic
    is not making to my PC. I tried setting up a VIP and policy to route
    all port 500 traffic to one PC on my home LAN and I could then get
    connected, but was unable to ping anything on the corporate LAN. This
    setup worked fine with a Netgear FVS-318, so I know it's not my PC or
    ISP.

    I've seen conflicting articles concerning IPSec passthru on the NS. I
    read somewhere that 4.0 does it, and another place that it was a new
    feature in 5.0.

    Any assistance is appreciated.

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Martin Mačok: "Re: [fw-wiz] PIX dropping packets with source port 80"

    Relevant Pages

    • Re: how can I remove the Internet Gateway connection ?
      ... I tried to add port ... >> This machine connects thru a router to the internet. ... >> inside my home LAN. ... >> I noticed that in the Netwrok Connection folder that my ...
      (microsoft.public.windowsxp.network_web)
    • Re: Correction
      ... Normally to physically disconnect is just a matter of reaching for the ... >> I have an ADSL connection which polls my computer from time to time, ... > disallow each and every port with Windows Firewall? ...
      (microsoft.public.windowsxp.messenger)
    • Re: Using Remote Desktop From an SBS Domain
      ... when you tried to RDP while attached directly to a port on your router? ... Internet to initiate an IP conversation with your computer. ... This situation is different than if you ran your own NAT connection sharing ...
      (microsoft.public.windows.server.sbs)
    • Re: Still cant connect to RWW or OWA remotely
      ... it certainly appears to be something about the SBS configuration. ... Meridian.local Ethernet adapter Local Area Connection: ... Windows SMALL BUSINESS SERVER 2003 Windows IP Configuration ... 192.168.254.254) directly to a port on the router and then ...
      (microsoft.public.windows.server.sbs)
    • Re: Still cant connect to RWW or OWA remotely
      ... it certainly appears to be something about the SBS configuration. ... Meridian.local Ethernet adapter Local Area Connection: ... Windows SMALL BUSINESS SERVER 2003 Windows IP Configuration ... 192.168.254.254) directly to a port on the router and then ...
      (microsoft.public.windows.server.sbs)