Re: Secure Remote over PPoE VPN

From: jose.ramirez@lvmh-us-ssc.com
Date: 10/26/01


Subject: Re: Secure Remote over PPoE VPN
To: "Vachon, Scott" <Scott.Vachon@Paymentech.com>, security-basics@securityfocus.com
Message-ID: <OFD9D9DEA2.EA11F7D0-ON85256AF1.00752037@us.lvmh.fr>
From: jose.ramirez@lvmh-us-ssc.com
Date: Fri, 26 Oct 2001 17:29:21 -0400


Vachon,

I have a setup almost identical with remote users using Verizon DSL with
the exceptions of static IPs on the clients.
Several things to check for;
Do you have an IP pool setup for these VPN users,
Do you have multiple segments that the VPN users are trying to access and
if they're crossing routers do these routers know how to direct traffic for
the VPN users,
Check your FW Net objects and make sure that the remote users can access
the segment/s in your LAN;
Remember, encrypt rules should be before any stealth and general deny
rules,

Look through the documentation, as far as I've experienced there is no
issue with Verizon DSL and Securemote VPN users.

Hope this helps,

Jose N Ramirez
LVMH SSC
19 E 57th St.
New York, NY 10022

                                                                                                                   
                    "Vachon, Scott"
                    <Scott.Vachon@Payme To: security-basics@securityfocus.com
                    ntech.com> cc:
                                              Subject: Secure Remote over PPoE VPN
                    10/25/2001 01:28 PM
                                                                                                                   
                                                                                                                   

I am evaluating the following VPN solution and have encountered a problem:
Once the Secure Remote client is authenticated on a Nokia Firewall-1, the
remote workstation/laptop fails to communicate with the Corporate LAN (no
internal server access, no pings of ip addresses, etc).

Configuration info of clients:
Win 2k w/ latest service pack and patches.
Laptop are Toshiba Tecra 8000
Checkpoint VPN-1 Secure Client v 4.1 SP-3 3DES build 4176 using IKE
Netgear RP-314 (NAT)
Verizon DSL with PPoE

IP statically assigned on remote users LAN. DNS specified as Verizon DNS
ip.
Nokia firewall logs show authentication (of user 's Verizon assigned DHCP
WAN IP ) and key exchange but, nothing else.

Questions:

1) Has anyone been successful with a similar setup?
2) Has anyone been successful running VPN via Verizon DSL?
3) Has anyone been successful running VPN via Verizon DSL without NATting
behind a SOHO router ?

TIA.

~S~

"We have it in our power to begin the world anew...America shall make a
stand, not for herself alone, but for the world," from Common Sense,
published January 1776 , by Thomas Paine.

"Any comments or statements made are not necessarily those of the firm, its
subsidiaries or affiliates"



Relevant Pages

  • VPN Setup
    ... We are researching seting up a VPN solution for our remote users. ... would be better, to use the existing T1, or setup a new T1 for VPN only. ...
    (Security-Basics)
  • Re: Outlook
    ... Outlook, and you'd have the centralized configuration, backup, management, ... and other benefits of Exchange. ... Then remote users would have two options, OWA, or Outlook using RPC over ... By the way, on the topic of VPN, depending on your circumstances I'd almost ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN shares..... again
    ... browser on the remote computer (no VPN required). ... This feature is available in both versions of SBS ... A VPN can be painfully slow for remote users ...
    (microsoft.public.windows.server.sbs)
  • Re: How to share a file between remote users?
    ... Real data has to be shoved from one end of the VPN ... SBS 2003 can't run TS in Application mode so you can't use SBS as a Terminal ... Server itself. ... if the remote users can schedule access times to the QB ...
    (microsoft.public.windows.server.sbs)
  • Re: Network NeighbourHood problem
    ... log in directly into the domain, without the need of VPN) An Microsoft ... remote users do not appear in network neighbourhood on the server.. ... We have yet to set the backup to occur on the remote users computers ...
    (microsoft.public.windows.server.sbs)