Re: VPN problems



If you are using the IPSec protocol, you need to know that IPSec cannot handle NAT. You are using private IP addresses which will cause problems with IPSec.

Regards

Kim Guldberg
CPSA, GCFW

Diarmaid McManus skrev:
Dear list,

I'm working for a company that recently purchased a ZyWALL 5 for a
client. There are problems setting up a VPN, however, o the internal
network.

We are attempting to set up the ZyWALL to test the VPNs
compatibility with the Windows VPN client inbuilt with XP Pro. We have
it set up as follows(apologies if there's a lack of clarity...):

--------
192.168.1.5 -> ZyWall WAN port(.1.1) -> ZyWall LAN port(.10.223) ->
network -> 192.168.10.222
--------

192.168.10.222 is the client we are attempting to connect from, to
add .1.5 to the virtual network. I have tried various configuration
settings, both on .10.222 and the ZyWALL, but to no avail. I have read
and re-read the instructions for adding a VPN and it turns out the
same no matter what values I add.

Can anyone, from the sparse information provided, tell me anything
I may be doing wrong? With regards to ports etc. Is the Windows VPN
client compatible with ZyWALL? Are there any other free clients
compatible?

Much thanks in advance,
~Diarmaid McManus




Relevant Pages

  • RE: IPSEC VPN connection from client in SBS 2003 premium
    ... the IPSec protocol cannot pass through ISA if IPSec ... pass-through would not work in firewall client method. ... VPN scenario, between the remote client and the VPN gateway, all VPN ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN problems and Linksys BEFSR411????
    ... that we successfully use Nortel client software to connect to a Nortel ... Contivity switch using IPsec VPN from behind a linksys BEFSR41. ... If you're using the VPN client that comes with Windows, ...
    (comp.security.firewalls)
  • Re: VPN problems and Linksys BEFSR411????
    ... that we successfully use Nortel client software to connect to a Nortel ... Contivity switch using IPsec VPN from behind a linksys BEFSR41. ... If you're using the VPN client that comes with Windows, ...
    (comp.security.firewalls)
  • Re: LAN_A - VPN to VPN- LAN_B using Windows 2003 and PreSHared KEY
    ... you may want to create ipsec on ... this may help even it talks about client. ... > Company B have their own network LAN_B and have devices deployed on> our Network LAN_A, in order to service these devices remotely they> want to VPN into our site using a site - to site VPN. ... > They have said that the VPN at our lan, LAN_A must be setup to use> Pre-Shared KEY and not usernames and password, so just the pre shared> key to get on the VPN. ...
    (microsoft.public.win2000.ras_routing)
  • Re: VPN problems
    ... if the device is nat-t aware nating shouldn't be any problem for ipsec vpn. ... Check with customer support if ZyWALL supports nat-t, window xp native ipsec client supports NAT-T. ...
    (Security-Basics)