VPN issues when client AND server are behind NAT/Firewall

From: Swaroop Kumar (swaroop1967_at_yahoo.com)
Date: 05/20/04


Date: 20 May 2004 13:19:29 -0700

Hello:

    I work for a consulting company and we are currently executing a
project for a customer who is located across the country. In order to
avoid frequent travel for integration, testing & deployment of the
various software modules we are developing, we decided to request the
client for VPN access to their network. All our desktops are behind a
firewall/NAT router and we are assigned DHCP addresses. In addition,
the VPN server in the client's site is behind a similar firewall/NAT
setup. Because of all the IP masquerading taking place, we are unable
to establish a successful VPN connection unless one of the two
machines is in a DMZ (outside the firewall, openly accessible on the
internet). The VPN setup at the client is by NetScreen and the
operating environment on both sides is primarily Microsoft-based.

    Can somebody please advise us of solutions from their past
experiences or at least suggest possible workarounds/debugging methods
to resolve this issue?

Thanks a lot in advance,
Swaroop



Relevant Pages

  • ipsec/l2tp missing something key, error 678 on external inteface
    ... I've configured my vpn for remote access, no firewall/nat on an external ... static ip but nat on the internal interface, ... It definetly sounds like a network ...
    (microsoft.public.isa.vpn)
  • Re: VPN issues when client AND server are behind NAT/Firewall
    ... > client for VPN access to their network. ... > firewall/NAT router and we are assigned DHCP addresses. ... a connection to that unit from the internet - dmz would work, ...
    (comp.security.firewalls)
  • [NEWS] Cisco VPN 5000 Client Multiple Vulnerabilities
    ... Multiple vulnerabilities exist in the Cisco Virtual Private Network (VPN) ... 5000 Client software. ... These vulnerabilities are documented as Cisco bug ID ... CSCdx17109 - MAC OS VPN 5000 Client password vulnerability ...
    (Securiteam)
  • Re: VPN clients unable to connect to other resources.
    ... gateway matches the IP of the remote client, and DNS and WINS point to the ... remote (although it takes close to a minute to connect, ... This is just regular Windows VPN, ... VPN server, remote routing and access running on the SBS 2003 server ...
    (microsoft.public.windows.server.sbs)
  • RE: Slow VPN logon and Spuratic folder visibility
    ... I understand that the remote VPN client ... network configuration. ... the VPN client can access SBS fine? ... Slow VPN logon and Spuratic folder visibility ...
    (microsoft.public.windows.server.sbs)