Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Using the Cisco Client behind a Sonicwall firewall for Administration

Status
Not open for further replies.

andeeeeuk

Technical User
Oct 20, 2003
3
GB
I am wanting to use my cisco client 3.5 to access an authentication server on our customers network for administration duties.
I am using client 3.5 going through a Sonicwall Pro 300 firewall set for NAT and connecting to a 3005 concentrator which then authenticates the user via a a Radius Server.
I am able to authenticate from the client but am unable to use terminal services,vnc,telnet or even ping the destination server.
Where as when I use a dial-up connection via 3rd Party ISP I can authenticate and access the Radius server via terminal services etc etc.
I looked at the Sonicwall firewall to see if ipsec passthrough was available but unable to find it.
I find it strange that I can authenticate (establishing the tunnel) on my internal lan, but no do anything else.
I am assuming it has something to do with the sonicwall.
here is the path i am trying to achieve.

Cisco client-sonicwall-3005 concentrator-cygberguard firewall-authentication server.

---------------------------------------

I have enabled NAT-T - that is the UDP protocol on port 4500 on my sonicwall firewall and am still unable to use the VPN.Do I need to enable the Cyberguard Firewall for NAT-Traversal - UDP 4500.(that is in between the 3005 concentrator and the authentication server I am trying to connect to via terminal services)
It seems strange that I can authenticate initially.
Any thoughts or ideas would be grateful been looking at this for a while now without any progress.

Thanks

Andy


 
Have you enabled NAT-T on the VPN 3K? Some PAT devices are not able to handle IPSec through PAT, the issue is with ip protocol 50 (ESP) and PAT. NAT-T should overcome this issue but you should enable NAT-T on the concentrator. The tunnel is negotiated on UDP 500 but when you send traffic it is encrypted and sent on an ESP packet, which has issues with some PAT devices hence the ability to start the tunnel but no traffic passes through the tunnel. Of course it could be due to something else. I think you need 3.6 on both VPN concentrator and VPN client but I am not 100% sure.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top