Discuss EVDO PC Cards, ExpressCards, EVDO USB, PDAs, Phones, Coverage and Mobile Broadband Cards. Discuss Verizon and Sprint Coverage. CradlePoint CTR500, MBR1000, PHS300 & Kyocera KR2 & LinkSys WRT54G3G-ST / WRT54G3GV2 Forums!
EVDOforums.com
Discussion forum for EVDO users
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Our sites Include: EVDO Info :: EVDO Forums :: EVDO Maps :: EVDO Blog :: 3Gstore.com

To purchase your EVDO Card / Antenna / Amplifier / Router from the EVDO Experts, just contact us!

KR1 and KPC650 - The Nortel VPN Client software - ISSUE

Goto page 1, 2  Next  
Post new topic   Reply to topic    EVDOforums.com Forum Index -> Kyocera KR1 / KR2 Router Support Forum
View previous topic :: View next topic  
Author Message
mgodsoe
EVDO Newbie


Joined: 12 Oct 2005
Posts: 9
Location: seattle, WA

PostPosted: Fri Feb 17, 2006 5:33 pm    Post subject: KR1 and KPC650 - The Nortel VPN Client software - ISSUE Reply with quote

I have my Router configured, my PC is optimized per this forums recommendations, and my speed times are pretty good (considering no Venturi).

My problem is that I cannot get my VPN Client to connect through the KR1. If I put the KPC650 in my laptop, the VPN works just fine.

I do have the router set to support VPN passthrough. I have added UDP Port 500 to and from in the routers enable protocol list configuration. Still not working.

Any ideas?
Back to top
View user's profile Send private message
Mackieman
EVDO Junkie


Joined: 31 Oct 2005
Posts: 491

PostPosted: Fri Feb 17, 2006 7:38 pm    Post subject: Reply with quote

It really depends on how your Nortel VPN server is configured and how well it plays with NAT and what type of authentication it uses. Some security protocol send replys on different ports than they recieved requests on. These replies bounce off the firewall.

Depending on your configuration, you may be able to set a VirtualServer rule to allow port 9550 for TCP and UDP. This may allow data to pass through correctly.

Edit: D-Link posted an FAQ on this issue: http://support.dlink.com/faq/view.asp?prod_id=2245&question=KR-1
Back to top
View user's profile Send private message
mgodsoe
EVDO Newbie


Joined: 12 Oct 2005
Posts: 9
Location: seattle, WA

PostPosted: Sat Feb 18, 2006 12:12 am    Post subject: Thanks Mackieman Reply with quote

I'm used to working with the Linksys gear, and have always had good sucess with making the Nortel work through them (in my home). But the DLink was giving me a run for my money.

I sure appreciate the Q&A on the DLink site.

Thanks!
Back to top
View user's profile Send private message
hxmiller
EVDO User


Joined: 30 Jun 2005
Posts: 46

PostPosted: Sun Feb 19, 2006 8:30 pm    Post subject: Reply with quote

I'm using the KR1 with Contivity VPN Client V4_65.09. I've had problems with other Linux based routers.
Back to top
View user's profile Send private message
Michael
Site Admin


Joined: 13 Jan 2005
Posts: 5154
Location: Cary, IL

PostPosted: Fri Feb 24, 2006 10:51 am    Post subject: Reply with quote

Apparently, there are still problems with the Notel Contivity VPN that do now work with the KR1. Here is an email that I received from a customer. I am bumping up this thread as a sticky - until there is a resolution to this issue. If anyone has Nortel VPN working - please post your details to this thread, until then, we DO NOT recommend you purchase a Kyocera KR1, if you are using Nortel Contivity VPN

Quote:
Follows are the options on a Nortel Contivity VPN that do not work.
I have marked with "ON" the options that are on.
What the D-Link tech said was with VPN NAT Traversal Enabled a KR1 will
not work.
They said that there needs to be a "firewall" type feature in the router

to pass the correct packet header from the WAN to the LAN.


**************************************************
Nortel Contivity VPN
Allowed Services
IPsec ON
PPTP
L2TP & L2F

Ipsec Settings
Authentication
User Name & Password/Pre-Shared Key ON
RSA SecurID ON
User Name and Password ON

Encryption
ESP - AES 128 w/ SHA1 Integrity
ESP - Triple DES w/ SHA1 Integrity ON
ESP - Triple DES w/ MD5 Integrity ON
ESP - 56 bit DES w/ SHA1 Integrity
ESP - 56 bit DES w/ MD5 Integrity
ESP - 40 bit DES w/ SHA1 Integrity
ESP - 40 bit DES w/ MD5 Integrity
ESP - Null w/ SHA1 Integrity
ESP - Null w/ MD5 Integrity
AH - Authentication HMAC-SHA1
AH - Authentication HMAC-MD5

IKE Encryption
56-bit DES w/ Group 1
Triple DES w/ Group 2 ON
Triple DES w/ Group 7

NAT Traversal
Enabled ON
Disable Client IKE Source Port Switching
UDP Port 4500

_________________
EVDO :: EVDO News :: EVDO Antennas :: Buy Verizon :: Buy Sprint :: EVDO Amplifier
Back to top
View user's profile Send private message Send e-mail Visit poster's website AIM Address
mgodsoe
EVDO Newbie


Joined: 12 Oct 2005
Posts: 9
Location: seattle, WA

PostPosted: Mon Feb 27, 2006 1:36 pm    Post subject: Reply with quote

My Nortel Contivity client is v.04_65.26.

Having followed all of the 'tips' from you folks here, I can get the client to connect to the VPN Server. The session stalls and subsequently drops when the "Banner text" is requested. This is the legaleeze statement that says if you don't belong here, get out.

Not sure if this helps provide any clues or not, so I thought I would try.

Unfortunately, this issue presents a blocking issue for me and my wife both as we both routinely 'work from home' via the Linksys-based system at home and were hoping to 'work from home' from the boat too via our shinny new KR1.
Back to top
View user's profile Send private message
Mackieman
EVDO Junkie


Joined: 31 Oct 2005
Posts: 491

PostPosted: Mon Feb 27, 2006 4:30 pm    Post subject: Reply with quote

Turning off the IKE port switching may help solve the problem. IKE and IKMP don't seem to play well on KR1.
Back to top
View user's profile Send private message
mgodsoe
EVDO Newbie


Joined: 12 Oct 2005
Posts: 9
Location: seattle, WA

PostPosted: Mon Feb 27, 2006 6:38 pm    Post subject: Reply with quote

Is that something I can control within the KR1? I don't have any options to 'adjust' a particular setting within the Nortel Contivity Server or client as these are controlled by our Enterprise Security Department at work.
Back to top
View user's profile Send private message
Mackieman
EVDO Junkie


Joined: 31 Oct 2005
Posts: 491

PostPosted: Mon Feb 27, 2006 9:44 pm    Post subject: Reply with quote

I was actually talking about the list of options Mike posted in the quote from one of his customers. No, there isn't anything you can change in KR1 that I'm aware of.
Back to top
View user's profile Send private message
mgodsoe
EVDO Newbie


Joined: 12 Oct 2005
Posts: 9
Location: seattle, WA

PostPosted: Wed Mar 08, 2006 6:31 pm    Post subject: KR1 New Firmware coming soon? Reply with quote

I see reference to a possible release of updated firmware for the KR1. Any insights as to whether this will remove many of the VPN related roadblocks I am seeing posted here.

It seems that the D-Link traditional routers do a good job of supporting the various VPNs, but for some reason the KR1 is not. Do you think it just wasn't something they thought folks would want to use it for perhaps?

Thanks for all you guys do on this forum!

Mark
Back to top
View user's profile Send private message
mgodsoe
EVDO Newbie


Joined: 12 Oct 2005
Posts: 9
Location: seattle, WA

PostPosted: Wed Mar 08, 2006 6:39 pm    Post subject: KR1 New Firmware coming soon? Reply with quote

I see reference to a possible release of updated firmware for the KR1. Any insights as to whether this will remove many of the VPN related roadblocks I am seeing posted here.

It seems that the D-Link traditional routers do a good job of supporting the various VPNs, but for some reason the KR1 is not. Do you think it just wasn't something they thought folks would want to use it for perhaps?

Thanks for all you guys do on this forum!

Mark
Back to top
View user's profile Send private message
hxmiller
EVDO User


Joined: 30 Jun 2005
Posts: 46

PostPosted: Sun Mar 19, 2006 2:46 pm    Post subject: Reply with quote

hxmiller wrote:
I'm using the KR1 with Contivity VPN Client V4_65.09. I've had problems with other Linux based routers.



Well my company just enabled NAT traversal and now the KR1 doesn't work with my VPN.

Come on Dlink fix this!!!!
Back to top
View user's profile Send private message
ralphiles
EVDO Newbie


Joined: 18 Nov 2006
Posts: 1
Location: North Carolina

PostPosted: Sat Nov 18, 2006 4:37 am    Post subject: Reply with quote

Ok I understand everything so far my only questions is why doesn't DMZ work? DMZ should open all ports and protocols and send them straight through. Is this not a true DMZ?
_________________
Ralph Iles
Back to top
View user's profile Send private message Yahoo Messenger MSN Messenger
buratpuday
EVDO Newbie


Joined: 20 Oct 2006
Posts: 6

PostPosted: Tue Nov 21, 2006 2:40 pm    Post subject: Reply with quote

Hahahaha!!! The DMZ does not work on most of D-Link's routers. I've used D-Link from DI-524 to DIR-625 and the DMZ features would not work on those routers. Now I'm using a KR-1 and I believe it has the same problem regarding DMZ...
Back to top
View user's profile Send private message
Mackieman
EVDO Junkie


Joined: 31 Oct 2005
Posts: 491

PostPosted: Wed Nov 22, 2006 12:04 am    Post subject: Reply with quote

The DMZ is actually functioning. The issues you experience are on a different layer. The problem is that KR1 does not support the encryption protocols used, not that the packets aren't being passed. They bounce off at the firewall because KR1 doesn't know how to handle them.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    EVDOforums.com Forum Index -> Kyocera KR1 / KR2 Router Support Forum All times are GMT - 6 Hours
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum







Buy from the 3G Experts @ 3Gstore.com


CradlePoint CTR500

Purchase a MBR1000


CTR350 Router


CradlePoint PHS300


Sprint Rev A USB: Compass 597


Sprint Rev A ExpressCard: Merlin EX720


Purchase an V740 Rev A ExpressCard


Purchase an EVDO Booster Antenna

Purchase a LinkSys 3GV2 Router



Purchase an EVDO Amplifier


Your Mac EVDO Experts









EVDO Antenna Booster





Digg Us :: del.icio.us :: technorati :: furl

4G :: 4G Forums :: PHS300 :: MBR1000 :: KR2 :: Novatel Ovation U760 :: Verizon USB760 :: CBA250 :: MBR800 :: 598U :: U760