| View previous topic :: View next topic |
| Author |
Message |
rmk EVDO Newbie
Joined: 07 Feb 2006 Posts: 5
|
Posted: Wed Mar 01, 2006 9:07 pm Post subject: Cisco client works with D-Link DI-604 router, but not KR1 |
|
|
Hi,
I have the Cisco VPN client 4.7.00.0533, which is using IPSec over UDP (NAT/PAT). I have tried the following configurations when attempting to connect to the network with the Cisco VPN client: (Note non-VPN activities are fine)
Works - Laptop connected to DSL via D-link DI-604 (set to factory defaults)
Works - KPC650 air card inserted directly into laptop
Fails - Laptop connected to KR1 set to factory defaults (PPTP & IPSec are Enabled). Client connects, but cannot access anything on the network (ping, telnet, ftp ...).
Fails - Laptop connected to KR1 set to factory defaults plus laptop IP is the DMZ IP address. Again the client connects, but cannot access anything on the network (same as above).
Anyone have any ideas?
Thanks. |
|
| Back to top |
|
 |
Mackieman EVDO Junkie
Joined: 31 Oct 2005 Posts: 453
|
Posted: Thu Mar 02, 2006 10:54 am Post subject: |
|
|
| This happens with some types of Cisco VPN due to the IKE security handshake that it tries to do over the IPSec tunnel. Because KR1 does not do PAT, the handshake ACK packets are dropped at the firewall because they return on a different port than they came in on. KR1 isn't able to route them in its current state. |
|
| Back to top |
|
 |
rmk EVDO Newbie
Joined: 07 Feb 2006 Posts: 5
|
Posted: Sun Mar 05, 2006 3:16 pm Post subject: |
|
|
Just to clarify.
Do the DI 604 & DI-704 routers support PAT?
When can we expect the KR1 to support PAT?
Thanks. |
|
| Back to top |
|
 |
Mackieman EVDO Junkie
Joined: 31 Oct 2005 Posts: 453
|
Posted: Mon Mar 06, 2006 10:38 am Post subject: |
|
|
| I'm not sure about the DI-604 but I believe the 704 does; I could be wrong, however. KR1 will not support PAT on the current hardware platform. |
|
| Back to top |
|
 |
pverzoni EVDO Newbie
Joined: 30 Mar 2006 Posts: 10
|
Posted: Thu Apr 06, 2006 10:53 am Post subject: Re: Cisco client works with D-Link DI-604 router, but not KR |
|
|
Have the same issue on a Juniper Netscreen device, I found out that if I connect the laptop to one of the physical ports then VPN's work.
I had same issue where tunnel would get connected but hosts could not access any devices on the remote end.
Try connecting your laptop directly to one of the ports on the KR1 and see if it works,
Peter
| rmk wrote: | Hi,
I have the Cisco VPN client 4.7.00.0533, which is using IPSec over UDP (NAT/PAT). I have tried the following configurations when attempting to connect to the network with the Cisco VPN client: (Note non-VPN activities are fine)
Works - Laptop connected to DSL via D-link DI-604 (set to factory defaults)
Works - KPC650 air card inserted directly into laptop
Fails - Laptop connected to KR1 set to factory defaults (PPTP & IPSec are Enabled). Client connects, but cannot access anything on the network (ping, telnet, ftp ...).
Fails - Laptop connected to KR1 set to factory defaults plus laptop IP is the DMZ IP address. Again the client connects, but cannot access anything on the network (same as above).
Anyone have any ideas?
Thanks. |
|
|
| Back to top |
|
 |
visortgw EVDO User
Joined: 28 Oct 2005 Posts: 67
|
Posted: Thu Apr 06, 2006 5:32 pm Post subject: Re: Cisco client works with D-Link DI-604 router, but not KR |
|
|
| rmk wrote: | Hi,
I have the Cisco VPN client 4.7.00.0533, which is using IPSec over UDP (NAT/PAT). I have tried the following configurations when attempting to connect to the network with the Cisco VPN client: (Note non-VPN activities are fine)
Works - Laptop connected to DSL via D-link DI-604 (set to factory defaults)
Works - KPC650 air card inserted directly into laptop
Fails - Laptop connected to KR1 set to factory defaults (PPTP & IPSec are Enabled). Client connects, but cannot access anything on the network (ping, telnet, ftp ...).
Fails - Laptop connected to KR1 set to factory defaults plus laptop IP is the DMZ IP address. Again the client connects, but cannot access anything on the network (same as above).
Anyone have any ideas?
Thanks. |
Do you have access to an older version of the Cisco VPN client? I currently use v4.0.3 (F), as supplied/preconfigured by my Corporate IT department, successfully with the KR1 -- my configuration also uses IPSec/UDP. |
|
| Back to top |
|
 |
grywalsr EVDO Fledgling
Joined: 08 Dec 2005 Posts: 15
|
Posted: Thu Apr 06, 2006 7:40 pm Post subject: I'm in the same boat! |
|
|
| I have Cisco VPN Client 4.0.1 and I have the same problem. Has anyone figured out a workaround? |
|
| Back to top |
|
 |
Mackieman EVDO Junkie
Joined: 31 Oct 2005 Posts: 453
|
Posted: Fri Apr 07, 2006 9:08 am Post subject: |
|
|
| Unfortunately there is no workaround that I know of. I'm no expert but I've seen this problem in several places and it always has something to do with AES/IKE or ESP/EAP or some other security issue. The data connection is made but no traffic can pass over the VPN because KR1 doesn't handle the authentication packets. KR1 just doesn't play with the security protocols that some Cisco VPN concentrators operate with. |
|
| Back to top |
|
 |
|