| View previous topic :: View next topic |
| Author |
Message |
pverzoni EVDO Newbie
Joined: 30 Mar 2006 Posts: 10
|
Posted: Wed Apr 05, 2006 2:30 pm Post subject: VPN's and KR1 |
|
|
Has anyone had any success in IPSEC VPN's with KR1's? I have tried:
1) Using software VPN on the PC's connected to the KR1 (NETSCREEN REMOTE), while the tunnel works (i.e. VPN gets created OK), no packets seem to return to destination.
2) Tried putting a Netscreen firewall/vpn between the KR1 and PC's, same issue.
I put the IP of the firewall or laptop in DMZ, so all traffic should go through. Also have VPN passthrough enabled.
Card is V620 from Sprint. It works fine (VPN) when connected to the laptop directly.
Peter |
|
| Back to top |
|
 |
pverzoni EVDO Newbie
Joined: 30 Mar 2006 Posts: 10
|
Posted: Wed Apr 05, 2006 8:48 pm Post subject: |
|
|
Oh well, looks like a full day of working on getting KR1 to work with VPN's hasnt been fruitful.
Called Kyocera/Dlink support but they claim that it should work, however it does not. Spent the remaining day on the phone with Juniper support, escalated several levels but no luck.
Having same issue as post at http://www.evdoforums.com/viewtopic.php?t=1914&highlight=vpn where VPN connection is successful but cannot access anything on the remote network via VPN.
I doubt we'll get this resolved - does anyone know if there is any alternative to KR1? |
|
| Back to top |
|
 |
pverzoni EVDO Newbie
Joined: 30 Mar 2006 Posts: 10
|
Posted: Thu Apr 06, 2006 10:50 am Post subject: |
|
|
Well here's an update - not all that great.
I was able to get a Netscreen hardware firewall working between the KR1 and LAN and VPN's worked. With this configuration the VPN tunnels are initiated at the Netscreen firewall.
So this made me think, since the VPN's worked using a hardware firewall then there should be no reason they shouldnt work if the vendor is same when connected directly to the KR1
Now in my original testing, the hosts behind the KR1 were connected to the KR1 using WIFI connection. So just for the kicks I decided to connect a laptop directly to a port of the KR1 and bang it worked. VPN's worked just fine.
So who knows why, but VPN's only work when you use a physical port on the KR1, not the wireless interface.
So my workaround is to use an Access Point connected to the physical port of the KR1 and then disable the WIFI on the KR1.
What is disturbing is Kyocera / Dlink support. They basically responded saying that if a VPN doesnt work then they dont support it. I would understand this logic if VPN's wouldnt work on neither the wireless or the wired interfaces. This clearly looks like a bug to me but they seem to fail to acknowledge this.
Anyway if anyone has any suggestions please let me know.
Peter
<< RESPONSE FROM DLINK/KYOCERA >>
Hello,I spoke with the Account Manager for the KR1,and basically we can only support propietary VPNs to a point,after that if it still does not connect,there is not much we can do unfortunately,from our conversations it appears the packets are being appended with a header that the router will not acknowledge. |
|
| Back to top |
|
 |
Chappp EVDO Newbie
Joined: 24 Feb 2006 Posts: 3
|
Posted: Sat Apr 08, 2006 5:57 pm Post subject: |
|
|
This is an MTU problem , you have to put the MTU of your computer at 1325 and all will be fine.
Tell me ! |
|
| Back to top |
|
 |
pverzoni EVDO Newbie
Joined: 30 Mar 2006 Posts: 10
|
Posted: Sat Apr 08, 2006 8:13 pm Post subject: |
|
|
I fail to understand how this would be an issue for the wireless ports only though? I will try it and post an update.
I know how to change on a PC, but not on OSX? How do you change the mtu on OSX?
| Chappp wrote: | This is an MTU problem , you have to put the MTU of your computer at 1325 and all will be fine.
Tell me ! |
|
|
| Back to top |
|
 |
bccinc EVDO Newbie
Joined: 15 Apr 2006 Posts: 1
|
|
| Back to top |
|
 |
nativgod EVDO Newbie
Joined: 22 May 2006 Posts: 3
|
Posted: Mon May 22, 2006 7:17 am Post subject: |
|
|
| Enable TCP over IPSec port 10000. I have done so on both my Cisco 3002 VPN Hardware Client and Cisco VPN software and successfully connected and passing data. |
|
| Back to top |
|
 |
|