VPN problems from Linksys WAG54G to Netscreen 208 using netscreen client

VPN problems from Linksys WAG54G to Netscreen 208 using netscreen client

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
VPN problems from Linksys WAG54G to Netscreen 208 using netscreen client RA 11-28-2005
Posted by RA on November 28, 2005, 5:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I am trying to connect to the company network via my linksys WAG54G
router.

IPsec filtering is on and the router asks for my username and password.
Once connected I can access my email using microsoft exchange without
any problems however I cannot access any of my shared drives or SQL
enterprise manager and a whole host of other required applications.

Can anyone help

Russ


Posted by Somebody. on November 28, 2005, 9:07 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>I am trying to connect to the company network via my linksys WAG54G
> router.
>
> IPsec filtering is on and the router asks for my username and password.
> Once connected I can access my email using microsoft exchange without
> any problems however I cannot access any of my shared drives or SQL
> enterprise manager and a whole host of other required applications.
>
> Can anyone help
>
> Russ

That sounds pretty odd -- Exchange uses TCP and UDP so generally if that
works you have a wide open tunnel. So you should be looking at filtering on
the WAG or incorrect policies on the NS.

So the first thing (as always) is to do a trace on the NS to see what's
actually happening, or if the traffic is actually getting there or not. The
usual...

undebug all
clear dbuf
set ffilter dst-ip 1.1.1.1*
set ffilter src-ip 2.2.2.2**
debug flow basic

<send some traffic to 1.1.1.1* from 2.2.2.2**over the VPN>

undebug all
get dbuf stream

* is the IP of your server for which you want to examine the traffic
** is your source device.

My wild guess is you'll see the exchange taffic, and pings and such, but not
the 445 or the SQL traffic because your WAG think's it's not good Internet
traffic and has filtered it.

I'd suggest not putting it in router mode at all, just put it in as an
access point and hang it off an interface of the 208, do your NAT there
instead. If you don't know how to do this, just connect the 208 interface
to an IP on the trust side of the WAG and set the wireless client gateways
to the 208 IP, that will make it work as a WAP instead of a gateway. That
will hand all control of that zone to the 208.

-Russ. (a different Russ)



Similar ThreadsPosted
Netscreen 5GT VPN Client May 6, 2005, 3:26 pm
Netscreen VPN client April 13, 2006, 4:46 pm
NetScreen Client VPN Configure November 25, 2005, 5:34 pm
Problems: VPNs whit Netscreen 500 July 14, 2004, 8:21 am
Netscreen Remote and Symantec Firewall Client November 8, 2004, 6:31 am
Juniper Netscreen Home/Logoff problems with Web Applications February 8, 2008, 7:27 am
Windows XP VPN to Netscreen using native client and L2TP over IPSEC May 18, 2005, 11:59 pm
Recieving Phase 1 Error When attempting to connect Linksys (BEFVP41) and NetScreen (5XP) VPN January 26, 2005, 9:59 am
Problems with Common Client Update July 20, 2004, 2:44 pm
Backup Exec problems with client using Sygate...................Anyone know the answer? November 28, 2005, 12:00 am

The site map in XML format XML site map

Contact Us | Privacy Policy