RE: contents of VPN Digest, Vol 13, Issue 1
"saurav khanna" <[email protected]>
| Newsgroups | gmane.comp.security.vpn |
|---|---|
| Message-ID | <[email protected]> |
Hi Jason, Check if you have the stateful firewall enabled in the VPN Client or not also if the client has the ability to do split tunneling or not. >From: [email protected] >Reply-To: [email protected] >To: [email protected] >Subject: VPN Digest, Vol 13, Issue 1 >Date: Tue, 4 May 2004 10:49:56 -0600 (MDT) > >Send VPN mailing list submissions to > [email protected] > >To subscribe or unsubscribe via the World Wide Web, visit > http://lists.shmoo.com/mailman/listinfo/vpn >or, via email, send a message with subject or body 'help' to > [email protected] > >You can reach the person managing the list at > [email protected] > >When replying, please edit your Subject line so it is more specific >than "Re: Contents of VPN digest..." > > >Today's Topics: > > 1. Fw: Help with VPN Client 4.0.3 to PIX through A vigor > internet link (Onsite DeTeWe) > 2. Fw: Help with VPN Client 4.0.3 to PIX through A vigor > internet link (Onsite DeTeWe) > > >---------------------------------------------------------------------- > >Message: 1 >Date: Tue, 4 May 2004 13:01:52 +0100 >From: Onsite DeTeWe <[email protected]> >Subject: [VPN] Fw: Help with VPN Client 4.0.3 to PIX through A vigor > internet link >To: [email protected] <[email protected]> >Message-ID: > <OFC8DF59FB.BF7B30E9-ON80256E8A.0041CF75-80256E8A.004216A3@firstgroup.com> > >Content-Type: text/plain; charset="us-ascii" > >New Problem. > >I have been having a few problems with gettnig a VPN working. I can bring >the tunnel up now but the problem I have now is that I cannot connect to >anything on the network from the client?!?! > >I have done a 'sh debug isa sa' and get the following: > > >ISAKMP (0): processing NOTIFY payload 36136 protocol 1 > spi 0, message ID = 3573924010 >ISAMKP (0): received DPD_R_U_THERE from peer xxx.xxx.xxx.xxx >ISAKMP (0): sending NOTIFY message 36137 protocol 1 >return status is IKMP_NO_ERR_NO_TRANS >crypto_isakmp_process_block:src:217.155.241.118, dest:192.168.0.249 >spt:500 dpt: >500 > > >192.168.0.249 is the DMZ ip address of where the connection is comming in. > >Hope someone can help. > >Regards > >Jason > >********************************************************************** >This message is confidential. It may not be disclosed to, or used by, >anyone other than the addressee. If you receive this message in >error, please advise us immediately. > >Internet email is not necessarily secure. First does not accept >responsibility for changes to any email which occur after the email >has been sent. Attachments to this email could contain software >viruses which could damage your system. First have checked the >attachments for viruses before sending, but you should virus-check >them before opening. > >http://www.firstgroup.com >********************************************************************** > >-------------- next part -------------- >An HTML attachment was scrubbed... >URL: http://sisyphus.iocaine.com/pipermail/vpn/attachments/20040504/952d7af4/attachment.html > >------------------------------ > >Message: 2 >Date: Tue, 4 May 2004 16:02:32 +0100 >From: Onsite DeTeWe <[email protected]> >Subject: [VPN] Fw: Help with VPN Client 4.0.3 to PIX through A vigor > internet link >To: [email protected] <[email protected]> >Message-ID: > <OFF8B69527.6257A3D1-ON80256E8A.0052535C-80256E8A.0052A10D@firstgroup.com> > >Content-Type: text/plain; charset="us-ascii" > >OK so I was thinking that my last email was a bit vague. Here is an >output from my pix with the following debug. > >debug packet inside src 172.1.1.1 dst JASON both > >172.1.1.1 is from the pool and JASON is my PC the only PC in the 0 NAT >access list. > >The below output is generated from perfoming a VNC request from the Client >PC, but does not connect?!?!? Any Ideas?? > >Kind regards in advance. > >Jason > > > >172.1.1.1 ==> JASON > > ver = 0x4 hlen = 0x5 tos = 0x0 tlen = 0x30 > id = 0xeb88 flags = 0x40 frag off=0x0 > ttl = 0x80 proto=0x6 chksum = 0x5335 > > -- TCP -- > source port = 0x570 dest port = 0x170csyn > > seq = 0x109067c2 > ack = 0xec312177 > hlen = 0x7 window = 0xfff0 > checksum = 0x2575 urg = 0x0 >tcp options: > 0x2 0x4 0x4 0xec 0x1 0x1 0x4 0 >x2 >--------- END OF PACKET --------- > >--------- PACKET --------- > >-- IP -- >JASON ==> 172.1.1.1 > > ver = 0x4 hlen = 0x5 tos = 0x0 tlen = 0x30 > id = 0x5850 flags = 0x40 frag off=0x0 > ttl = 0x7f proto=0x6 chksum = 0xe76d > > -- TCP -- > source port = 0x170c dest port = 0x570syn ack > > seq = 0xdc635b54 > ack = 0x109067c3 > hlen = 0x7 window = 0xfc00 > checksum = 0xfe7c urg = 0x0 >tcp options: > 0x2 0x4 0x5 0xb4 0x1 0x1 0x4 0 >x2 >--------- END OF PACKET --------- > >--------- PACKET --------- > >-- IP -- >172.1.1.1 ==> JASON > > ver = 0x4 hlen = 0x5 tos = 0x0 tlen = 0x30 > id = 0xeb95 flags = 0x40 frag off=0x0 > ttl = 0x80 proto=0x6 chksum = 0x5328 > > -- TCP -- > source port = 0x570 dest port = 0x170csyn > > seq = 0x109067c2 > ack = 0xec312177 > hlen = 0x7 window = 0xfff0 > checksum = 0x2575 urg = 0x0 >tcp options: > 0x2 0x4 0x4 0xec 0x1 0x1 0x4 0 >x2 >--------- END OF PACKET --------- > >--------- PACKET --------- > >-- IP -- >JASON ==> 172.1.1.1 > > ver = 0x4 hlen = 0x5 tos = 0x0 tlen = 0x28 > id = 0x5879 flags = 0x40 frag off=0x0 > ttl = 0x7f proto=0x6 chksum = 0xe74c > > -- TCP -- > source port = 0x170c dest port = 0x570ack > > seq = 0xdc635b55 > ack = 0x109067c3 > hlen = 0x5 window = 0xfc00 > checksum = 0x2b41 urg = 0x0 > -- DATA -- > 00000020: 00 00 00 00 00 00 4e | > ......N > >--------- END OF PACKET --------- > >--------- PACKET --------- > >-- IP -- >JASON ==> 172.1.1.1 > > ver = 0x4 hlen = 0x5 tos = 0x0 tlen = 0x30 > id = 0x587d flags = 0x40 frag off=0x0 > ttl = 0x7f proto=0x6 chksum = 0xe740 > > -- TCP -- > source port = 0x170c dest port = 0x570syn ack > > seq = 0xdc635b54 > ack = 0x109067c3 > hlen = 0x7 window = 0xfc00 > checksum = 0xfe7c urg = 0x0 >tcp options: > 0x2 0x4 0x5 0xb4 0x1 0x1 0x4 0 >x2 >--------- END OF PACKET --------- > >--------- PACKET --------- > >-- IP -- >172.1.1.1 ==> JASON > > ver = 0x4 hlen = 0x5 tos = 0x0 tlen = 0x30 > id = 0xebb4 flags = 0x40 frag off=0x0 > ttl = 0x80 proto=0x6 chksum = 0x5309 > > -- TCP -- > source port = 0x570 dest port = 0x170csyn > > seq = 0x109067c2 > ack = 0xec312177 > hlen = 0x7 window = 0xfff0 > checksum = 0x2575 urg = 0x0 >tcp options: > 0x2 0x4 0x4 0xec 0x1 0x1 0x4 0 >x2 >--------- END OF PACKET --------- > >--------- PACKET --------- > >-- IP -- >JASON ==> 172.1.1.1 > > ver = 0x4 hlen = 0x5 tos = 0x0 tlen = 0x28 > id = 0x58d8 flags = 0x40 frag off=0x0 > ttl = 0x7f proto=0x6 chksum = 0xe6ed > > -- TCP -- > source port = 0x170c dest port = 0x570ack > > seq = 0xdc635b55 > ack = 0x109067c3 > hlen = 0x5 window = 0xfc00 > checksum = 0x2b41 urg = 0x0 > -- DATA -- > 00000020: 00 00 00 00 00 00 00 | > ....... > >--------- END OF PACKET --------- > >--------- PACKET --------- > >-- IP -- >JASON ==> 172.1.1.1 > > ver = 0x4 hlen = 0x5 tos = 0x0 tlen = 0x30 > id = 0x58e4 flags = 0x40 frag off=0x0 > ttl = 0x7f proto=0x6 chksum = 0xe6d9 > > -- TCP -- > source port = 0x170c dest port = 0x570syn ack > > seq = 0xdc635b54 > ack = 0x109067c3 > hlen = 0x7 window = 0xfc00 > checksum = 0xfe7c urg = 0x0 >tcp options: > 0x2 0x4 0x5 0xb4 0x1 0x1 0x4 0 >x2 >--------- END OF PACKET --------- > > >********************************************************************** >This message is confidential. It may not be disclosed to, or used by, >anyone other than the addressee. If you receive this message in >error, please advise us immediately. > >Internet email is not necessarily secure. First does not accept >responsibility for changes to any email which occur after the email >has been sent. Attachments to this email could contain software >viruses which could damage your system. First have checked the >attachments for viruses before sending, but you should virus-check >them before opening. > >http://www.firstgroup.com >********************************************************************** > >-------------- next part -------------- >An HTML attachment was scrubbed... >URL: http://sisyphus.iocaine.com/pipermail/vpn/attachments/20040504/93f3ba7b/attachment.html > >------------------------------ > >_______________________________________________ >VPN mailing list >[email protected] >http://lists.shmoo.com/mailman/listinfo/vpn > >End of VPN Digest, Vol 13, Issue 1 >********************************** ---------- Best of Indian handicrafts. At MSN Shopping. _______________________________________________ VPN mailing list [email protected] http://lists.shmoo.com/mailman/listinfo/vpn