Re: Cisco VPN Client with GuardDog
Craig Donnelly <[email protected]>
| Newsgroups | gmane.network.guarddog |
|---|---|
| Message-ID | <[email protected]> |
I enabled UDP port: 29747 (Local & Internet Bidirectional) and it works now! Thanks for your comments. Cheers, Craig Craig Donnelly wrote: > Kevin, > > Just tried what you recommended, *tail +f /var/log/messages * > > I then tried "vpnclient connect MYHOST" > > Which resulted in: > ################################################################## > vpnclient connect MYHOST > Cisco Systems VPN Client Version 4.6.02 (0030) > Copyright (C) 1998-2004 Cisco Systems, Inc. All Rights Reserved. > Client Type(s): Linux > Running on: Linux 2.6.12-1.1398_FC4.stk16 #1 Fri Jul 22 13:55:37 EDT > 2005 i686 > Config file directory: /etc/opt/cisco-vpnclient > > Initializing the VPN connection. > Secure VPN Connection terminated locally by the Client > Reason: Failed to establish a VPN connection. > There are no new notification messages at this time. > ################################################################## > > I checked the realtime log and this was the result: > ################################################################## > Aug 31 12:12:30 wingfield kernel: DROPPED IN= OUT=wlan0 > SRC=192.168.2.2 DST=xx.xx.xx.xx LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 > DF PROTO=UDP SPT=1063 DPT=29747 LEN=24 > Aug 31 12:12:30 wingfield kernel: DROPPED IN= OUT=wlan0 > SRC=192.168.2.2 DST=xx.xx.xx.xx LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=0 > DF PROTO=UDP SPT=1063 DPT=29747 LEN=20 > ################################################################## > > HHHmmm..I dont have those ports config through GuarDog: > - 1063 > - 29747 > Im hoping this helps..Any thoughts? > > Regards, > Craig > > Craig Donnelly wrote: > >> Hi Kevin >> >> Im running through a wireless router, but this is not >> effecting/blocking the VPN connection. >> The VPN works fine on win32 and also, it works fine when I disable >> guarddog. >> >> Will have a look at the message logs and post anything here. >> >> Regards, >> Craig >> >> ----- Original Message ----- From: "Kevin Ferguson" >> <[email protected]> >> To: "Craig Donnelly" <[email protected]> >> Cc: <[email protected]> >> Sent: Wednesday, August 31, 2005 11:19 AM >> Subject: Re: [GD-user] Cisco VPN Client with GuardDog >> >> >> >>>> Hi Craig >>>> >>>> I work from home at the weekends, I'm in the process of configuring >>>> cisco vpn too on my laptop. It maybe worth while checking your syslog >>>> or messages logs while trying to connect with vpn. If your behind a >>>> router you may need to forward the ports to a specific ip address. >>>> I've >>>> got it working on window 2000. But still looking at getting it working >>>> on my laptop. If you run *tail +f /var/log/messages *as root* *it >>>> will >>>> give you a realtime logging and any connections/dropped blocked. I >>>> think that would be a good place to start. >>>> >>>> Are you behind a router incidently? >>>> >>>> Regards >>>> Kevin >>>> >>>> Craig Donnelly wrote: >>>> >>> >>> >>>>> > >>>>> > Hello, >>>>> > >>>>> > Im hoping someone can help me out. I have a VPN client that I >>>>> need to >>>>> > get >>>>> > running through GuardDog. >>>>> > Its compiled and running on Fedora FC4. When I disable the >>>>> firewall, it >>>>> > works fine, but not so when enabled >>>>> > thus ruling out an router/modem issues. I followed the cisco >>>>> docs which >>>>> > state the following ports need to be enabled >>>>> > for the client to communicate: >>>>> > >>>>> > The CISCO documentation mentions several other ports, quoting: >>>>> > * UDP port 500 >>>>> > * UDP port 10000 (or any other port number being used for >>>>> IPSec/UDP) >>>>> > * IP protocol 50 (ESP) >>>>> > * TCP port configured for IPSec/TCP >>>>> > * NAT-T port 4500 >>>>> > >>>>> > I have created 3 user defined protocols: >>>>> > - 500 (UDP bidirectional) >>>>> > - 10000 (UDP bidirectional) >>>>> > - 4500 (UDP bidirectional) >>>>> > >>>>> > An enabled these on local & internet zones. I have also enabled >>>>> ESP on >>>>> > these two zones. >>>>> > Still I cannot get it to allow the communication through. >>>>> > >>>>> > If anyone can help it would be very much appreciated. >>>>> > >>>>> > Regards, >>>>> > Craig >>>>> > >>>>> > >>>>> > >>>>> > ------------------------------------------------------- >>>>> > SF.Net email is Sponsored by the Better Software Conference & EXPO >>>>> > September 19-22, 2005 * San Francisco, CA * Development Lifecycle >>>>> > Practices >>>>> > Agile & Plan-Driven Development * Managing Projects & Teams * >>>>> Testing >>>>> > & QA >>>>> > Security * Process Improvement & Measurement * >>>> >>>> >>>> >>> >>> >> http://www.sqe.com/bsce5sf >> >>>>> > _______________________________________________ >>>>> > Guarddog-user mailing list >>>>> > [email protected] >>>>> > https://lists.sourceforge.net/lists/listinfo/guarddog-user >>>>> > >>>>> > >>>> >>>> >>>> >>>> >>>> >>>> ------------------------------------------------------- >>>> SF.Net email is Sponsored by the Better Software Conference & EXPO >>>> September 19-22, 2005 * San Francisco, CA * Development Lifecycle >>> >>> >>> >>> >> Practices >> >>>> Agile & Plan-Driven Development * Managing Projects & Teams * >>>> Testing & QA >>>> Security * Process Improvement & Measurement * >>>> http://www.sqe.com/bsce5sf >>>> _______________________________________________ >>>> Guarddog-user mailing list >>>> [email protected] >>>> https://lists.sourceforge.net/lists/listinfo/guarddog-user >>>> >>>> >>> >>> >> > > ------------------------------------------------------- SF.Net email is Sponsored by the Better Software Conference & EXPO September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf