Re: Cisco VPN Client with GuardDog
Kevin Ferguson <[email protected]>
| Newsgroups | gmane.network.guarddog |
|---|---|
| Message-ID | <[email protected]> |
Craig Thats a great result, I was going to suggest to enable those two ports that got dropped. Really pleased you got it working. I always use /var/log/messages to trace to any failing connections. Regards Kevin Craig Donnelly wrote: > I enabled UDP port: 29747 (Local & Internet Bidirectional) and it > works now! > Thanks for your comments. > > Cheers, > Craig > > Craig Donnelly wrote: > >> Kevin, >> >> Just tried what you recommended, *tail +f /var/log/messages * >> >> I then tried "vpnclient connect MYHOST" >> >> Which resulted in: >> ################################################################## >> vpnclient connect MYHOST >> Cisco Systems VPN Client Version 4.6.02 (0030) >> Copyright (C) 1998-2004 Cisco Systems, Inc. All Rights Reserved. >> Client Type(s): Linux >> Running on: Linux 2.6.12-1.1398_FC4.stk16 #1 Fri Jul 22 13:55:37 EDT >> 2005 i686 >> Config file directory: /etc/opt/cisco-vpnclient >> >> Initializing the VPN connection. >> Secure VPN Connection terminated locally by the Client >> Reason: Failed to establish a VPN connection. >> There are no new notification messages at this time. >> ################################################################## >> >> I checked the realtime log and this was the result: >> ################################################################## >> Aug 31 12:12:30 wingfield kernel: DROPPED IN= OUT=wlan0 >> SRC=192.168.2.2 DST=xx.xx.xx.xx LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 >> DF PROTO=UDP SPT=1063 DPT=29747 LEN=24 >> Aug 31 12:12:30 wingfield kernel: DROPPED IN= OUT=wlan0 >> SRC=192.168.2.2 DST=xx.xx.xx.xx LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=0 >> DF PROTO=UDP SPT=1063 DPT=29747 LEN=20 >> ################################################################## >> >> HHHmmm..I dont have those ports config through GuarDog: >> - 1063 >> - 29747 >> Im hoping this helps..Any thoughts? >> >> Regards, >> Craig >> >> Craig Donnelly wrote: >> >>> Hi Kevin >>> >>> Im running through a wireless router, but this is not >>> effecting/blocking the VPN connection. >>> The VPN works fine on win32 and also, it works fine when I disable >>> guarddog. >>> >>> Will have a look at the message logs and post anything here. >>> >>> Regards, >>> Craig >>> >>> ----- Original Message ----- From: "Kevin Ferguson" >>> <[email protected]> >>> To: "Craig Donnelly" <[email protected]> >>> Cc: <[email protected]> >>> Sent: Wednesday, August 31, 2005 11:19 AM >>> Subject: Re: [GD-user] Cisco VPN Client with GuardDog >>> >>> >>> >>>>> Hi Craig >>>>> >>>>> I work from home at the weekends, I'm in the process of configuring >>>>> cisco vpn too on my laptop. It maybe worth while checking your >>>>> syslog >>>>> or messages logs while trying to connect with vpn. If your behind a >>>>> router you may need to forward the ports to a specific ip >>>>> address. I've >>>>> got it working on window 2000. But still looking at getting it >>>>> working >>>>> on my laptop. If you run *tail +f /var/log/messages *as root* *it >>>>> will >>>>> give you a realtime logging and any connections/dropped blocked. I >>>>> think that would be a good place to start. >>>>> >>>>> Are you behind a router incidently? >>>>> >>>>> Regards >>>>> Kevin >>>>> >>>>> Craig Donnelly wrote: >>>>> >>>> >>>> >>>>>> > >>>>>> > Hello, >>>>>> > >>>>>> > Im hoping someone can help me out. I have a VPN client that I >>>>>> need to >>>>>> > get >>>>>> > running through GuardDog. >>>>>> > Its compiled and running on Fedora FC4. When I disable the >>>>>> firewall, it >>>>>> > works fine, but not so when enabled >>>>>> > thus ruling out an router/modem issues. I followed the cisco >>>>>> docs which >>>>>> > state the following ports need to be enabled >>>>>> > for the client to communicate: >>>>>> > >>>>>> > The CISCO documentation mentions several other ports, quoting: >>>>>> > * UDP port 500 >>>>>> > * UDP port 10000 (or any other port number being used for >>>>>> IPSec/UDP) >>>>>> > * IP protocol 50 (ESP) >>>>>> > * TCP port configured for IPSec/TCP >>>>>> > * NAT-T port 4500 >>>>>> > >>>>>> > I have created 3 user defined protocols: >>>>>> > - 500 (UDP bidirectional) >>>>>> > - 10000 (UDP bidirectional) >>>>>> > - 4500 (UDP bidirectional) >>>>>> > >>>>>> > An enabled these on local & internet zones. I have also >>>>>> enabled ESP on >>>>>> > these two zones. >>>>>> > Still I cannot get it to allow the communication through. >>>>>> > >>>>>> > If anyone can help it would be very much appreciated. >>>>>> > >>>>>> > Regards, >>>>>> > Craig >>>>>> > >>>>>> > >>>>>> > >>>>>> > ------------------------------------------------------- >>>>>> > SF.Net email is Sponsored by the Better Software Conference & EXPO >>>>>> > September 19-22, 2005 * San Francisco, CA * Development Lifecycle >>>>>> > Practices >>>>>> > Agile & Plan-Driven Development * Managing Projects & Teams * >>>>>> Testing >>>>>> > & QA >>>>>> > Security * Process Improvement & Measurement * >>>>> >>>>> >>>>> >>>>> >>>> >>>> >>>> >>> http://www.sqe.com/bsce5sf >>> >>>>>> > _______________________________________________ >>>>>> > Guarddog-user mailing list >>>>>> > [email protected] >>>>>> > https://lists.sourceforge.net/lists/listinfo/guarddog-user >>>>>> > >>>>>> > >>>>> >>>>> >>>>> >>>>> >>>>> >>>>> >>>>> ------------------------------------------------------- >>>>> SF.Net email is Sponsored by the Better Software Conference & EXPO >>>>> September 19-22, 2005 * San Francisco, CA * Development Lifecycle >>>> >>>> >>>> >>>> >>>> >>> Practices >>> >>>>> Agile & Plan-Driven Development * Managing Projects & Teams * >>>>> Testing & QA >>>>> Security * Process Improvement & Measurement * >>>>> http://www.sqe.com/bsce5sf >>>>> _______________________________________________ >>>>> Guarddog-user mailing list >>>>> [email protected] >>>>> https://lists.sourceforge.net/lists/listinfo/guarddog-user >>>>> >>>>> >>>> >>>> >>> >> >> > > > ------------------------------------------------------- SF.Net email is Sponsored by the Better Software Conference & EXPO September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf