Re: Cisco VPN Client with GuardDog

Kevin Ferguson <[email protected]>
Newsgroups gmane.network.guarddog
Message-ID <[email protected]>
Craig

Thats a great result, I was going to suggest to enable those two ports 
that got dropped.  Really pleased you got it working.  I always use 
/var/log/messages to trace to any failing connections.

Regards
Kevin

Craig Donnelly wrote:

> I enabled UDP port: 29747 (Local & Internet Bidirectional) and it 
> works now!
> Thanks for your comments.
>
> Cheers,
> Craig
>
> Craig Donnelly wrote:
>
>> Kevin,
>>
>> Just tried what you recommended, *tail +f /var/log/messages *
>>
>> I then tried "vpnclient connect MYHOST"
>>
>> Which resulted in:
>> ##################################################################
>> vpnclient connect MYHOST
>> Cisco Systems VPN Client Version 4.6.02 (0030)
>> Copyright (C) 1998-2004 Cisco Systems, Inc. All Rights Reserved.
>> Client Type(s): Linux
>> Running on: Linux 2.6.12-1.1398_FC4.stk16 #1 Fri Jul 22 13:55:37 EDT 
>> 2005 i686
>> Config file directory: /etc/opt/cisco-vpnclient
>>
>> Initializing the VPN connection.
>> Secure VPN Connection terminated locally by the Client
>> Reason: Failed to establish a VPN connection.
>> There are no new notification messages at this time.
>> ##################################################################
>>
>> I checked the realtime log and this was the result:
>> ##################################################################
>> Aug 31 12:12:30 wingfield kernel: DROPPED IN= OUT=wlan0 
>> SRC=192.168.2.2 DST=xx.xx.xx.xx LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 
>> DF PROTO=UDP SPT=1063 DPT=29747 LEN=24
>> Aug 31 12:12:30 wingfield kernel: DROPPED IN= OUT=wlan0 
>> SRC=192.168.2.2 DST=xx.xx.xx.xx LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=0 
>> DF PROTO=UDP SPT=1063 DPT=29747 LEN=20
>> ##################################################################
>>
>> HHHmmm..I dont have those ports config through GuarDog:
>>    - 1063
>>    - 29747
>> Im hoping this helps..Any thoughts?
>>
>> Regards,
>> Craig
>>
>> Craig Donnelly wrote:
>>
>>> Hi Kevin
>>>
>>> Im running through a wireless router, but this is not 
>>> effecting/blocking the VPN connection.
>>> The VPN works fine on win32 and also, it works fine when I disable 
>>> guarddog.
>>>
>>> Will have a look at the message logs and post anything here.
>>>
>>> Regards,
>>> Craig
>>>
>>> ----- Original Message ----- From: "Kevin Ferguson" 
>>> <[email protected]>
>>> To: "Craig Donnelly" <[email protected]>
>>> Cc: <[email protected]>
>>> Sent: Wednesday, August 31, 2005 11:19 AM
>>> Subject: Re: [GD-user] Cisco VPN Client with GuardDog
>>>
>>>
>>>
>>>>> Hi Craig
>>>>>
>>>>> I work from home at the weekends, I'm in the process of configuring
>>>>> cisco vpn too on my laptop.  It maybe worth while checking your 
>>>>> syslog
>>>>> or messages logs while trying to connect with vpn.  If your behind a
>>>>> router you may need to forward the ports to a specific ip 
>>>>> address.  I've
>>>>> got it working on window 2000. But still looking at getting it 
>>>>> working
>>>>> on my laptop.  If you run *tail +f /var/log/messages *as root* *it 
>>>>> will
>>>>> give you a realtime logging and any connections/dropped blocked.  I
>>>>> think that would be a good place to start.
>>>>>
>>>>> Are you behind a router incidently?
>>>>>
>>>>> Regards
>>>>> Kevin
>>>>>
>>>>> Craig Donnelly wrote:
>>>>>
>>>>  
>>>>
>>>>>> >
>>>>>> > Hello,
>>>>>> >
>>>>>> > Im hoping someone can help me out.  I have a VPN client that I 
>>>>>> need to
>>>>>> > get
>>>>>> > running through GuardDog.
>>>>>> > Its compiled and running on Fedora FC4.  When I disable the 
>>>>>> firewall, it
>>>>>> > works fine, but not so when enabled
>>>>>> > thus ruling out an router/modem issues.  I followed the cisco 
>>>>>> docs which
>>>>>> > state the following ports need to be enabled
>>>>>> > for the client to communicate:
>>>>>> >
>>>>>> > The CISCO documentation mentions several other ports, quoting:
>>>>>> >    * UDP port 500
>>>>>> >    * UDP port 10000 (or any other port number being used for 
>>>>>> IPSec/UDP)
>>>>>> >    * IP protocol 50 (ESP)
>>>>>> >    * TCP port configured for IPSec/TCP
>>>>>> >    * NAT-T port 4500
>>>>>> >
>>>>>> > I have created 3 user defined protocols:
>>>>>> >    - 500 (UDP bidirectional)
>>>>>> >    - 10000 (UDP bidirectional)
>>>>>> >    - 4500 (UDP bidirectional)
>>>>>> >
>>>>>> > An enabled these on local & internet zones.  I have also 
>>>>>> enabled ESP on
>>>>>> > these two zones.
>>>>>> > Still I cannot get it to allow the communication through.
>>>>>> >
>>>>>> > If anyone can help it would be very much appreciated.
>>>>>> >
>>>>>> > Regards,
>>>>>> > Craig
>>>>>> >
>>>>>> >
>>>>>> >
>>>>>> > -------------------------------------------------------
>>>>>> > SF.Net email is Sponsored by the Better Software Conference & EXPO
>>>>>> > September 19-22, 2005 * San Francisco, CA * Development Lifecycle
>>>>>> > Practices
>>>>>> > Agile & Plan-Driven Development * Managing Projects & Teams * 
>>>>>> Testing
>>>>>> > & QA
>>>>>> > Security * Process Improvement & Measurement *
>>>>>
>>>>>
>>>>>
>>>>>   
>>>>
>>>>
>>>>
>>> http://www.sqe.com/bsce5sf
>>>
>>>>>> > _______________________________________________
>>>>>> > Guarddog-user mailing list
>>>>>> > [email protected]
>>>>>> > https://lists.sourceforge.net/lists/listinfo/guarddog-user
>>>>>> >
>>>>>> >
>>>>>
>>>>>
>>>>>
>>>>>  
>>>>>
>>>>>
>>>>> -------------------------------------------------------
>>>>> SF.Net email is Sponsored by the Better Software Conference & EXPO
>>>>> September 19-22, 2005 * San Francisco, CA * Development Lifecycle
>>>>
>>>>
>>>>
>>>>  
>>>>
>>> Practices
>>>
>>>>> Agile & Plan-Driven Development * Managing Projects & Teams * 
>>>>> Testing & QA
>>>>> Security * Process Improvement & Measurement * 
>>>>> http://www.sqe.com/bsce5sf
>>>>> _______________________________________________
>>>>> Guarddog-user mailing list
>>>>> [email protected]
>>>>> https://lists.sourceforge.net/lists/listinfo/guarddog-user
>>>>>
>>>>>
>>>>  
>>>>
>>>
>>
>>
>
>
>



-------------------------------------------------------
SF.Net email is Sponsored by the Better Software Conference & EXPO
September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices
Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA
Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.