//flex table opened by JP

Click to See Complete Forum and Search --> : Company VPN stopped working with Router installation


Jimstep
12-14-2002, 01:09 PM
I installed a Dlink router to share a cable modem and now my company VPN will not connect. Is there something that I can look at on my end or is this something the company has to resolve?

BipolarBill
12-15-2002, 01:31 PM
Find out what ports the VPN connection is using (TCP and UDP) and enable port forwarding to your PC's IP in the setup for the router. You could also put your PC in the DMZ, but that would open it wide to attacks and necessitate a software firewall which would require you to open the very same ports anyway in the firewall setup.

Try port forwarding first.

Jimstep
12-15-2002, 07:31 PM
Thanks for the reply. I had called the Dlink support team and they told me that their DI604 router does not work with the Nortel VPN.

Since Dlink does not provide the support, I returned the product.

Again, thank for your help.:)

BipolarBill
12-15-2002, 10:49 PM
*sigh* :(

kwebb
12-16-2002, 07:56 AM
Contivity right? When buying my NAT router that was the single most important factor for me as I have to connect to our VPN and without hiccups. I ended up getting a Siemens Speedstream 2624 Router/AP combo. I wasn't too sure about it because I had never used a Siemens product but the place I bought it from had a decent return policy so I bought it. Has been a very good purchase. Works well with Contivity and the 5.5 dBi dipole on it gives me excellent wireless coverage. They of course have non-wireless SOHO routers so if you haven't already purchased a replacement that'd be one to look at if you are shopping at a circuit city or other electronics mega-store.

AllGamer
12-16-2002, 08:46 AM
Originally posted by Jimstep
Thanks for the reply. I had called the Dlink support team and they told me that their DI604 router does not work with the Nortel VPN.

Since Dlink does not provide the support, I returned the product.

Again, thank for your help.:)

That's BS, all router works with VPN software

You just need to know how to configure it

DLink tech supp sucks, they didn't even bother to help you out

good choice on returning it

by the way i use Nortel too, and it works just fine for me

port forwarding, and passive, and other stuff you need to set on both the Nortel Software and the Router itself, then it all works happily

:t

Logan[TeamX]
12-16-2002, 09:02 AM
I'd say Linksys, as their products are quite excellent in every regard, but after checking my documentation, my router (BEFSR11) only supports one VPN session at a time.

I've been configuring a Watchguard Firebox 700 for our office over the last week. So far, it's a welcome breath of fresh air. All I have left to do at lunch is to set-up the POP3 and SMTP proxies, and we're totally thru the Firebox for external communications.

Check out www.watchguard.com for more information. As a business, you'll need something that can meet your needs. I think you might find the Watchguard products to be appealing.

Logan

EDIT - going here (http://www.watchguard.com/products/fbcompare.asp) will give you a quick rundown on their current products, and features of each.

AllGamer
12-16-2002, 09:27 AM
Any and Every Router that you use Will ONLY work with 1 session at a time when it comes to Port forwarding

else they'll have to rename that to port Broadcasting instead ;)

Logan[TeamX]
12-16-2002, 09:29 AM
Ok AG, now I'm confused. Why then can I host my Counter-Strike server and allow up to 12 players in from the Internet at one time, over one port forwarding allotment?

AllGamer
12-16-2002, 09:34 AM
That's cuz you Only need 1 for yourself

the Joiners, don't need it on your side, but they do need it in their own homes

:t

DVNT1
12-17-2002, 10:17 AM
Originally posted by AllGamer
That's BS, all router works with VPN software

You just need to know how to configure it...
Allgamer, what you said seems to be BS to me.

NAT isn't support in all VPN implementations.

NAT often breaks IKE & IPSEC beause it is not currently covered in the standards. There are proposed drafts to help with this situation.

http://www.ietf.org/internet-drafts/draft-ietf-ipsec-udp-encaps-03.txt
http://www.ietf.org/internet-drafts/draft-ietf-ipsec-nat-t-ike-03.txt

Port forwarding generally has nothing to with being a VPN client. It does affect the VPN server if you are doing NAT instead of directly giving it a public IP address.



Counterstrike related:
Originally posted by AllGamer
Any and Every Router that you use Will ONLY work with 1 session at a time when it comes to Port forwarding
Incorrect too. All 12 Internet players used the same port mapping to access your CS host.


I don't come to Sysopt.com very often but you can always find me at TechIMO.com (http://www.techimo.com/forum/index.html) if you would like more help from me sooner.