Re: NAT-T question...

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: John Smith (na_at_na.com)
Date: 11/25/04


Date: Thu, 25 Nov 2004 15:06:21 -0700

hum very interesting that this is no longer recommended.. but for now I
still need to do it..

I made the reg change and rebooted and now when I try to connect very
quickly it says "Error 651: The modem (or other connecting device) has
reported an error"

Is there a way to find what his error is? I looked in the even log and other
places but couldn't see anything. Everything is happening much faster now,
like the error comes up in a few seconds. I also can see UDP 500 and 4500
packets going both ways from the firewall. Right now 5 UDP 500 ISAKMP
packets followed by 6 4500 ESP and 2 more 500s for every time I try to
connect.

"Jorge Coronel" <jcoronel@online.microsoft.com> wrote in message
news:u4Tdvco0EHA.3908@TK2MSFTNGP12.phx.gbl...
> That deploymen is not longer recomended by MS; in order to make it work
> you'll need to check the following KB...
>
> 885407 The default behavior of IPSec NAT traversal (NAT-T) is changed in
> Windows XP Service Pack 2
>
> This will tell you what is the regkey you'll need to add to your XP box in
> order to initiate to a server that is behind a NAT
> I hope this helps
> JC
>
>
>
> "John Smith" <na@na.com> wrote in message
> news:eq9lkUa0EHA.1392@TK2MSFTNGP14.phx.gbl...
>>I have RAS up and running on a win2003 server, and have LT2P and IPSEC
>>running with certificates I have tested this directly and can connect. I
>>am now trying to connect over NAT-T from a XPSP2 client and it's not
>>working here is what I've done.
>>
>>
>>
>> I have tried connecting from both of the below:
>>
>> [client with public IP] -> [internet] -> [NAT/FW] -> [server] [client
>> with private IP] -> [NAT] -> [internet] -> [NAT/FW] -> [server]
>>
>> I have also checked my firewall and all ports needed are open and I see
>> traffic going to and from the IP of the client on ports 500 and 4500.
>> Everything seams right but after about 40sec of the client connecting I
>> get an error of "Error 678 the remote computer did not respond" Does
>> anyone have any ideas or how I troubleshoot it farther?
>>
>>
>>
>> Thanks
>>
>>
>
>



Relevant Pages

  • Re: Easy RRAS VPN question
    ... When NAT-T is used port 1701 UDP ... to go through a firewall directly then port 1701 UDP needs to be open. ... >> accessed from the internet. ...
    (microsoft.public.windows.server.networking)
  • Re: bind() udp behavior 2.6.8.1
    ... Allowing a high numbered udp port to remain ... The firewall should allow traffic from the same ip:port to the other ... ip:port and from no other server on the net. ... You new session is totally ...
    (Linux-Kernel)
  • Re: Keyboard Maestro Calling Home... how to stop?
    ... ports like 22 to my ISP, 80, and 443 so it sends the UDP broadcast ... A tutorial on writing firewall rules is really beyond the ... add deny log ip from any to 127.0.0.0/8 ... look in the log and see what port ...
    (comp.sys.mac.apps)
  • Re: IP address spoofing
    ... >These are mostly UDP packets being dropped. ... You don't need a firewall to stop ... bandwidth' over the wire, there really isn't that much you can do ... If you are lucky, your ISP might be ...
    (comp.security.firewalls)
  • Re: How can I make the server to call back to client without being blocked by firewall.
    ... Her post says the UDP will always be blocked by firewall. ... Since UDP can also be in connection mode even ... > Texas Imperial Software | Try WFTPD, the Windows FTP Server. ...
    (comp.security.firewalls)