Re: Cisco VPN Client through SBS2k3 - cann't connect

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi Daniel
Some time ago I had to configure a Zyxel vpn client through ISA 2k4
(outbound). To do so, I created a rule for UDP port 500 (IKE), UDP port 4500
(NAT-T) and port 50 (ESP). Please make be aware not to define a protocol
with port 50 (IP traffic). But after the definition of the rule I could
still not connect through ISA. I deleted the rule several times,
deactivated/activated it, restarted the ISA Firewall and last but not least
restarted the server...
Finally I changed the rank of the rule and all of a sudden the connection
worked! Probably this will help you as well ... (btw. there is no blocking
rule before the IPSEC-protocol-rule). Form time to time I have the same
behavior coming back after a reboot of the server. "Shacking the rules" than
helps me ...
I have no clue way this happens.

Good luck,
Simon


"Daniel" <Daniel@xxxxxxxxxxxxxxxxxxxxxxxxx> schrieb im Newsbeitrag
news:423FACDC-B901-43A3-82A2-10CF69753F2A@xxxxxxxxxxxxxxxx
> Hello,
>
> I'm having difficulties connecting a Cisco VPN Client 4.0.5 D using an
> XPsp2
> station in an SBS2k3 SP1 premium network with ISA2004. A profile was
> imported
> for the VPN and it's using IPSEC, UDP port=500, protocol number=50.
> The error message I'm getting is: "Secure VPN connection terminated
> locally
> by the client. Reason 412. The remote Peer is no longer responding."
> XPsp2 firewall allows UDP port 500, and ISA 2004 firewall rule was created
> for this port.
> Your input is much appreciated.
> Daniel


.



Relevant Pages

  • Re: Nortel VPN Client
    ... so that one VPN client can get through. ... > Bottom line in our case was that the other party did not support NAT-T ... > the only way to do that without ISA 2004. ... Port 10001 never shows up on the ISA logs. ...
    (microsoft.public.windows.server.sbs)
  • RE: Cisco vpn client behind ISA not working > vpn concentrator
    ... well if that was the problem, that your vpn client isn't a member of your ... > I'm trying to connect to a cisco VPN concentrator and opened port UDP, ... > ISA server en configures the ISA as default gateway. ... Must this desktop be a member if the domain? ...
    (microsoft.public.isa.vpn)
  • Nortel VPN Client
    ... I have a nortel VPN client trying to connect to a server in the outside ... Port 10001 never shows up on the ISA logs. ... from the PC, I found that port 500 was using the MSProxy protocol, ... My initial thought is to have ISA ...
    (microsoft.public.windows.server.sbs)
  • Re: Nortel VPN Client
    ... ISA can't "let anything from a program through", ... > I have a nortel VPN client trying to connect to a server in the outside ... Port 10001 never shows up on the ISA logs. ... > but when the VPN client switched to port 10001 the MSProxy protocol is ...
    (microsoft.public.windows.server.sbs)
  • Re: sys/1386/i386/mptable.c rev 1.239 breaks boot.
    ... >> If a valid ELCR was found, consult it for the trigger mode of ISA ... ioapic0: intpin 1 bus ISA ... xl0: using port I/O ...
    (freebsd-current)