ESP packets dropped



We're using a Windows Server 2003 machine as the firewall for our
office network. I have not configured the firewall with any outbound
filters. However, by using Ethereal to capture packets on both sides
of the firewall, I can see that ESP packets that are not tunneled are
being dropped. Does anyone know why this might happen?

If the ESP packets are tunneled through UDP or TCP, then they are not
dropped.

I discovered this after having some trouble accessing network
resources on a remote network from a machine on our office network
after connecting to the remote network using a Cisco VPN client.

I don't have any problems if I use a different firewall. For example,
I don't have any problems using a simple 8-port Netgear NAT router/
firewall.

Thanks,
Seamus

.



Relevant Pages

  • RE: can ping but not browse
    ... I have stopped the firewall. ... # are safed from all (security) hazards. ... firewall/bastion host to the internet ... # internet and to an internal network, ...
    (Fedora)
  • Re: Why not use NETBEUI on Windows XP ??
    ... Trusted zones means that firewall rules will be bypassed for any or certain ... not count on netbeui being a defense for such as long as smb connectivity ... while the connection is open. ... > Microsoft Networking components on my network. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Why not use NETBEUI on Windows XP ??
    ... Trusted zones means that firewall rules will be bypassed for any or certain ... not count on netbeui being a defense for such as long as smb connectivity ... while the connection is open. ... > Microsoft Networking components on my network. ...
    (microsoft.public.win2000.networking)
  • Re: Simple Printer Sharing/Networking Question
    ... And all 3 desktop computers are running Windows XP Pro ... We have turned on sharing for the network printers (in association with this ... caused by 1) a misconfigured firewall or overlooked firewall (including ...
    (microsoft.public.windowsxp.network_web)
  • Re: Firewall for broadband connection
    ... A personal firewall application that runs on your computer will often be ... it clearly needs user intervention to apply updates. ... IP address, then VNC is a simple way to do ... I install VNC, even in a protected network, I always change the port ...
    (comp.security.firewalls)