republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » D-Link » DI-624 MS L2TP/IPSEC
Search Topic:
Uniqs:
1275
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Is this s good modem »
« d-link Dl-102 voip accelerator  
AuthorAll Replies

jacobinos

join:2005-07-06

 DI-624 MS L2TP/IPSEC

Hi did anybody get XP SP2 Microsoft L2TP/IPSEC VPN to work on A DI-624? I have all VPN pass thrus ON and all I get is error:792 security negotiation time out, which means that DI-624 is blocking udp 500 and protocol ID 50 & 51.
D-LINK say it should work. Any comments much appreciated.


funchords
Hello
Premium,MVM
join:2001-03-11
Washington, DC
Did you set it up in Advanced / Virtual Server?

jacobinos

join:2005-07-06

reply to jacobinos
Yes I have, althought that setting is more relevant for a server on the LAN, and had even tried under DMZ.
It seems MS L2TP/IPSEC is not supported since it also uses protocol ID 51 'Authentication Header' which is not even set when the Virtual setting is enabled,but I just want to confirm if its so maybe someone did get it working after all.

THX


funchords
Hello
Premium,MVM
join:2001-03-11
Washington, DC
·Verizon Online DSL
·Skype

I have seen the firewall enable a protocol entry for me when I enabled the IPSec Virtual Server entry. It does the same for PPTP which uses Proto ID 47.

So you're inside the LAN trying to connect to a server on the WAN side? You should not need to open up a Virtual Server for that.

Here are some steps that might or might not help, I found these as advice for a Nortel IPSec tunnel:

Step 1 Open the Web Configuration Page

Step 2 Click on Advanced / Applications

Step 3 Check Enable

Step 4 Enter a name e.g. L2TP

Step 5 Enter 500 for Trigger Port (500 - 500)

Step 6 Select Both for Trigger Type

Step 7 Enter 500 for Public Port

Step 8 Select Both for Public Type

Step 9 Click Apply
--
Robb Topolski || http://www.funchords.com/ || Hillsboro, Oregon USA
The enemy of freedom is dependence.
Support this site - Get more features - Be a Member! - It's Free!

jacobinos

join:2005-07-06
Thank you for your tips, but setting the applications entry does not work either !!!

Bwuutje

join:2005-01-10

Question: Is the VPN server you are trying to connect to behind a NAT router too ?

If so, read this:
»www.computerworld.com/securityto···,00.html

Bwuutje.

jacobinos

join:2005-07-06
No its not, and without the DI-624 one can connect with L2TP/IPSEC for example with XP ICS.


funchords
Hello
Premium,MVM
join:2001-03-11
Washington, DC
Please confirm: You're inside the LAN trying to connect to a server on the WAN side?

jacobinos

join:2005-07-06

I confirm I am trying to connect from my LAN at home, to a VPN server at the office over the internet, I can connect using VPN PPTP with PPTP pass through enabled and nothing else, but cannot say the same for L2TP !!! Also would like to confirm if I get the DI-624 out of the picture and change my setup to use XP ICS, L2TP works fine.

Bwuutje

join:2005-01-10

"Also would like to confirm if I get the DI-624 out of the picture and change my setup to use XP ICS, L2TP works fine."

Just to confirm/clarify too....you exchanged the 624 by another XP ICS machine which NAT's (for) the machine you are trying to establish the VPN from ? Right ?

Bwuutje.

jacobinos

join:2005-07-06
Yes


funchords
Hello
Premium,MVM
join:2001-03-11
Washington, DC
·Verizon Online DSL
·Skype

reply to jacobinos
Then this should work all day long without any Virtual Servers or Firewall Rules. Maybe or maybe not just that "perhaps this might help" Nortel thing I gave you.

Sadly I don't know what to tell you -- it sounds like you've done this exactly right.
--
Robb Topolski || http://www.funchords.com/ || Hillsboro, Oregon USA
The enemy of freedom is dependence.
Support this site - Get more features - Be a Member! - It's Free!

jacobinos

join:2005-07-06
Well thanks I was curious if someone else had this same problem.

jacobinos

join:2005-07-06
I have solved the problem with L2TP/IPSEC VPN, no fault to the DI-624, had to open port 4500 1701 udb and 1701 TCP on office firewall Thanks for the help.


ozzy52

@swbell.ne

Was just reading through all that you know with the intent of lending a hand if I could. How may I ask do you suspect it worked from home when you used XP box in place of the DI-624 when the problem was a blocked port on the remote end? Does Windows XP have some magical power to punch through corporate firewalls? I don't get it.

jacobinos

join:2005-07-06

My short sightedness was that under XP I was using it on the gateway of the ICS and so it was going through the recommend ports I had already opened on the office firewall, but then when I tried under the DI-624 I was really behind an NAT and L2TP/IPSEC VPN needs the extra ports I mentioned to function properly, so no XP has no magical power to punch through corporate firewalls!!!
Forums » Equipment Support » Hardware By Brand » D-LinkIs this s good modem »
« d-link Dl-102 voip accelerator  


Saturday, 28-Nov 12:11:54 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [72] TiVo Sees Record Customer Losses
· [69] In-Flight Internet Headed For Bumpy Landing?
· [69] Verizon CEO: Hulu Will Be Dead Soon
· [62] Thanksgiving Open Thread
· [58] Weekend Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· [Vista] Why is HD So Full? [Microsoft Help]
· [Future9] Future9 status [VOIP Tech Chat]
· Is Gear Score now the new requirement to get pug invite? [World of Warcraft]
· Why does it take so long? Mail question [General Questions]
· Using DIR-615 C1/3.01 with Trendnet TEW-652BRP in N Mode [D-Link]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· Is Themida a legitimate threat? [Security]
· So we need a legitimate reason to use a lot of bandwidth? [TekSavvy]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]