Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Sonic Wall TZ100 Enhanced 5610 VPN Setup

Status
Not open for further replies.

TecTel

Vendor
Feb 22, 2003
91
0
0
US
Having a problem getting a VPN to work for a 5610. The IP office is an IP office 500 Version 2 with Release 6 software.
The Network side is a Sonic Wall TZ100 Enhanced.
I am using Tech Tip 190 to set up the phone and the Sonic Wall. The only setting I can't match up with on the phone is Password type. I can't set it for "Save in flash" it just shows N/A. I also don't see any info to set up Syslog Server on the phone.

The phone exchanges keys but doesn't get past Building VPN
3 Errors show on the phone
Ike Phase 2 no response

Ike Phase 1 recieved notify
Error code 3997698:18
Module Notify:305

Ike Phase 2 no response
Error Code 3997700:0
Module: IKMPO:353

Ike Phase 2 no response
Error code 399770:0
Module IKECFG:1184


Any help would be appreciated.
 
More info in the Main Network en Remote Network.

Also you might have a look here, the same error on IkePH1;


Avaya_Red.gif

___________________________________________
It works! Now if only I could remember what I did...

Dain Bramaged
___________________________________________
 
This is something I typed up a couple of months ago for the TZ100.

Sonicwall Settings
WAN Group VPN
General Tab
Authentication Method - IKE using Preshared Secret
Name - WAN GroupVPN
Shared Secret - 12345678910

Proposals Tab
DH Group - Group 2
Encryption - 3DES
Authentication - SHA1
Lifetime - 28800
Protocol - ESP
Encryption - 3DES
Authentication - SHA1
Check Enable Perfect Forward Secrecy
DH Group - Group2
Life Time - 28800

Advanced Tab
Allow Unauthenticated VPN Client Access - LAN Primary Subnet

Client Tab
Virtual Adapter settings - DHCP Lease or Manual Configuration
Allow Connections To - Split Tunnels


VPN Phone Settings
Server - Public IP Address of main firewall
IKE ID - GroupVPN
PSK - Pre Shared Secret in main firewall

IKE Parameters
IKE ID Type - FQDN
DH Group - 2
Encryption ALG - 3DES
Authentication ALG – SHA1
IKE Xchange Mode - Aggressive
IKE Config Mode - Disable
XAUTH - Disable
Cert Expiry Check - Disable
Cert DN Check - Disable

IPSEC Parameters
Encryption ALG - 3DES
Authentication ALG – SHA1
DH Group - 2

VPN Start Mode - On Demand
Password Type - NA
Encapsulation - 4500-4500
Syslog Server - Leave Blank
Protected Nets - Virtual IP – IP Phone IP Address
Remote Net#1 – Main office IP Scheme (i.e. 192.168.0.0/24)
Copy TOS - No
File Server -
QTest - Disabled
Connectivity Check - Always
 
Thanks for the info Gknight1. But unless I am missing something this is basically the same as the info in Tech Tip 190.

The only difference is you have 12345678910 instead of 1234567890 as the shared secret and you have VPN start mode as on demand instead of boot.

With the on demand the my ip phone doesn't even try to go to the VPN.

Is there something I should be looking at that I am missing?
 
Bas1234

Thanks for the info. Could you explain what you mean by

"More info in the Main Network en Remote Network
 
The ip range on both sites?
VPN licence?
Version?

Avaya_Red.gif

___________________________________________
It works! Now if only I could remember what I did...

Dain Bramaged
___________________________________________
 
The IP range at the Sonic Wall is 192.168.10.xxx

The IP phone is presently connected via DHCP with a 192.168.2.xxx address

Since this is a IP Office 500V2 no VPN license is needed. The system is 6.0 (14)
 
You do need a licence, but it's a normal
"Avaya IP Phones license"
So i guess you have one?

Avaya_Red.gif

___________________________________________
It works! Now if only I could remember what I did...

Dain Bramaged
___________________________________________
 
I forgot to mention the system has a VCM which provides the access for the IP phone
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top