Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Help setting up Contivity Control Tunnel for external access

Status
Not open for further replies.

mrgauth

Technical User
Jul 19, 2002
64
US
I have about 50+ 1010 Contivities that I need to be able to access via the web via a control tunnel. I have set up a Profile/user account with rights to manage the box, but when I attempt to use my Nortel client and come in via the web I always get 'remote host not responding'. Nortel support says it should work and that I must be using some kind of corporate firewall or something. That is not the case since there are no firewalls nor corporate network devices of any kind between my 1010 and the broadband modem connecting me to the internet. I see nothing that should be stopping them from accessing my 1010 via the ISP provided static IP address and setting up a user tunnel.

I do not use the 1010's firewall feature and everything in that area is out-of-the-box default settings.

Anyone get this to work? How?


Appreciate your help.
 
what software ver. got the 1010 run ?

What software ver. is the client you test with. ?

Is NAT traversel enable on the 1010 ?

What does the eventlog say ?
 
1010 is running 4_85.200
Client is the latest 5_01.110
NAT traversal to port 24063 is enabled under Services/IPSEC
This is a typical Event Log error:

04/21/2005 10:43:02 0 ISAKMP [02] Deleting ISAKMP SA with 161.235.195.220
04/21/2005 10:43:02 0 tIsakmp [34] Failed Login Attempt: Username=netsvc: Date/Time=04/21/2005 10:43:02
04/21/2005 10:43:02 0 ISAKMP [13] No proposal chosen in message from 161.235.195.220
04/21/2005 10:43:02 0 Security [01] Session: IPSEC[netsvc] netsvc netsvc has no active accounts
04/21/2005 10:43:02 0 Security [01] Session: IPSEC[netsvc] has no active sessions


I am clueless. Sad thing is, so is Nortel. Now where does that leave me?

Thanks.
 
How have you configured that control tunnel?

you need to be connected to be connected with the serial port to create an user control tunnel .

Although you can enable it with telnet afterwards

restrict on confirm

If that is done, enable or disable the keepalives on the contivity client....that got it running once at my company.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top