Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Nortel VPN Client access issue through PIX

Status
Not open for further replies.

shakamon

MIS
Feb 4, 2002
103
0
0
US
I am trying to access a customers network via the Nortel VPN client (ver eac2622dd.exe ) . The system trying to access customer network is in DMZ behind firewall, w/ static IP xlated to a valid outside IP, in which the customer has allowed.
The customer sees us hit their Contivity switch, but I seem to be getting an error when I connect. I am getting a message box with the following;

‘Bannersock: The attempt to connect timed out without establishing a connection.’

If I cancel this box or wait long enough a new message box appears saying the connection has been established. A couple of times I have gotten up the connection status window, which I have attached. However after a couple of minutes I get the old error after the client says it is trying to retrieve banner text;

‘The secure Extranet connection has been lost. Click continue to re-establish the connection.’

Is there a specific port I have to open, is my PIX dropping this? Is IPSec having issues...I am stuck.....



Shakamon
"Only the dead fish follow the stream"
 
You'll probably need to enable IPSec over TCP/UDP, then set a TCP/UDP port to be used on the Central VPN device end. This port will then need to be allowed thru the Firewall as the IPSec traffic will run on it (i.e. UDP 599 ?)

 
I allowed UDP 1455 from between the VPN and my systems on my firewall, is that what you are telling me to do?
Does the customer have to open anything up on his end? Shakamon
"Only the dead fish follow the stream"
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top