Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Problem with scuremote and IKE pre-shared secrets ...

Status
Not open for further replies.

lejih

Technical User
Nov 27, 2001
2
CA
Hello,

I can't connect to my internal network with my securemote client.

My configuration is FW-1 / VPN-1 4.1 with SP5 (gateway and management) on an
AIX server.
I've installed the licence keys for the VPN and for the securemote clients
on the AIX server.
I've configured the gateway. On the workstation properties, VPN tab, I've
checked IKE, Valid Addresses (of interfaces) and exportable for securemote.
On the Edit for IKE, I've checked DES, CAST and 3DES - MD5 and SHA1,
pre-shared secret and Supports Aggresive Mode. Edit secrets ... nothing.
I've created a user for remote access. On the authentication tab, I've
selected Undefrined for the authentication scheme, and on the encryption
tab, I've selected IKE, specified my password, choosed encryption + data
integrity, MD5 and DES.
I've created a group remote-users and put my user in it

I've created the rule :
source : remote-users@any , destination : internal-network , services : any
, action : Client-Encrypt , Track : long

On the remote user side (a win2k workstation with SP2 behind a Nexland ISB
Pro 400 connected to an ADSL link), I've installed the securemote client 4.1
SP5 for win2K. I can create my site and download the topology. For that, I
need to enter my remote user name and password.
But when I trie to access to a server located in my internal network, I
cannot. On the securemote client, I can see that it tries to exchange the
keys with the firewall. I have the message 'Exchanging keys with firewall',
then I have the message 'Error: communication with site xxx.xxx.xxx.xxx has
failed'. Nothing appears on the logs.

What's the problem. Any idea.

Regards


 
Dear Lejih,

I seem to have a similar problem.

Trying to run Securemote client 4.1 on Windows 98, which is running under VMware on a Linux platform. Everything else feels like a real Win98 system, but in the case of connecting to a VPN-1 server I get the exact same behavior as you:

"But when I trie to access to a server located in my internal network, I cannot. On the securemote client, I can see that it tries to exchange the keys with the firewall. I have the message 'Exchanging keys with firewall', then I have the message 'Error: communication with site xxx.xxx.xxx.xxx has failed'. Nothing appears on the logs."

Any solutions found??

Best regards,
Nikob

 
Hello

I had the same problems. I takes me hours to solve. But it is very small MAIN setting. Go to the workstation properties general and check the Ip-Address. If its the internal firewall address change it to the external. Load the policy and think about, that you must reload the topology. Just delete the site on your securemote client and make an new one.

I hope it works after this havy procedure...

Best Regards

trhubble
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top