Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Unable to connect via VPN

Status
Not open for further replies.

hack12

IS-IT--Management
Dec 26, 2003
24
0
0
US
Hi, I am running the Netgear prosafe vpn client on my laptop which is behind a firewall. I am trying to access a remote site which is behind a netgear prosafe vpn firewall FWAG114 and I am unable to connect. Per the logs on the laptop it seems that I am getting past phase 1 however it fails on phase 2. Attached are the logs

3-01: 11:04:36.671
3-01: 11:04:36.671 My Connections\New Connection - Initiating IKE Phase 1 (IP ADDR=1.1.1.1)
3-01: 11:04:36.671 My Connections\New Connection - SENDING>>>> ISAKMP OAK MM (SA, VID 2x)
3-01: 11:04:36.718 My Connections\New Connection - RECEIVED<<< ISAKMP OAK MM (SA, VID)
3-01: 11:04:36.984 My Connections\New Connection - Peer is NAT-T draft-01 capable
3-01: 11:04:36.984 My Connections\New Connection - SENDING>>>> ISAKMP OAK MM (KE, NON, NAT-D 2x, VID 3x)
3-01: 11:04:37.406 My Connections\New Connection - RECEIVED<<< ISAKMP OAK MM (KE, NON, NAT-D 3x)
3-01: 11:04:37.406 My Connections\New Connection - NAT is detected for Client
3-01: 11:04:38.125 My Connections\New Connection - SENDING>>>> ISAKMP OAK MM *(ID, HASH, NOTIFY:STATUS_INITIAL_CONTACT)
3-01: 11:04:38.609 My Connections\New Connection - RECEIVED<<< ISAKMP OAK MM *(ID, HASH)
3-01: 11:04:38.609 My Connections\New Connection - Established IKE SA
3-01: 11:04:38.609 MY COOKIE dc 5d 9 30 a3 8e ff e0
3-01: 11:04:38.609 HIS COOKIE e5 93 7d 77 ca 56 f 75
3-01: 11:04:38.765 My Connections\New Connection - Initiating IKE Phase 2 with Client IDs (message id: 1C629C4F)
3-01: 11:04:38.765 Initiator = IP ADDR=10.10.10.10, prot = 0 port = 0
3-01: 11:04:38.765 Responder = IP ADDR=1.1.1.1, prot = 0 port = 0
3-01: 11:04:38.765 My Connections\New Connection - SENDING>>>> ISAKMP OAK QM *(HASH, SA, NON, ID 2x)

I have changed the ip addresses for security purposes. Could someone please help me. I have tried various computations but always the same result. I am just wondering why the protocol and port =0.

On the netgear fwag114 side I see the following message in the VPN status

[2007-03-01 08:05:27]<POLICY: XXX> PAYLOADS: HASH,SA,PROP,TRANS,NONCE,ID,ID

[2007-03-01 08:05:42]**** RECEIVED INFORMATIONAL EXCHANGE MESSAGE ****
 
I see from the log that NAT is detected. I assume it is trying to take some action to accomodate the NAT. I suggest testing with a direct non-NAT'ed connection and see if that works. If so you would then need to figure out what they are trying to do when NAT is detected.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top