Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Unexpected Payload on Symantec VPN

Status
Not open for further replies.

nyshawty

IS-IT--Management
Aug 28, 2002
2
US
hey folks,

i'm fairly new to the firewall and vpn world, so i need some serious help. we have a Symantec Firewall/VPN 200R appliance, and the firewall component is great. i am, however, having a serious problem setting up the client-to-site VPN. I installed the appropriate Symantec Enterprise VPN Client 7.0 software and the 7.01 update.

all of the settings are exactly the same on both ends of the tunnel. Everytime that I try to connect, i receive an error -3366 stating that i can't connect because of an "unexpected payload received upon request."

i have looked all over symantec's site for some answer to this dilemma, but i can't find anything.

any help that you folks can offer would be great.

thanks.
 
Hi I have installed working versions of VPN Client 7.0.1 (I actually use the 3DES version but not in the tunnel to the VPN 200R.
You need to ensure that the latest firmware is in the 200R
Then on the 200R
In VPN Dynamic Key Set up the SA for say Remote Users to:
Aggressive Mode, encryption to ESP DES MD5
SA lifetime to 480
Enable PFS
Local Security Gateway to IP Address no Phase 1 ID
Remote Security Gateway
Address 0.0.0.0
ID Type Distinguished name everything else blank
(except I like to enable NETBIOS Broadcast)
Save that info
Then in Client Identity
Set up a user name and a 20 character Pre share key
(and enable!!)
Now on the PC running VPN Client 7.01
Set up a security gateway with the external ip address of the VPN200R, the shared secret
and the Client id (thats the same as the user name above)
On the advanced tab set the IKE policy to STRONG
Now create a tunnel for that security policy
I just specify the subnet ips in the form 192.168.xxx.0
with a mask of whatever the internal subnet is set to.
And of course set the VPN policy to STRONG
Save that
It works for me!



 
Hi,

Have the same error, can not connect to the vpn200R,

have been searching four days now, still not working !

Any idea ???
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top