Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

vpn authentication problem with 9608

Status
Not open for further replies.

AlfonsoSF

Vendor
Mar 3, 2009
238
ES
Hi all.

I have a IPO 500 v2 (R11.1.1.00) behind a sonicwall tz400 at the office
The IPO lan2 is in a separate subnet. IPO gateway is the IPO subnet firewall interface IP (X4)

A 9608G at home directly to a router (not behind a firewall) (R6.8....)

If I connect home with the office with a site to site VPN, the phone registers and works.

Now I try to make the phone perform its own vpn

At the Sonicwal side I have:
VPN settings
enable VPN
unique Firewall identifier: name
At VPN Policies
WAN groupVPN is marked
Autentication method: IKE preshared key
Password: password (for testing)
At User / local users
User created: name: username (for testing)
Password: password (the same as psk for testing)
on-time password disabled
account lifetime : never expires
At groups
member of trusted users
At VPN acces
X4 subnet (the IPO subnet)


At the phone side
ADDR
IPv4 : 0.0.0.0
Call server: Lan2 IPO IP address.
Router: 0.0.0.0
mask: 0.0.0.0
VPN
VPN: enabled
VPN vendor : other
Gateway address Public IP at the office
external IP phone address = 0.0.0.0
external router = 0.0.0.0
external subnet mask = 0.0.0.0
xternal DNS server = 8.8.8.8
encapsulation = 4500-4500
Auth type = PSK with XAUTH
VPN User Type = Any
VPN user = username
Password type = Save in flash
user password = password
IKE id = unique firewall identifier in the sonicwall
Pre-Shared Key = password

Ike phase 1
IKE ID type = IPV4 addr
IKE xchg mode = Aggressive
IKE DH Group= 2
IKE Encryption Alg = 3DES
IKE Auth Alg = SHA-1
IKE config Mode = Enabled

Ike fase 2
IPsec PFS DH group = No PFS
IPsec Encryption Alg AES-128
IPsec Auth Alg = SHA-1

Protected network = X4 subnet in xxx.xxx.xxx.0/24 format
IKE over TCP = Never


Reboot the phone and....
the phone ask for the user name and show the one we configured. Accept
the phone asf for the password. we can accpt or tyupe again. Accept
And the phone ask for the name again.
Sometines shows a Auth error.

After a hundred o revissions I cant' find a mistake.

Any help

Thanks in advanced.


 
it has, but we are at the prior stage. Making the tunnel.

 
The first time the phone asks for the name and password it’s usually the tunnel username and password.

EG: Vpnphone1. Admin1234

This is used to login to the vpn tunnel

The second time it asks for the username and password it’s usually the extension users login number and password

EG: 4000. 123456789

This is used to login to the IPO as a user.


 
SonicWall - Wan GroupVPN
General Tab
IKE using Preshared Secret
WAN GroupVPN
password
Proposals Tab
Phase 1
Group 2
3DES
SHA1
28800
Phase 2
ESP
3DES
SHA1
28800
Advanced Tab
All unchecked
Default Gateway 0.0.0.0
Allow Unauthenticated VPN Client Access LAN Subnets
Client Tab
Cache XAUTH User Name and Password on Client Never
Virtual Adapter Settings None
Allow Connections to Split Tunnels
All unchecked

9608 Phone
VPN Enabled
VPN Vendor Juniper/NetScreen
Gateway Address - Public IP
Auth Type PSK
IKE ID GroupVPN
PSK password
IDE ID KEY-ID
IKE Xchg Mode Aggressive
IDE SH Group 2
IDE Encryption Alg 3DES
IKE Auth Alg SHA-1
IKE Config Mode Disabled
Ipsec PFS SH Group No PFS
Ipsec Encryption Alg 3DES
ipsec Auth Alg SHA-1
Protected Network A.B.C.0/24
IKE Over TCP Auto

Set Call Server and File Server to internal address of IPO


 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top