Networking Forums  

Go Back   Networking Forums > Networking Newsgroups > Broadband Hardware

VPN lost connection even after Persistent port forwarding win XP

Reply
 
Thread Tools Display Modes
  #1  
Old 08-02-2004, 07:29 PM
Default VPN lost connection even after Persistent port forwarding win XP



I have a MN-700 router and DSL service from SBC Yahoo
with a Dynamic IP, I use win XP.

I have updated the latest FW and SW from the MS web site
posted in July 2003.

My problems persist before and after the updates:

I enabled persistent port forwarding in the router for
the ports (500 and 2200-2300 ) my Nortel VPN client needs
over UDP.

When I try to connect, the VPN client is able to
authenticate and connect but then immediately (in less
than 30 seconds) times out while trying to get Banner
text (the message is, "Getting Banner Text from server").

Any tips on what might be wrong here?

I am able to connect only when I enable DMZ over a
particular host, however I feel I am compromising
security by enabling DMZ, more over I often have to
connect multiple clients and DMZ allows only one client
at a time to be on DMZ.



UD
Reply With Quote
  #2  
Old 08-02-2004, 08:22 PM
lilo
Guest
 
Posts: n/a
Default VPN lost connection even after Persistent port forwarding win XP

It appears like one of the ports needed is not open.

Enable the DMZ again, run netstat -ano before and while
running the VPN, and compare which ports are open.

>-----Original Message-----
>I have a MN-700 router and DSL service from SBC Yahoo
>with a Dynamic IP, I use win XP.
>
>I have updated the latest FW and SW from the MS web site
>posted in July 2003.
>
>My problems persist before and after the updates:
>
>I enabled persistent port forwarding in the router for
>the ports (500 and 2200-2300 ) my Nortel VPN client needs
>over UDP.
>
>When I try to connect, the VPN client is able to
>authenticate and connect but then immediately (in less
>than 30 seconds) times out while trying to get Banner
>text (the message is, "Getting Banner Text from server").
>
>Any tips on what might be wrong here?
>
>I am able to connect only when I enable DMZ over a
>particular host, however I feel I am compromising
>security by enabling DMZ, more over I often have to
>connect multiple clients and DMZ allows only one client
>at a time to be on DMZ.
>
>.
>

Reply With Quote
  #3  
Old 08-03-2004, 12:30 AM
joker
Guest
 
Posts: n/a
Default Re: VPN lost connection even after Persistent port forwarding winXP

Is the computer on a wireless connection to the MN-700?

If so what kind of wireless security are you using?

UD wrote:
> I have a MN-700 router and DSL service from SBC Yahoo
> with a Dynamic IP, I use win XP.
>
> I have updated the latest FW and SW from the MS web site
> posted in July 2003.
>
> My problems persist before and after the updates:
>
> I enabled persistent port forwarding in the router for
> the ports (500 and 2200-2300 ) my Nortel VPN client needs
> over UDP.
>
> When I try to connect, the VPN client is able to
> authenticate and connect but then immediately (in less
> than 30 seconds) times out while trying to get Banner
> text (the message is, "Getting Banner Text from server").
>
> Any tips on what might be wrong here?
>
> I am able to connect only when I enable DMZ over a
> particular host, however I feel I am compromising
> security by enabling DMZ, more over I often have to
> connect multiple clients and DMZ allows only one client
> at a time to be on DMZ.
>


Reply With Quote
  #4  
Old 08-03-2004, 01:00 AM
joker
Guest
 
Posts: n/a
Default Re: VPN lost connection even after Persistent port forwarding winXP

I also forgot you can't connect more then one client behind the MN-700
at the same time.

joker wrote:

> Is the computer on a wireless connection to the MN-700?
>
> If so what kind of wireless security are you using?
>
> UD wrote:
>
>> I have a MN-700 router and DSL service from SBC Yahoo with a Dynamic
>> IP, I use win XP.
>>
>> I have updated the latest FW and SW from the MS web site posted in
>> July 2003.
>>
>> My problems persist before and after the updates:
>>
>> I enabled persistent port forwarding in the router for the ports (500
>> and 2200-2300 ) my Nortel VPN client needs over UDP.
>> When I try to connect, the VPN client is able to authenticate and
>> connect but then immediately (in less than 30 seconds) times out while
>> trying to get Banner text (the message is, "Getting Banner Text from
>> server").
>> Any tips on what might be wrong here?
>> I am able to connect only when I enable DMZ over a particular host,
>> however I feel I am compromising security by enabling DMZ, more over I
>> often have to connect multiple clients and DMZ allows only one client
>> at a time to be on DMZ.
>>

>


Reply With Quote
  #5  
Old 08-04-2004, 07:24 AM
UD
Guest
 
Posts: n/a
Default VPN lost connection even after Persistent port forwarding win XP

Thanks Lilo, that worked!
Also with the help of "netstat -ano" I was able to change
from persistent to application triggered port forwarding.

Answer to the question from "Joker", I use both WEP and
MAC security on the wireless, however I am curious how
will that impact VPN connections?

UD
>-----Original Message-----
>It appears like one of the ports needed is not open.
>
>Enable the DMZ again, run netstat -ano before and while
>running the VPN, and compare which ports are open.
>
>>-----Original Message-----
>>I have a MN-700 router and DSL service from SBC Yahoo
>>with a Dynamic IP, I use win XP.
>>
>>I have updated the latest FW and SW from the MS web

site
>>posted in July 2003.
>>
>>My problems persist before and after the updates:
>>
>>I enabled persistent port forwarding in the router for
>>the ports (500 and 2200-2300 ) my Nortel VPN client

needs
>>over UDP.
>>
>>When I try to connect, the VPN client is able to
>>authenticate and connect but then immediately (in less
>>than 30 seconds) times out while trying to get Banner
>>text (the message is, "Getting Banner Text from

server").
>>
>>Any tips on what might be wrong here?
>>
>>I am able to connect only when I enable DMZ over a
>>particular host, however I feel I am compromising
>>security by enabling DMZ, more over I often have to
>>connect multiple clients and DMZ allows only one client
>>at a time to be on DMZ.
>>
>>.
>>

>.
>

Reply With Quote
  #6  
Old 08-04-2004, 09:42 AM
joker
Guest
 
Posts: n/a
Default Re: VPN lost connection even after Persistent port forwarding winXP

Because of problems with 802.1x authentication (which is enabled by
default with SP1) and some VPN connections when using wireless. I take
it that you are using a wired connection then. Because when using WEP
the MN-700 is not a 802.1x authentication server & that causes problems
for wireless VPN computers. (That is at least my understanding of VPN's
& 802.1x authentication.) Thus if you were using WEP & wireless I'd
recommend using WPA & enabling 802.1x authentication on the wireless
computers. Since you are using WEP you will need to do the VPN on a
wired connection. (Once again this is according to my understanding of
the technologies involved.)

UD wrote:
> Thanks Lilo, that worked!
> Also with the help of "netstat -ano" I was able to change
> from persistent to application triggered port forwarding.
>
> Answer to the question from "Joker", I use both WEP and
> MAC security on the wireless, however I am curious how
> will that impact VPN connections?
>
> UD
>
>>-----Original Message-----
>>It appears like one of the ports needed is not open.
>>
>>Enable the DMZ again, run netstat -ano before and while
>>running the VPN, and compare which ports are open.
>>
>>
>>>-----Original Message-----
>>>I have a MN-700 router and DSL service from SBC Yahoo
>>>with a Dynamic IP, I use win XP.
>>>
>>>I have updated the latest FW and SW from the MS web

>
> site
>
>>>posted in July 2003.
>>>
>>>My problems persist before and after the updates:
>>>
>>>I enabled persistent port forwarding in the router for
>>>the ports (500 and 2200-2300 ) my Nortel VPN client

>
> needs
>
>>>over UDP.
>>>
>>>When I try to connect, the VPN client is able to
>>>authenticate and connect but then immediately (in less
>>>than 30 seconds) times out while trying to get Banner
>>>text (the message is, "Getting Banner Text from

>
> server").
>
>>>Any tips on what might be wrong here?
>>>
>>>I am able to connect only when I enable DMZ over a
>>>particular host, however I feel I am compromising
>>>security by enabling DMZ, more over I often have to
>>>connect multiple clients and DMZ allows only one client
>>>at a time to be on DMZ.
>>>
>>>.
>>>

>>
>>.
>>


Reply With Quote
Reply

Tags
connection, forwarding, lost, persistent, port, vpn, win

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 11:44 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.