Please Help : IPsec VPN Tunnel Established, but no Traffic

Please Help : IPsec VPN Tunnel Established, but no Traffic

NewsGroups | Search | Tools
 comp.dcom.vpn  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Please Help : IPsec VPN Tunnel Established, but no Traffic vkode78 04-01-2005
Posted by on April 1, 2005, 9:47 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


My Local Network
DSL -> Linksys BEFSR41 - SBS 2003 External Nic - SBS 2003 Internal Nic
( does DHCP for LAN) - Win XP workstation
I use ISA as Firewall

Remote VPN Server
Netscreen x25

My XP workstation is using Netscreen Remote to connect to the Netscreen
X25 . It is IPSec based.

Here is the Log:
14:35:48.218 Interface added: 192.168.16.23/255.255.255.0 on LAN
"Intel(R) PRO/100 VE Network Connection".
14:41:31.718
14:41:32.859 RequestLocalAddress failure: C24BF02
14:41:32.859 My Connections\company - Initiating IKE Phase 1 (IP
ADDR=12.36.191.2)
14:41:32.875 My Connections\company - SENDING>>>> ISAKMP OAK AG (SA,
KE, NON, ID, VID, VID, VID, VID)
14:41:32.953 My Connections\company - Received message from wrong IP
Address = c0a81002
14:41:36.953 My Connections\company - RECEIVED<<< ISAKMP OAK AG (SA,
VID, VID, KE, NON, ID, HASH, VID, NAT-D, NAT-D)
14:41:36.968 My Connections\company - Peer is NAT-T capable
14:41:36.968 My Connections\company - NAT is detected for Client
14:41:36.984 My Connections\company - SENDING>>>> ISAKMP OAK AG *(HASH,
NAT-D, NAT-D, NOTIFY:STATUS_INITIAL_CONTACT)
14:41:36.984 My Connections\company - Established IKE SA
14:41:36.984 MY COOKIE b2 1d 72 d4 f5 f2 2d 7b
14:41:36.984 HIS COOKIE d4 15 80 df 2 3f 1a d1
14:41:37.000 My Connections\company - Initiating IKE Phase 2 with
Client IDs (message id: BA73E63A)
14:41:37.000 Initiator = IP ADDR=192.168.16.23, prot = 0 port = 0
14:41:37.000 Responder = IP SUBNET/MASK=10.10.1.0/255.255.255.0, prot
= 0 port = 0
14:41:37.000 My Connections\company - SENDING>>>> ISAKMP OAK QM *(HASH,
SA, NON, KE, ID, ID)
14:41:37.062 My Connections\company - RECEIVED<<< ISAKMP OAK QM *(HASH,
SA, NON, KE, ID, ID, NAT-OA, NOTIFY:STATUS_RESP_LIFETIME)
14:41:37.062 My Connections\company - SENDING>>>> ISAKMP OAK QM *(HASH)
14:41:37.078 My Connections\company - Loading IPSec SA (Message ID =
BA73E63A OUTBOUND SPI = D2961D8E INBOUND SPI = 7CA77B9B)
14:41:37.078
14:41:37.109 My Connections\company - RECEIVED<<< ISAKMP OAK INFO
*(HASH, DEL)

So, it looks like the tunnel is established. But I can not ping the
remote network clients or access the SQL server that I want to connect
to.

Looks like I am connected But NO traffic.
I looked in the Linksys router logs
It has outbound logs for UDP 500 and nothing else.
I have enabled IPsec Pass Through on the server.

Do anyone of you know if Netscreen is NAT-T ? Because I would think I
should see Traffic on UDP port 4500 ( encapsulating ESP IP 50 over UDP
ports)

I am stumped as to why there is no traffic. That is what the Admin on
the remote site, he sees the Tunnel established but no traffic.

1) Could it be that the Router is not really doing IPsec Pass Through?

2)Even if the router doesnt do IP pass Through, I would think if the
VPN router and VPN client both support NAT-T, that should be fine right
? Then I should see UDP traffic on port 4500?

I would appreciat it if someone would post any suggestions on how to
troubleshoot this. I could try to take the Linksys router out and
connect the External NIC of SBS to DSL Modem directly but its a pain to
change the settings back and forth, and I want to do it only if that
will solve the issue.

Thanks for your help
KOde



Similar ThreadsPosted
Can establish IPSec Tunnel but no traffic through it March 9, 2006, 5:52 pm
Tunnel established, but no ping February 25, 2006, 9:52 am
GRE traffic over PIX IPSEC VPN June 6, 2005, 5:55 pm
IPSec tunnel works to one concentrator, not another March 23, 2005, 2:57 pm
IPSec Tunnel strange problem March 22, 2006, 1:43 pm
cisco VPN ipsec tunnel virtual interface operation detail question July 28, 2006, 3:06 pm
forcing traffic over the vpn May 28, 2008, 11:52 pm
What traffic is pumped through the VPN? November 3, 2007, 7:03 pm
Route all traffic through Cisco VPN October 13, 2005, 6:25 pm
VPN clients catches ALL network traffic... February 28, 2005, 9:21 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map