Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec Remote Access VPN to XGS

Hi,

I’m trying to test a vpn connection to an XGS.

I have the XGS connected to the DMZ of a UTM so I can test it. I have the UTM rules set to allow any port from the XSG to/from the UTM, and can ping the XGS's WAN port from my client machine on the UTM's LAN.

I understand that actually getting to local resources through the XGS will probably not work since my local UTM network is the same as the XGS (I’m eventually replacing one with the other). But since right now I’m just trying to get the connection established to the WAN side of the XGS, I didn’t think it mattered (maybe it does?).

I have an IPSec VPN (Remote Access) set up on the XGS. 

The Sophos VPN client returns “The IKE UDP Port seems to be blocked.”

I am unsure if it’s being blocked by my UTM or my XGS, or if it's just some other error and the Sophos client isn't sure what's wrong.

Ports 500 and 4500 are opened between the devices, and running
nc -vnuz [XGS_WAN_IP] 500 and 4500 from my client succeeds.
nc -vnuz [UTM_IP] 500 and 4500 also succeeds.

I’m not sure what, if anything is actually being blocked or what's doing the blocking.

While trying to initiate a connection, I get these results running tcpdump on my client, the UTM, and the XGS:

14:56:08.255010 IP [CLIENT_LAN_IP].101.62563 > [[XGS_WAN_IP].isakmp: isakmp: phase 1 I agg
14:56:08.757399 IP  [CLIENT_LAN_IP].62563 > [XGS_WAN_IP].isakmp: isakmp: phase 1 I agg
14:56:09.261241 IP  [CLIENT_LAN_IP].62563 > [XGS_WAN_IP].isakmp: isakmp: phase 1 I agg
14:56:10.336075 IP  [CLIENT_LAN_IP].58196 > [XGS_WAN_IP].isakmp: isakmp: phase 1 I ident
14:56:13.410039 IP  [CLIENT_LAN_IP].58196 > [XGS_WAN_IP].isakmp: isakmp: phase 1 I ident
14:56:19.486495 IP 1 [CLIENT_LAN_IP].58196 > [XGS_WAN_IP].isakmp: isakmp: phase 1 I ident

On the XGS, I get this message in the LogViewer:

messageid="18057" log_type="Event" log_component="IPSec" log_subtype="System" status="Expire" user="" con_name="" con_type="0" src_ip="" gw_ip="" local_network="" dst_ip="" remote_network="" additional_information="" message="IKE_SA timed out before it could be established"

After configuring the XGS, I’m exporting the configuration file and importing into the Sophos client. I try to open connection and get the "The IKE UDP Port seems to be blocked" error.

(I did also try L2TP since I've always has better luck with that on my UTM, but got the same result.)

Thanks!

Jeff



This thread was automatically locked due to age.
Parents
  • Hello Jeff,

    please show us edit screens of your port forwarding rules or the fw rules for opening those ports.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Phillip,

    Attached are the rules but I think I see the problem .-- though I'm not sure how to fix it.

    My XGS is on the DMZ, which is masqueraded to the Internet .. and that works: I can get online MyLaptop -->XGS_WAN_Interface-->UTM_DMZ_Interface|UTM_WAN_Interface-->Internet.

    The issue with testing the VPN is that since my laptop is on the UTM's LAN network, it's trying to go this way to connect to the VPN: MyLaptop -->UTM_LAN_Interface|UTM_DMZ_Interface-->XGS_WAN_Interface.

    But, if I put an ethernet switch between the UTM and the XGS, giving me a way to plug my laptop directly into the DMZ, the VPN Works!

    I'm not sure if this is because the XGS is only allowing traffic from the DMZ, not anything else connected to the DMZ, or if the UTM isn't properly translating my LAN traffic to/from the DMZ.

    I assuming trying to masquerade the DMZ on onto my LAN interface would be a bad thing, but maybe not?

    So, I don't know if the issue is with my UTM settings or my XGS settings.

    Thanks so much,

    Jeff

Reply
  • Hi Phillip,

    Attached are the rules but I think I see the problem .-- though I'm not sure how to fix it.

    My XGS is on the DMZ, which is masqueraded to the Internet .. and that works: I can get online MyLaptop -->XGS_WAN_Interface-->UTM_DMZ_Interface|UTM_WAN_Interface-->Internet.

    The issue with testing the VPN is that since my laptop is on the UTM's LAN network, it's trying to go this way to connect to the VPN: MyLaptop -->UTM_LAN_Interface|UTM_DMZ_Interface-->XGS_WAN_Interface.

    But, if I put an ethernet switch between the UTM and the XGS, giving me a way to plug my laptop directly into the DMZ, the VPN Works!

    I'm not sure if this is because the XGS is only allowing traffic from the DMZ, not anything else connected to the DMZ, or if the UTM isn't properly translating my LAN traffic to/from the DMZ.

    I assuming trying to masquerade the DMZ on onto my LAN interface would be a bad thing, but maybe not?

    So, I don't know if the issue is with my UTM settings or my XGS settings.

    Thanks so much,

    Jeff

Children
  • Hello Jeff,

    I now understand that you are testing the VPN connection from inside the LAN, is this right?

    This normally delivers unwanted results, since the packets are not flowing in the direction they would flow when coming from outside.

    We normaly test these things like this: detach your laptop from any internal net(s) (LAN/WiFi) use a mobile phone as a hotspot and then connect your laptop to this "internet line" through that mobile hotspot. Et voilà: you are doing a valid test for your VPN setup, since you are going over a public net and come to the external interface of your firewall "from the right direction". Very helpful!

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • Yes, from inside my UTM LAN, but outside my XGS LAN. In a perfect world I'd have a separate internet connection with a half dozen "Additional Addresses" and create a tiny temporary network to make sure everything works and I set it up correctly. Alas, I need to test it piece-meal (get VPN working, then flip it around and hook up a few servers to the XGS to make sure I can see them from the "WAN" (in quotes because it's not really a WAN yet; the XGS just thinks the UTM's DMZ is the WAN). Thanks, Jeff

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?