Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec Remote Access VPN to XGS

Hi,

I’m trying to test a vpn connection to an XGS.

I have the XGS connected to the DMZ of a UTM so I can test it. I have the UTM rules set to allow any port from the XSG to/from the UTM, and can ping the XGS's WAN port from my client machine on the UTM's LAN.

I understand that actually getting to local resources through the XGS will probably not work since my local UTM network is the same as the XGS (I’m eventually replacing one with the other). But since right now I’m just trying to get the connection established to the WAN side of the XGS, I didn’t think it mattered (maybe it does?).

I have an IPSec VPN (Remote Access) set up on the XGS. 

The Sophos VPN client returns “The IKE UDP Port seems to be blocked.”

I am unsure if it’s being blocked by my UTM or my XGS, or if it's just some other error and the Sophos client isn't sure what's wrong.

Ports 500 and 4500 are opened between the devices, and running
nc -vnuz [XGS_WAN_IP] 500 and 4500 from my client succeeds.
nc -vnuz [UTM_IP] 500 and 4500 also succeeds.

I’m not sure what, if anything is actually being blocked or what's doing the blocking.

While trying to initiate a connection, I get these results running tcpdump on my client, the UTM, and the XGS:

14:56:08.255010 IP [CLIENT_LAN_IP].101.62563 > [[XGS_WAN_IP].isakmp: isakmp: phase 1 I agg
14:56:08.757399 IP  [CLIENT_LAN_IP].62563 > [XGS_WAN_IP].isakmp: isakmp: phase 1 I agg
14:56:09.261241 IP  [CLIENT_LAN_IP].62563 > [XGS_WAN_IP].isakmp: isakmp: phase 1 I agg
14:56:10.336075 IP  [CLIENT_LAN_IP].58196 > [XGS_WAN_IP].isakmp: isakmp: phase 1 I ident
14:56:13.410039 IP  [CLIENT_LAN_IP].58196 > [XGS_WAN_IP].isakmp: isakmp: phase 1 I ident
14:56:19.486495 IP 1 [CLIENT_LAN_IP].58196 > [XGS_WAN_IP].isakmp: isakmp: phase 1 I ident

On the XGS, I get this message in the LogViewer:

messageid="18057" log_type="Event" log_component="IPSec" log_subtype="System" status="Expire" user="" con_name="" con_type="0" src_ip="" gw_ip="" local_network="" dst_ip="" remote_network="" additional_information="" message="IKE_SA timed out before it could be established"

After configuring the XGS, I’m exporting the configuration file and importing into the Sophos client. I try to open connection and get the "The IKE UDP Port seems to be blocked" error.

(I did also try L2TP since I've always has better luck with that on my UTM, but got the same result.)

Thanks!

Jeff



This thread was automatically locked due to age.
Parents
  • Hi JeffCooper

    May I know if the user was able to connect IPSec VPN (remote access) and stopped working? and now getting an error message as  “The IKE UDP Port seems to be blocked.”?

    Thanks and Regards

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Got it to work. Think it has to do with being on my UTM's LAN and connecting to the XGS on the DMZ. When I put my computer on the DMZ it works. Maybe it has something to do with douible-NAT (which I never completely under stood since all connections from remote users run through at least two routers yet somehow work).

Reply
  • Got it to work. Think it has to do with being on my UTM's LAN and connecting to the XGS on the DMZ. When I put my computer on the DMZ it works. Maybe it has something to do with douible-NAT (which I never completely under stood since all connections from remote users run through at least two routers yet somehow work).

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?