Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Isakmp

hi

I have RTM and searched the forum and am still stumped... I am trying to IPSEC into the UTM 9.02 both from the same network and remotely and all VPN clients ( iPad, Android phone, apple macbook) all fail.  The firewall log says:

15:41:10 Default DROP ISAKMP x.x.x.x : 60200
→ 192.168.Y.Y : 500
len=504 ttl=43 tos=0x00 srcmac=c0:c1:c0:1b:1b:e6 dstmac=0:c:29:78:45:46

15:41:13 Default DROP ISAKMP x.x.x.x : 60200
→ 192.168.Y.Y : 500
len=504 ttl=43 tos=0x00 srcmac=c0:c1:c0:1b:1b:e6 dstmac=0:c:29:78:45:46

15:41:16 Default DROP ISAKMP x.x.x.x : 60200
→ 192.168.Y.Y : 500
len=504 ttl=43 tos=0x00 srcmac=c0:c1:c0:1b:1b:e6 dstmac=0:c:29:78:45:46

15:41:19 Default DROP ISAKMP x.x.x.x : 60200
→ 192.168.Y.Y : 500
len=504 ttl=43 tos=0x00 srcmac=c0:c1:c0:1b:1b:e6 dstmac=0:c:29:78:45:46

15:41:22 Default DROP ISAKMP x.x.x.x : 60200
→ 192.168.Y.Y : 500
len=504 ttl=43 tos=0x00 srcmac=c0:c1:c0:1b:1b:e6 dstmac=0:c:29:78:45:46

15:41:25 Default DROP ISAKMP x.x.x.x : 60200
→ 192.168.Y.Y : 500
len=504 ttl=43 tos=0x00 srcmac=c0:c1:c0:1b:1b:e6 dstmac=0:c:29:78:45:46

15:41:28 Default DROP ISAKMP x.x.x.x : 60200
→ 192.168.Y.Y : 500
len=504 ttl=43 tos=0x00 srcmac=c0:c1:c0:1b:1b:e6 dstmac=0:c:29:78:45:46



I have manually added a firewall rule to permit any port to :500 UDP once this started happening... no luck

I have toggled NAT-T under advanced
I have toggled IPSEC Traversal on the router that is between the UTM9 and the internet.

any help would be appreciated

thanks
dj


This thread was automatically locked due to age.
  • Hi, is the router doing NAT?

    Barry
  • Hi, dj, and welcome to the User BB!

    In my iPhone, the IPsec client is, in fact, a Cisco client that doesn't work with the IPsec Remote Access server. 

    Cheers - Bob
    PS If you search here, you will find that everyone recommends turning your wireless router into a wireless switch (WAN port unused, DHCP disabled) behind the UTM so that you can put the public IP on the External interface of the UTM.

    PPS I'm moving this thread to the VPN forum.

    Sorry for any short responses.  Posted from my iPhone.
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?