Firewall blocking connexions via IPSec

Post your questions about SoftEther VPN software here. Please answer questions if you can afford.
Post Reply
joshYarnspinner
Posts: 11
Joined: Mon Aug 24, 2015 2:24 pm

Firewall blocking connexions via IPSec

Post by joshYarnspinner » Thu Aug 27, 2015 9:49 am

...
Last edited by joshYarnspinner on Fri Jan 20, 2017 9:18 pm, edited 2 times in total.

joshYarnspinner
Posts: 11
Joined: Mon Aug 24, 2015 2:24 pm

Re: Firewall blocking connexions via IPSec

Post by joshYarnspinner » Fri Aug 28, 2015 8:17 am

Anyone?

jdubjr
Posts: 5
Joined: Fri Aug 28, 2015 8:20 pm

Re: Firewall blocking connexions via IPSec

Post by jdubjr » Fri Aug 28, 2015 8:30 pm

On the firewall, your port numbers look ok except for one. Double check they are the correct protocol too.

UDP - 500
UDP - 4500
TCP - 443
TCP - 992
TCP - 1194
TCP - 5555

Your symptoms sound like ports 500 and 4500 are not UDP.

joshYarnspinner
Posts: 11
Joined: Mon Aug 24, 2015 2:24 pm

Re: Firewall blocking connexions via IPSec

Post by joshYarnspinner » Fri Aug 28, 2015 10:29 pm

jdubjr wrote:
> On the firewall, your port numbers look ok except for one. Double check
> they are the correct protocol too.
>
> UDP - 500
> UDP - 4500
> TCP - 443
> TCP - 992
> TCP - 1194
> TCP - 5555
>
> Your symptoms sound like ports 500 and 4500 are not UDP.
They are all TCP/UDP

jdubjr
Posts: 5
Joined: Fri Aug 28, 2015 8:20 pm

Re: Firewall blocking connexions via IPSec

Post by jdubjr » Sat Aug 29, 2015 1:20 am

Have you tried setting the RPi as the DMZ host in your Super Hub 2?

jdubjr
Posts: 5
Joined: Fri Aug 28, 2015 8:20 pm

Re: Firewall blocking connexions via IPSec

Post by jdubjr » Sat Aug 29, 2015 1:45 am

One difference I see between your config and mine is I have:

bool L2TP_Raw false

I'm pretty sure you don't want that set to true. That would be an unencrypted connection.

joshYarnspinner
Posts: 11
Joined: Mon Aug 24, 2015 2:24 pm

Re: Firewall blocking connexions via IPSec

Post by joshYarnspinner » Sat Aug 29, 2015 7:20 am

jdubjr wrote:
> Have you tried setting the RPi as the DMZ host in your Super Hub 2?
Yes. Didn't work. Also the L2TP thing has been changed I don't think it affects whether I'm able to connect.

joshYarnspinner
Posts: 11
Joined: Mon Aug 24, 2015 2:24 pm

Re: Firewall blocking connexions via IPSec

Post by joshYarnspinner » Sun Aug 30, 2015 4:27 pm

Any other suggestions? I've checked and made sure all the ports are forwarded etc... also disabled the L2TP thing.

jdubjr
Posts: 5
Joined: Fri Aug 28, 2015 8:20 pm

Re: Firewall blocking connexions via IPSec

Post by jdubjr » Mon Aug 31, 2015 1:08 am

Any clues in the packet logs on the VPN server? If not, I would do a wireshark capture next.

jdubjr
Posts: 5
Joined: Fri Aug 28, 2015 8:20 pm

Re: Firewall blocking connexions via IPSec

Post by jdubjr » Mon Aug 31, 2015 7:31 pm


joshYarnspinner
Posts: 11
Joined: Mon Aug 24, 2015 2:24 pm

Re: Firewall blocking connexions via IPSec

Post by joshYarnspinner » Mon Aug 31, 2015 7:39 pm

jdubjr wrote:
> Seen this tutorial?
>
>
> http://tomearp.blogspot.com/2013/11/set ... ether.html

Yes, I followed it to set up the Pi. I'm attempting to get the logs out right now but I am not sure which ones to take out.

thisjun
Posts: 2458
Joined: Mon Feb 24, 2014 11:03 am

Re: Firewall blocking connexions via IPSec

Post by thisjun » Thu Sep 10, 2015 7:46 am

Please show a log around connecting time.

joshYarnspinner
Posts: 11
Joined: Mon Aug 24, 2015 2:24 pm

Re: Firewall blocking connexions via IPSec

Post by joshYarnspinner » Sat Sep 26, 2015 3:53 pm

...
Last edited by joshYarnspinner on Fri Jan 20, 2017 9:18 pm, edited 1 time in total.

thisjun
Posts: 2458
Joined: Mon Feb 24, 2014 11:03 am

Re: Firewall blocking connexions via IPSec

Post by thisjun » Thu Oct 08, 2015 8:27 am

In the log, user name "temporary_session" is used for auth.
Is it correct? Is there the user name on a RADIUS?

Post Reply