|
Home > Archive > VPN > September 2004 > Netgear FVS318 and ActionTec 701-wg
You are viewing an archived Text-only version of the thread.
To view this thread in it's original format and/or if you want to reply to
this thread please [click here]
| Author |
Netgear FVS318 and ActionTec 701-wg
|
|
|
| I am trying to figure which ports to open on the actiontec modem to allow
vpn passthru. My modem is running Qwest firmware and doesn't have a radio
button to turn vpn passthru on. And does anyone know on the Netgear FVS318
can two of them establish a vpn connection if one is running firmware 2.3
and the other 2.4
Thanks
| |
|
| i had a vpn connection with 2x FVS318 where one was on 2.4 and the other 2.3
firmware (it seemed to work) - this was only for a half day or so while I
upgraded all units to version 2.4. It's probably better to run all units at
the same/latest firmware level.
"Steve" <mcp5@qwest.net> wrote in message
news:MwL1d.44$l_4.63959@news.uswest.net...
> I am trying to figure which ports to open on the actiontec modem to allow
> vpn passthru. My modem is running Qwest firmware and doesn't have a radio
> button to turn vpn passthru on. And does anyone know on the Netgear
FVS318
> can two of them establish a vpn connection if one is running firmware 2.3
> and the other 2.4
>
> Thanks
>
>
| |
|
| also,
I was looking for the same information and found loads of different answers
on google, etc. These are some notes I made at the time.
Netgear tech support:
ports 1723 and 500.
Newsgroups:
1723 for PPTP
500 - IPSec ?
50
51 for IPSec.
groups.google
port UDP 500 if using key neg (IPSec?)
port UDP 1723 for PPTP
Protocol 50 ESP (not port number, but protocol)
Protocol 51 AH?
PPTP: use port 1723 and GRE protocol 47 (Generic Routing Ecapsulation
protocol)
L2TP: ports 1701 and port 500
then my notes say: "check some books".
I've got both of mine in the 'DMZ' (i.e. all ports are open and all packets
are forwarded to the FVS318 now).
I actually have 3 sites with these units and find that even thought all
ports are open on all sites and all the sites' FVS318's report a fully
established connection that 1 of the sites does not work properly - e.g.
network browse and ping don't work - actually nothing that you'd like to do
over a network actually works with this site (in either direction). Some
packet sniffers at various points on the way indicated a problem with an
intervening corporate ISP provider mangling the encrypted VPN packets - e.g.
modifying the source or destination IP address and sending the modified
packet on, but then sending on the original as well - stuff like that. They
currently have their firewall vendor looking into the problem - so things
can screw up in realms outside of your control.
"Steve" <mcp5@qwest.net> wrote in message
news:MwL1d.44$l_4.63959@news.uswest.net...
> I am trying to figure which ports to open on the actiontec modem to allow
> vpn passthru. My modem is running Qwest firmware and doesn't have a radio
> button to turn vpn passthru on. And does anyone know on the Netgear
FVS318
> can two of them establish a vpn connection if one is running firmware 2.3
> and the other 2.4
>
> Thanks
>
>
| |
|
| Are you running netgear firmware 2.4 on all three routers?
"Joe" <ffffh.no.spam@hotmail-spammers-paradise.com> wrote in message
news:ci9734$uk6$1@newsg2.svr.pol.co.uk...
> also,
>
> I was looking for the same information and found loads of different
answers
> on google, etc. These are some notes I made at the time.
>
> Netgear tech support:
> ports 1723 and 500.
>
> Newsgroups:
> 1723 for PPTP
> 500 - IPSec ?
> 50
> 51 for IPSec.
>
> groups.google
> port UDP 500 if using key neg (IPSec?)
> port UDP 1723 for PPTP
>
> Protocol 50 ESP (not port number, but protocol)
> Protocol 51 AH?
>
> PPTP: use port 1723 and GRE protocol 47 (Generic Routing Ecapsulation
> protocol)
> L2TP: ports 1701 and port 500
>
> then my notes say: "check some books".
>
> I've got both of mine in the 'DMZ' (i.e. all ports are open and all
packets
> are forwarded to the FVS318 now).
>
> I actually have 3 sites with these units and find that even thought all
> ports are open on all sites and all the sites' FVS318's report a fully
> established connection that 1 of the sites does not work properly - e.g.
> network browse and ping don't work - actually nothing that you'd like to
do
> over a network actually works with this site (in either direction). Some
> packet sniffers at various points on the way indicated a problem with an
> intervening corporate ISP provider mangling the encrypted VPN packets -
e.g.
> modifying the source or destination IP address and sending the modified
> packet on, but then sending on the original as well - stuff like that.
They
> currently have their firewall vendor looking into the problem - so things
> can screw up in realms outside of your control.
>
> "Steve" <mcp5@qwest.net> wrote in message
> news:MwL1d.44$l_4.63959@news.uswest.net...
allow[vbcol=seagreen]
radio[vbcol=seagreen]
> FVS318
2.3[vbcol=seagreen]
>
>
| |
|
| yes.
"Steve" <mcp5@qwest.net> wrote in message
news:AP42d.30$Mi.55172@news.uswest.net...
> Are you running netgear firmware 2.4 on all three routers?
>
> "Joe" <ffffh.no.spam@hotmail-spammers-paradise.com> wrote in message
> news:ci9734$uk6$1@newsg2.svr.pol.co.uk...
> answers
> packets
> do
Some[vbcol=seagreen]
> e.g.
> They
things[vbcol=seagreen]
> allow
> radio
> 2.3
>
>
>
>
| |
| Fred Kogel 2004-09-23, 9:31 am |
| "Steve" <mcp5@qwest.net> schrieb in
news:MwL1d.44$l_4.63959@news.uswest.net:
> I am trying to figure which ports to open on the actiontec modem to
> allow vpn passthru. My modem is running Qwest firmware and doesn't
> have a radio button to turn vpn passthru on. And does anyone know on
> the Netgear FVS318 can two of them establish a vpn connection if one
> is running firmware 2.3 and the other 2.4
>
> Thanks
>
>
Netgear tech support:
ports 1723 and 500.
is correct, for IPSec you only need 500 UDP (but you know that normaly you
only need it, if you run IPsec software behind or without a router, like
Netgears VPN-Software). If you establish IPSec bewteen two Netgear FVS318,
be shure to have the latest identical Firmware on both of them, because
they realized entries you need ... .
(I will go on further with setting up for others ...)
Then it depends. If you have dynamic IP adresses, first you do have to use
aggressive mode(!). Then you should have two DNS entries at DynDNS (or at
simular services, see documentation) one for each site.
Next is, two estabish identical configurations. The only exceptions are the
(vice versa configured) identity data and the network addresses.
Thats all (and easy, made it serveral times),
Fred
|
|
|
|
|