VPN - Netgear FVS318 and ActionTec 701-wg

This is Interesting: Free IT Magazines  
Home > Archive > VPN > September 2004 > Netgear FVS318 and ActionTec 701-wg





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author Netgear FVS318 and ActionTec 701-wg
Steve

2004-09-15, 8:47 pm

I am trying to figure which ports to open on the actiontec modem to allow
vpn passthru. My modem is running Qwest firmware and doesn't have a radio
button to turn vpn passthru on. And does anyone know on the Netgear FVS318
can two of them establish a vpn connection if one is running firmware 2.3
and the other 2.4

Thanks


Joe

2004-09-15, 8:47 pm

i had a vpn connection with 2x FVS318 where one was on 2.4 and the other 2.3
firmware (it seemed to work) - this was only for a half day or so while I
upgraded all units to version 2.4. It's probably better to run all units at
the same/latest firmware level.



"Steve" <mcp5@qwest.net> wrote in message
news:MwL1d.44$l_4.63959@news.uswest.net...
> I am trying to figure which ports to open on the actiontec modem to allow
> vpn passthru. My modem is running Qwest firmware and doesn't have a radio
> button to turn vpn passthru on. And does anyone know on the Netgear

FVS318
> can two of them establish a vpn connection if one is running firmware 2.3
> and the other 2.4
>
> Thanks
>
>



Joe

2004-09-15, 8:47 pm

also,

I was looking for the same information and found loads of different answers
on google, etc. These are some notes I made at the time.

Netgear tech support:
ports 1723 and 500.

Newsgroups:
1723 for PPTP
500 - IPSec ?
50
51 for IPSec.

groups.google
port UDP 500 if using key neg (IPSec?)
port UDP 1723 for PPTP

Protocol 50 ESP (not port number, but protocol)
Protocol 51 AH?

PPTP: use port 1723 and GRE protocol 47 (Generic Routing Ecapsulation
protocol)
L2TP: ports 1701 and port 500

then my notes say: "check some books".

I've got both of mine in the 'DMZ' (i.e. all ports are open and all packets
are forwarded to the FVS318 now).

I actually have 3 sites with these units and find that even thought all
ports are open on all sites and all the sites' FVS318's report a fully
established connection that 1 of the sites does not work properly - e.g.
network browse and ping don't work - actually nothing that you'd like to do
over a network actually works with this site (in either direction). Some
packet sniffers at various points on the way indicated a problem with an
intervening corporate ISP provider mangling the encrypted VPN packets - e.g.
modifying the source or destination IP address and sending the modified
packet on, but then sending on the original as well - stuff like that. They
currently have their firewall vendor looking into the problem - so things
can screw up in realms outside of your control.

"Steve" <mcp5@qwest.net> wrote in message
news:MwL1d.44$l_4.63959@news.uswest.net...
> I am trying to figure which ports to open on the actiontec modem to allow
> vpn passthru. My modem is running Qwest firmware and doesn't have a radio
> button to turn vpn passthru on. And does anyone know on the Netgear

FVS318
> can two of them establish a vpn connection if one is running firmware 2.3
> and the other 2.4
>
> Thanks
>
>



Steve

2004-09-15, 8:48 pm

Are you running netgear firmware 2.4 on all three routers?

"Joe" <ffffh.no.spam@hotmail-spammers-paradise.com> wrote in message
news:ci9734$uk6$1@newsg2.svr.pol.co.uk...
> also,
>
> I was looking for the same information and found loads of different

answers
> on google, etc. These are some notes I made at the time.
>
> Netgear tech support:
> ports 1723 and 500.
>
> Newsgroups:
> 1723 for PPTP
> 500 - IPSec ?
> 50
> 51 for IPSec.
>
> groups.google
> port UDP 500 if using key neg (IPSec?)
> port UDP 1723 for PPTP
>
> Protocol 50 ESP (not port number, but protocol)
> Protocol 51 AH?
>
> PPTP: use port 1723 and GRE protocol 47 (Generic Routing Ecapsulation
> protocol)
> L2TP: ports 1701 and port 500
>
> then my notes say: "check some books".
>
> I've got both of mine in the 'DMZ' (i.e. all ports are open and all

packets
> are forwarded to the FVS318 now).
>
> I actually have 3 sites with these units and find that even thought all
> ports are open on all sites and all the sites' FVS318's report a fully
> established connection that 1 of the sites does not work properly - e.g.
> network browse and ping don't work - actually nothing that you'd like to

do
> over a network actually works with this site (in either direction). Some
> packet sniffers at various points on the way indicated a problem with an
> intervening corporate ISP provider mangling the encrypted VPN packets -

e.g.
> modifying the source or destination IP address and sending the modified
> packet on, but then sending on the original as well - stuff like that.

They
> currently have their firewall vendor looking into the problem - so things
> can screw up in realms outside of your control.
>
> "Steve" <mcp5@qwest.net> wrote in message
> news:MwL1d.44$l_4.63959@news.uswest.net...
allow[vbcol=seagreen]
radio[vbcol=seagreen]
> FVS318
2.3[vbcol=seagreen]
>
>





Joe

2004-09-23, 9:31 am

yes.

"Steve" <mcp5@qwest.net> wrote in message
news:AP42d.30$Mi.55172@news.uswest.net...
> Are you running netgear firmware 2.4 on all three routers?
>
> "Joe" <ffffh.no.spam@hotmail-spammers-paradise.com> wrote in message
> news:ci9734$uk6$1@newsg2.svr.pol.co.uk...
> answers
> packets
> do
Some[vbcol=seagreen]
> e.g.
> They
things[vbcol=seagreen]
> allow
> radio
> 2.3
>
>
>
>



Fred Kogel

2004-09-23, 9:31 am

"Steve" <mcp5@qwest.net> schrieb in
news:MwL1d.44$l_4.63959@news.uswest.net:

> I am trying to figure which ports to open on the actiontec modem to
> allow vpn passthru. My modem is running Qwest firmware and doesn't
> have a radio button to turn vpn passthru on. And does anyone know on
> the Netgear FVS318 can two of them establish a vpn connection if one
> is running firmware 2.3 and the other 2.4
>
> Thanks
>
>


Netgear tech support:
ports 1723 and 500.

is correct, for IPSec you only need 500 UDP (but you know that normaly you
only need it, if you run IPsec software behind or without a router, like
Netgears VPN-Software). If you establish IPSec bewteen two Netgear FVS318,
be shure to have the latest identical Firmware on both of them, because
they realized entries you need ... .

(I will go on further with setting up for others ...)

Then it depends. If you have dynamic IP adresses, first you do have to use
aggressive mode(!). Then you should have two DNS entries at DynDNS (or at
simular services, see documentation) one for each site.

Next is, two estabish identical configurations. The only exceptions are the
(vice versa configured) identity data and the network addresses.

Thats all (and easy, made it serveral times),

Fred
Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com