Tom's Hardware > Forum > General Networking > Firewall > NetScreen 5XP / ScreenOS 2 preventing VPN connections over..

NetScreen 5XP / ScreenOS 2 preventing VPN connections over..

Forum General Networking : Firewall - NetScreen 5XP / ScreenOS 2 preventing VPN connections over..

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Archived from groups: comp.security.firewalls (More info?)

 

Hi -

I am managing a small network which is accessed off-site by a number
of users. There is usually at least one user connected to our network
during the day via VPN. Recently, the NetScreen 5XP firewall has
occasionally preventing our VPN users from accessing our network,
always the first thing in the morning, or when they have been trying
to connect during the weekend, when nobody is around on-site. When
this happens, on-site users can access the Internet from within, can
ping the firewall, but it refuses Telnet and HTTP connection attempts.
After some experimentation, it seems that only rebooting the Firewall
fixes the prohlem. When I eventually connected to the firewall via
its "diagnostics" port, using Hyperterminal on Windows, I discovered
the single message:

IKE warning, I don't know what attribute 20480 is!

.... scrolling endlessly. Incidentally, I noticed that on this model,
the diagnostics aren't interactive. You can't login; in fact, nothing
happens when you press any key. After rebooting, I noticed that other
messages appeared when I configured the Firewall using its HTTP
interface.

--
Mark Bertenshaw
IT Manager
LEAX Controls

Sponsored Links
Register or log in to remove.

Archived from groups: comp.security.firewalls (More info?)

 

Hi,

To begin with, if you really run Screenos 2.x, stop reading
and upgrade the box...

Mark Bertenshaw <mark.bertenshaw@virgin.net> wrote:
> fixes the prohlem. When I eventually connected to the firewall via
> its "diagnostics" port,

It´s not only a diagnostic port, it's a console with complete
CLI.

> using Hyperterminal on Windows, I discovered
> the single message:
>
> IKE warning, I don't know what attribute 20480 is!

Which indicates, that your software is so old, that it cannot
recognize all attributes your clients are using and behaves
badly in this situation.

> After rebooting, I noticed that other
> messages appeared when I configured the Firewall using its HTTP
> interface.
>

Normal.


Greetigns,
Jens

Reply to Anonymous

Archived from groups: comp.security.firewalls (More info?)

 

Jens Hoffmann <jh@bofh.de> wrote in message news:<slrnc8dofm.al6.jh@churrasco.bofh.de>...
> Hi,
>
> To begin with, if you really run Screenos 2.x, stop reading
> and upgrade the box...
>
> Mark Bertenshaw <mark.bertenshaw@virgin.net> wrote:
> > fixes the prohlem. When I eventually connected to the firewall via
> > its "diagnostics" port,
>
> It´s not only a diagnostic port, it's a console with complete
> CLI.
>
> > using Hyperterminal on Windows, I discovered
> > the single message:
> >
> > IKE warning, I don't know what attribute 20480 is!
>
> Which indicates, that your software is so old, that it cannot
> recognize all attributes your clients are using and behaves
> badly in this situation.
>
> > After rebooting, I noticed that other
> > messages appeared when I configured the Firewall using its HTTP
> > interface.
> >
>
> Normal.

Jens -

Thanks for the reply. It seems that I had to toggle some keys on the
keyboard before I got a two way connection on HyperTerminal.

I very much agree that the software ought to be upgraded. Now someone
else has said this, I think I have a better case at pitching this at
my company's directors.

My clients' software is of the same vintage as the firewall software,
so I would be surprised if it was them causing the problem - they are
normally connected during the day when we have no problems. Since
this message, when it arrives, seems to be appearing constantly, could
it be that some evil person is trying to crack our firewall using more
modern software?

--
Mark Bertenshaw
IT Manager
LEAX Controls

Reply to Anonymous
Tom's Hardware > Forum > General Networking > Firewall > NetScreen 5XP / ScreenOS 2 preventing VPN connections over..
Go to:

There are 1004 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them