Tom's Hardware > Forum > General Networking > Firewall > SSH sentinel and ZYWALL70 VPN Connection

SSH sentinel and ZYWALL70 VPN Connection

Forum General Networking : Firewall - SSH sentinel and ZYWALL70 VPN Connection

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Archived from groups: comp.security.firewalls (More info?)

 

Trying to establish a VPN connection from my home laptop to my company's
Internel LAN secured with a ZYXEL ZYWALL 70 firewall.

From my home computer I try to make a connection with SSH sentinel 1.4. The
connection seems to be OK, because I get I message "VPN connection
successfully established". But when I go to the explorer and type an IP
address of one of the computers in the network I can't get a connection.
What is going wrong?

Sponsored Links
Register or log in to remove.

Archived from groups: comp.security.firewalls (More info?)

 

On Wed, 23 Jun 2004 16:32:42 +0300, "Hatzigiannakis Nikos"
<ypai@aigaio.gr> wrote:
>
>Trying to establish a VPN connection from my home laptop to my company's
>Internel LAN secured with a ZYXEL ZYWALL 70 firewall.
>
>From my home computer I try to make a connection with SSH sentinel 1.4. The
>connection seems to be OK, because I get I message "VPN connection
>successfully established". But when I go to the explorer and type an IP
>address of one of the computers in the network I can't get a connection.
>What is going wrong?
>

What happens when you do a traceroute to that IP address?

Reply to Anonymous

Archived from groups: comp.security.firewalls (More info?)

 

The traceroute indicates that all the traffic goes to the default ISP
gateway and not to the VPN tunnel

Reply to Anonymous

Archived from groups: comp.security.firewalls (More info?)

 

On Wed, 23 Jun 2004 19:56:20 +0300, "Nikos Hatzigiannakis"
<nikos@khy.gr> wrote:
>
>The traceroute indicates that all the traffic goes to the default ISP
>gateway and not to the VPN tunnel
>

Well, that's a pretty good indication that SSH Sentinel is not
properly configured. Did you follow the instructions on the ZyXEL Tech
Support note I posted some time ago?

Reply to Anonymous

Archived from groups: comp.security.firewalls (More info?)

 

I did everything the support note says.

I can not figure out how can I troubleshoot the problem since I get the "VPN
connection successfully established" and have no error messages in the
ZYWALL log.



Should I configure any firewall rules in the ZYWALL ?

Is there any other indication that the VPN tunnel is working (except the
try and error method)?



Any further help will be mostly appreciated

Reply to Anonymous

Archived from groups: comp.security.firewalls (More info?)

 

On Wed, 23 Jun 2004 20:51:17 +0300, "Nikos Hatzigiannakis"
<nikos@khy.gr> wrote:
>
>I did everything the support note says.
>
>I can not figure out how can I troubleshoot the problem since I get the "VPN
>connection successfully established" and have no error messages in the
>ZYWALL log.
>

Try this and see what happens:

http://www.zyxel.com/support/suppo [...] /ipsec.htm

Reply to Anonymous

Archived from groups: comp.security.firewalls (More info?)

 

Have you tried pinging that destination's IP?

What do the logs in the Zywall tell you when you try to connect?
What do the SSH Sentinel logs tell you?

Brad


On Wed, 23 Jun 2004 16:32:42 +0300, "Hatzigiannakis Nikos"
<ypai@aigaio.gr> wrote:

>Trying to establish a VPN connection from my home laptop to my company's
>Internel LAN secured with a ZYXEL ZYWALL 70 firewall.
>
>From my home computer I try to make a connection with SSH sentinel 1.4. The
>connection seems to be OK, because I get I message "VPN connection
>successfully established". But when I go to the explorer and type an IP
>address of one of the computers in the network I can't get a connection.
>What is going wrong?
>

Reply to Brad

Archived from groups: comp.security.firewalls (More info?)

 

Sorry, I didn't see the other replies before I posted my last one
about pinging the remote side.

What IP addressing scheme are you using on both ends?
With this setup, if you're using the same addresssing scheme
e.g. 192.168.0.x on both sides, you will be able to create a
tunnel, but not be able to share anything or take any other action.

Brad





On Wed, 23 Jun 2004 20:51:17 +0300, "Nikos Hatzigiannakis"
<nikos@khy.gr> wrote:

>I did everything the support note says.
>
>I can not figure out how can I troubleshoot the problem since I get the "VPN
>connection successfully established" and have no error messages in the
>ZYWALL log.
>
>
>
>Should I configure any firewall rules in the ZYWALL ?
>
> Is there any other indication that the VPN tunnel is working (except the
>try and error method)?
>
>
>
>Any further help will be mostly appreciated
>

Reply to Brad

Archived from groups: comp.security.firewalls (More info?)

 

192.168.50.0./24 on one site

the other site is a single Laptop with dynamic IP

Reply to Anonymous

Archived from groups: comp.security.firewalls (More info?)

 

Currently I'm testing the same VPN configuration, it means Zyxel
ZYWALL 70 + SSH Sentinel, and I'm fighting a bit in order to make the
connection working. As Mr. Nikos the tunnel it's build up succesfully
in 2 remote client under test (first WIN XP Pro and second WIN 98).
But with WIN XP Pro I can partially access the network resouces,
instead with WIN 98 I cannot ping and obviously I cannot use any
remote network resources.

> On Wed, 23 Jun 2004 16:32:42 +0300, "Hatzigiannakis Nikos"
> <ypai@aigaio.gr> wrote:
>
> >Trying to establish a VPN connection from my home laptop to my company's
> >Internel LAN secured with a ZYXEL ZYWALL 70 firewall.
> >
> >From my home computer I try to make a connection with SSH sentinel 1.4. The
> >connection seems to be OK, because I get I message "VPN connection
> >successfully established". But when I go to the explorer and type an IP
> >address of one of the computers in the network I can't get a connection.
> >What is going wrong?
> >

Reply to Anonymous

Archived from groups: comp.security.firewalls (More info?)

 

nikos:

Do you mean the laptop's actually ip address is changing or...
Is that laptop behind a firewall or router or gateway of some kind,
and the firewall's or router's or gateway's address changes
dynamically?

Brad




On Thu, 24 Jun 2004 08:51:51 +0300, "Hatzigiannakis Nikos"
<nikos@ypai.gr> wrote:

>192.168.50.0./24 on one site
>
>the other site is a single Laptop with dynamic IP
>

Reply to Brad

Archived from groups: comp.security.firewalls (More info?)

 

On 23 Jun 2004 23:56:40 -0700, nonusarlo@virgilio.it (Sciawatt) wrote:
>
>Currently I'm testing the same VPN configuration, it means Zyxel
>ZYWALL 70 + SSH Sentinel, and I'm fighting a bit in order to make the
>connection working. As Mr. Nikos the tunnel it's build up succesfully
>in 2 remote client under test (first WIN XP Pro and second WIN 98).
>But with WIN XP Pro I can partially access the network resouces,
>instead with WIN 98 I cannot ping and obviously I cannot use any
>remote network resources.
>

Are you running the latest firmware on the ZyWALL 70, released on June
9th?

In any case, if the SSH Sentinel isn't atracting traffic to its
virtual interface, to me that suggests something's wrong on the SSH
Sentinel side. No guarantees, though...

Reply to Anonymous
Tom's Hardware > Forum > General Networking > Firewall > SSH sentinel and ZYWALL70 VPN Connection
Go to:

There are 616 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them