Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
Need a VPN expert

I'm trying to get my Android devices to talk to a NETGEAR ProSafe VPN Firewall FVS336GV2.

I have successfully configured two of these VPN gateways to talk to each other. I cannot get my Android devices to connect.

__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 06-25-2013, 01:38 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
Registered
 
id10t's Avatar
 
Join Date: Mar 2003
Posts: 10,322
Picking correct vpn settings, encryption types, etc? Key exchange being done properly?
__________________
“IN MY EXPERIENCE, SUSAN, WITHIN THEIR HEADS TOO MANY HUMANS SPEND A LOT OF TIME IN THE MIDDLE OF WARS THAT HAPPENED CENTURIES AGO.”
Old 06-25-2013, 06:00 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
It'll be legen-waitforit
 
stealthn's Avatar
 
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,979
Have to be WAY more specific; there are a ton of "Android devices" along with their variants of operating systems.
__________________
Bob James
06 Cayman S - Money Penny
18 Macan GTS
Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo
Old 06-25-2013, 06:12 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
The android application is pretty sparse. I'm trying to use the NCP client. It doesn't have all of the options that are on my firewall.

Firewall side - (key removed)

Config Removed
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020

Last edited by red-beard; 06-27-2013 at 12:24 PM..
Old 06-25-2013, 06:34 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
Sorry, took me a few minutes to get the screen shots off the Android device.
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 06-25-2013, 06:39 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
It'll be legen-waitforit
 
stealthn's Avatar
 
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,979
Looks good the only thing I would try to change would be your Group ID Type to Full Qualified Domain on the NCP Client. ID same as the one on the Netgear fvs_remote.com

Bob
__________________
Bob James
06 Cayman S - Money Penny
18 Macan GTS
Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo
Old 06-25-2013, 06:58 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
Config Removed
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020

Last edited by red-beard; 06-27-2013 at 12:24 PM..
Old 06-25-2013, 07:06 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 55,927
What type of Android device is it, a phone or a random tablet? What version of Android?

My phone, has a vpn client built in, that I've managed to get to connect to my home firewall running ipsec, but then it's a Cisco firewall, and that is what I do for a living. A netgear is a little different.

Can you get anything else to connect to the firewall? It would be nice to confirm that something can connect to the firewall before a lot of time is spent troubleshooting the Android.

Are you getting an error message on the Android?

In the netgear, you have "fqdn" selected for the remote identifier, but the client shows ip address and tetralan for the IKE group info. I think the "remote identifier" in the netgear might be the IKE group, but I'm not certain. Those two not agreeing may be the problem.
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 06-25-2013, 07:07 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 55,927
Quote:
Originally Posted by stealthn View Post
I would try to change would be your Group ID Type to Full Qualified Domain on the NCP Client. ID same as the one on the Netgear fvs_remote.com

Bob
+
Quote:
Originally Posted by red-beard View Post
2013 Jun 26 03:02:58 [FVS336GV2] [IKE] remote configuration for identifier "tetrawest.dyndns-home.com" found_
2013 Jun 26 03:02:58 [FVS336GV2] [IKE] Aggressive mode of 0.0.0.0[500] is not acceptable._
I think Bob is right.

Most IPSec VPN will have 2 sets of usernames and passwords, IKE and IPSec. In this case, because you have xauth disabled, you've only got the one set, and I don't think you have them configured the same.
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 06-25-2013, 07:10 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
Switched to "Main" instead of Aggressive
Client says

VPN Error
VPN Gateway not responding
(waiting for Msg 6)

Firewall side log

2013 Jun 26 03:16:58 [FVS336GV2] [IKE] Received Vendor ID: CISCO-UNITY_
2013 Jun 26 03:16:58 [FVS336GV2] [IKE] Setting DPD Vendor ID_
2013 Jun 26 03:16:59 [FVS336GV2] [IKE] Received Malformed packet of payload length 19394 and total length 64._
2013 Jun 26 03:17:08 [FVS336GV2] [IKE] Received Malformed packet of payload length 8724 and total length 64._
- Last output repeated 2 times -
2013 Jun 26 03:17:26 [FVS336GV2] [IKE] Ignore information because ISAKMP-SA has not been established yet._
2013 Jun 26 03:17:59 [FVS336GV2] [IKE] Phase 1 negotiation failed due to time up for 76.31.194.205[10952]. 2dfeeacb86a5afca:f3549ca129cb446f_
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 06-25-2013, 07:19 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #10 (permalink)
It'll be legen-waitforit
 
stealthn's Avatar
 
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,979
Strange it says aggressive mode not accepted, when it's set....?

Use mode config on the Netgear and name both ends...
__________________
Bob James
06 Cayman S - Money Penny
18 Macan GTS
Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo
Old 06-25-2013, 07:19 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #11 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
Quote:
Originally Posted by masraum View Post
What type of Android device is it, a phone or a random tablet? What version of Android?

My phone, has a vpn client built in, that I've managed to get to connect to my home firewall running ipsec, but then it's a Cisco firewall, and that is what I do for a living. A netgear is a little different.

Can you get anything else to connect to the firewall? It would be nice to confirm that something can connect to the firewall before a lot of time is spent troubleshooting the Android.

Are you getting an error message on the Android?

In the netgear, you have "fqdn" selected for the remote identifier, but the client shows ip address and tetralan for the IKE group info. I think the "remote identifier" in the netgear might be the IKE group, but I'm not certain. Those two not agreeing may be the problem.
Samsung Galaxy Tab 7.0 Plus, Android 4.0.4
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 06-25-2013, 07:20 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #12 (permalink)
 
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
Quote:
Originally Posted by masraum View Post
Can you get anything else to connect to the firewall? It would be nice to confirm that something can connect to the firewall before a lot of time is spent troubleshooting the Android.
I have successfully connected two of these gateways through VPN. In fact, I'm HOME, connecting to the work gateway through the VPN. So it does work. I'm trying to get a client to gateway VPN to work.
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 06-25-2013, 07:23 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #13 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
Quote:
Originally Posted by stealthn View Post
Strange it says aggressive mode not accepted, when it's set....?

Use mode config on the Netgear and name both ends...
I switched it to "Main", but the Netgear didn't accept the change, at first. I figured out how to disable it and switch both sides. Now the errors is "MSG 6" on the android side and the VPN log is above.
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 06-25-2013, 07:26 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #14 (permalink)
It'll be legen-waitforit
 
stealthn's Avatar
 
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,979
No it should be aggressive, main mode is for site to site tunnels.
__________________
Bob James
06 Cayman S - Money Penny
18 Macan GTS
Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo
Old 06-25-2013, 07:28 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #15 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
OK, somehow the ID type switch, they are both now FQDN.

Still getting error 6, but the gateway log is

Config Removed
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020

Last edited by red-beard; 06-27-2013 at 12:25 PM..
Old 06-25-2013, 07:31 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #16 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
OK, I'll switch them back to aggressive.
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 06-25-2013, 07:32 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #17 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
Switched back to aggressive.

Client:

IKE Error (Phase 2)
Lost contact to peer

Gateway

Config Removed
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020

Last edited by red-beard; 06-27-2013 at 12:25 PM..
Old 06-25-2013, 07:35 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #18 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
Looks like we're getting closer...
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 06-25-2013, 07:37 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #19 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
I'm guessing I need to select XAUTH.

__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 06-25-2013, 07:39 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #20 (permalink)
Reply


 


All times are GMT -8. The time now is 05:04 AM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.