Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
pfSense Forum
pfSense English Support
»
Post a bounty
»
Completed Bounties
»
[SOLVED] Solution to SonicWall VPN Client Behind pfsense [Now Up To $200]
Username:
Password:
1 Hour
1 Day
1 Week
1 Month
Forever
Home
Help
Search
Login
Register
Pages:
1
[
2
]
Go Down
« previous
next »
Print
Author
Topic: [SOLVED] Solution to SonicWall VPN Client Behind pfsense [Now Up To $200] (Read 25830 times)
0 Members and 2 Guests are viewing this topic.
Evgeny
Hero Member
Offline
Posts: 1808
Re: Solution to SonicWall VPN Client Behind pfsense [Now Up To $200]
«
Reply #15 on:
August 13, 2009, 05:35:46 pm »
Yes I did.
The issue is 'packet from LAN does not go out of WAN'. I can't believe -\\\
Logged
http://ru.doc.pfsense.org
jimp
Administrator
Hero Member
Online
Posts: 12830
Re: Solution to SonicWall VPN Client Behind pfsense [Now Up To $200]
«
Reply #16 on:
August 13, 2009, 05:39:58 pm »
I was looking back over the thread, and I didn't see where you said what version of pfSense you were running now.
A lot has changed since the 1.0 days, unfortunately, and a lot has even changed between pfSense 1.2.2 and 1.2.3-RC2.
Logged
Need help fast?
Commercial Support
!
Co-Author of
pfSense: The Definitive Guide
. - Check the
Doc Wiki
for FAQs.
Do not PM for help!
Donate to the project
|
My Wish List
Evgeny
Hero Member
Offline
Posts: 1808
Re: Solution to SonicWall VPN Client Behind pfsense [Now Up To $200]
«
Reply #17 on:
August 13, 2009, 05:44:07 pm »
I tried this antient 1.0.1 only because it still alive in my server room and I clearly remember that at those days SonicWall worked through this box. And indeed it works.
Logged
http://ru.doc.pfsense.org
mayesjc
Newbie
Offline
Posts: 19
Re: Solution to SonicWall VPN Client Behind pfsense [Now Up To $200]
«
Reply #18 on:
August 13, 2009, 05:45:08 pm »
I have tried both the automatic and forced NAT-T setting on the client. While I do not have access to the VPN server, I believe that NAT-T is set on that side as well, because my colleague in Germany (where the server is located) is the one who originally advised me to adjust the NAT-T setting. As to the version of pfsense, I am running 1.2.3-RC1.
Logged
Evgeny
Hero Member
Offline
Posts: 1808
Re: Solution to SonicWall VPN Client Behind pfsense [Now Up To $200]
«
Reply #19 on:
August 13, 2009, 07:03:57 pm »
I disabled 'scrub' on 1.2-RELEASE and... fragmented packet started to go from LAN to WAN but not natted!
19:59:42.253327 IP 192.168.7.189.500 > x.x.x.144.500: isakmp: phase 1 I agg
19:59:42.253745 IP 192.168.7.189 > x.x.x.144: udp
Normal icmp is natted normally
20:00:52.032185 IP x.x.x.144 > x.x.x.251: ICMP echo reply, id 26258, seq 30208, length 40
20:00:52.988798 IP x.x.x.251 > x.x.x.144: ICMP echo request, id 26258, seq 30464, length 40
Logged
http://ru.doc.pfsense.org
Evgeny
Hero Member
Offline
Posts: 1808
Re: Solution to SonicWall VPN Client Behind pfsense [Now Up To $200]
«
Reply #20 on:
August 13, 2009, 08:28:48 pm »
I managed to fix my SonicWall client by doing the following.
On my XP PC (where SonicWall client is installed) I went to Registry [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\
Interfaces\[Adapter ID]] found the virtual adapter installed by SW installation, changed MTU from 1300 to 1500. Then you have to run SW install again, it "repairs" its own installation and only after this "repaie" segmentation disappears as disappears the problem. On pfSense you have to allow only UDP:500, leave 'scrub' off.
Resume: although the problem at pfSense exists you can avoid it by adjusting MTU on client (as jimp fairly mentioned).
Logged
http://ru.doc.pfsense.org
mayesjc
Newbie
Offline
Posts: 19
Re: Solution to SonicWall VPN Client Behind pfsense [Now Up To $200]
«
Reply #21 on:
August 13, 2009, 09:39:03 pm »
Done! Thank you to everyone for their patient help. I just paid my $200 (Confirmation No. 3HS208994B4607915), and it was well worth it.
What I did was to ensure that scrub was disabled (it was). I also chose Manual Outbound NAT rule generation (Advanced Outbound NAT (AON)), setting up rules for ports 50, 500, and 4500, which I understand from other sources are used by the SonicWall client. Of course, I still have the inbound and outbound firewall rules allowing traffic to and from the VPN server's ip address. Even at that point, the client would not connect. The final step, which allowed the connection, was to enter 1500 in the MTU field on the WAN interface. (It is a bit fuzzy, but I first set the MTU to 1300. The software firewall on the XP client then asked me to approve the outbound connection of the SonicWall Client. That had never happened before. I clicked OK to allow the connection, but still had no connection. It was not until I entered 1500 into the MTU that the connection succeeded.)
I made no changes on the XP client, although NAT Traversal is Forced On.
Thanks again.
Logged
ermal
Administrator
Hero Member
Offline
Posts: 3094
Re: [SOLVED] Solution to SonicWall VPN Client Behind pfsense [Now Up To $200]
«
Reply #22 on:
August 14, 2009, 06:44:52 am »
I didn't get any part of the money
Logged
jimp
Administrator
Hero Member
Online
Posts: 12830
Re: [SOLVED] Solution to SonicWall VPN Client Behind pfsense [Now Up To $200]
«
Reply #23 on:
August 14, 2009, 06:59:46 am »
Quote from: ermal on August 14, 2009, 06:44:52 am
I didn't get any part of the money
He must have just made a project donation, and not a payment to any one person.
Logged
Need help fast?
Commercial Support
!
Co-Author of
pfSense: The Definitive Guide
. - Check the
Doc Wiki
for FAQs.
Do not PM for help!
Donate to the project
|
My Wish List
mayesjc
Newbie
Offline
Posts: 19
Re: [SOLVED] Solution to SonicWall VPN Client Behind pfsense [Now Up To $200]
«
Reply #24 on:
August 14, 2009, 08:17:24 am »
I paid the bounty as a project donation, which is what I though I was supposed to do. Indeed, I was told specifically to do that on another bounty. I am very sorry for the misunderstanding and will be sure to clarify that point next time. It is a great project, and I was happy to help financially.
As a practical matter, how else would it get paid when so many people contributed to the eventual solution?
Logged
jimp
Administrator
Hero Member
Online
Posts: 12830
Re: [SOLVED] Solution to SonicWall VPN Client Behind pfsense [Now Up To $200]
«
Reply #25 on:
August 14, 2009, 08:33:12 am »
Quote from: mayesjc on August 14, 2009, 08:17:24 am
I paid the bounty as a project donation, which is what I though I was supposed to do. Indeed, I was told specifically to do that on another bounty. I am very sorry for the misunderstanding and will be sure to clarify that point next time. It is a great project, and I was happy to help financially.
As a practical matter, how else would it get paid when so many people contributed to the eventual solution?
That is, as I understand it, how things have been done lately as an "escrow" sort of deal and then cmb or someone else with access to that can distribute it.
As to who gets what, that is up to you, depending on however you see fit to allocate. :-)
Logged
Need help fast?
Commercial Support
!
Co-Author of
pfSense: The Definitive Guide
. - Check the
Doc Wiki
for FAQs.
Do not PM for help!
Donate to the project
|
My Wish List
Pages:
1
[
2
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Administrative
-----------------------------
=> Forum rules
=> Messages from the pfSense Team
=> Feedback
-----------------------------
pfSense English Support
-----------------------------
=> Installation and Upgrades
=> General Questions
=> 2.1 Snapshot Feedback and Problems
=> Post a bounty
===> Completed Bounties
===> Expired/Withdrawn Bounties
=> Hardware
=> Firewalling
=> NAT
=> CARP/VIPs
=> Routing and Multi WAN
=> Traffic Shaping
=> DHCP and DNS
=> IPv6
=> IPsec
=> PPTP
=> PPPoE Server
=> Captive Portal
=> webGUI
=> Wireless
=> SNMP
=> Packages
=> Virtualization installations and techniques
=> OpenVPN
=> Gaming
-----------------------------
Development/Documentation
-----------------------------
=> Documentation
=> Development
-----------------------------
General Category
-----------------------------
=> General Discussion
-----------------------------
International Support
-----------------------------
=> Indonesian
=> Deutsch
=> Español
=> Français
=> Italiano
=> Russian
=> Nederlands
=> Norwegian
=> Portuguese
=> Polish
=> Romanian
=> Swedish
=> Turkish
-----------------------------
Retired
-----------------------------
=> 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
=> 1.2.1-RC Snapshot Feedback and Problems-RETIRED
=> 2.0-RC Snapshot Feedback and Problems - RETIRED
=> DNS Server testing area - RETIRED
Loading...