Home > Ask the Networking Experts > Wireless networking with Lisa Phifer Questions & Answers > After setting up my wireless router, I can no longer get on the VPN.
Ask The Networking Expert: Questions & Answers
EMAIL THIS

After setting up my wireless router, I can no longer get on the VPN.

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 16 February 2005
After I connected my wireless router (Netgear MR814), I cannot connect to my Nortel Contivity VPN anymore. It disconnected right after the display "Checking for banner text". Without the router, everything works fine. I even tried with another wireless router (US Robotics USR808054CAN). It has the same problem. If it is the wireless routers' problem, can you suggest one that will work?

>
EXPERT RESPONSE
The symptom you describe ("Checking for banner text" when using the Nortel Contivity VPN client) is a very common indicator of Network Address Translation (NAT) problems. In short, your VPN tunnel is being established (i.e., IKE gets through your router), but incoming VPN traffic is being blocked (i.e., IPsec ESP does not get through your router). Your VPN client is waiting to receive expected "banner text" that is being blocked, and eventually times out.

There are two ways for VPN clients to successfully make it through a NAT-ing device like a broadband/wireless router: VPN pass-through and NAT traversal.

  1. With VPN pass-through, the NAT-ing device observes VPN tunnel establishment and uses something to map arriving VPN data to the inside host that established the VPN tunnel. For example, when using IPsec VPNs, the NAT-ing device may forward inbound ESP (protocol 50) to the host that previously sent outbound IKE (UDP port 500) traffic. It is not unusual for this approach to work for one VPN tunnel at a time, or to work better with some VPN clients than others.

  2. With NAT traversal, the VPN client and gateway collaborate to avoid needing anything special from the NAT-ing device. They do this by detecting the presence of a NAT-ing device during tunnel establishment and agreeing to encapsulate VPN traffic inside a standard UDP envelope. The VPN client wraps outbound ESP inside a UDP header -- the NAT-ing device just sees a regular UDP packet and translates IP address and UDP port in the normal fashion. The VPN gateway sends ESP inside UDP as well, letting the NAT-ing device use the same IP address and UDP port number to map inbound packets back to the right VPN client.

The Netgear MR814 supports IPsec VPN pass-through, although I have seen some user posts suggesting that it only supports one tunnel at any given time. Your Nortel Contivity VPN client supports NAT traversal, although this option must be enabled on the VPN gateway to use it. I'm guessing that the MR814's VPN pass-through implementation isn't compatible with your version of the Contivity VPN client, but enabling NAT traversal would help.

Many users resolve this problem by contacting their VPN administrator to ask whether they need to use a newer version of their VPN client or connect to a different VPN gateway that has NAT traversal enabled. It is also possible that you need reconfigure your wireless router to unblock the UDP port used by NAT traversal. Consult Nortel's website (PDF) for a good description of this problem and possible resolutions, including figures that illustrate Contivity NAT traversal configuration.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Wireless networking with Lisa Phifer
How can I implement VLANs across WLAN links?
Extending Wi-Fi range indoors or outside with 802.11n and WDS
How does WiMAX compare to other wireless broadband services?
How many more users will 802.11n wireless access points support?
Accessing printers on a LAN while connected to a WLAN.
How to maintain corporate VPN connection while printing to a private network.
How to connect wireless networks for printing capabilities
What is the Free Public WiFi network I keep seeing in public places?
Will different wireless card link speeds cause network latency?
Open source authenticator implementation for LANs: How is open1x an 802.1X supplicant?

VPNs with Lisa Phifer
Would you consider a Microsoft VPN tunnel through a WEP encrypted access point to be secure?
I've heard rumors that some service providers can see unencrypted VPN traffic of their customers. Is this true?
I need to select a Cisco ADSL router which is capable of acting as a VPN server for Microsoft VPN clients that come through the Internet.
I am having issues with the IKE communication between the two Cisco VPN concentrators.
What about using SSL VPN with e-mail clients?
Can you have two VPN connections to the same machine simultaneously?
Why can't I access my folders on the server through the VPN?
I need a very basic VPN solution to connect two offices to allow two servers to talk to one another.
Can one use VPN over a peer-to-peer network within a home?
Why can't I access my company's VPN?

Wireless Network Security
What are recent security developments for MIPv6?
Wireless LANs -- 'CCNA Official Exam Certification Library, Third Edition,' Chapter 11
Book of Wireless author on wireless advantages and issues
Buying your own WAPs vs. Internet service provider's wireless routers
Aruba Networks unveils wireless intrusion prevention enhancements, other security upgrades, at Interop
Is my firewall setting preventing wireless network guest access?
Wireless hot spot security -- podcast
Wireless troubleshooting: AP not reestablishing association after loss of connectivity
Wireless security protocols -- How WPA and WPA2 work
Wireless security -- How WEP encryption works

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
Visit KnowledgeStorm's comprehensive and easy to use business white paper directory.
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts