Home > Ask the Networking Experts > Wireless networking Questions & Answers > Can you explain why certain wireless routers will not work with VPN connections?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Can you explain why certain wireless routers will not work with VPN connections?

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 01 March 2004
Can you explain why certain wireless routers will not work with VPN connections? For example, the D-Link 714P+ (SPI firewall) does not connect with a Nortel Contivity VPN whereas the D-Link 614 (NAT firewall) will connect.

>
The D-Link 714P+ and 614 both support IPsec and PPTP pass-through, but D-Link's knowledge base FAQs indicate that the Nortel Contivity (IPsec) Client generally will not work with these products, and suggests disabling this client's keep-alive feature to improve your odds.

Understanding conflicts between Network/Port Address Translation and IPsec VPNs is definitely a challenge. IPsec is designed to detect and discard any change to encapsulated, encrypted packets. NAT does just that - it changes outgoing packets by mapping private source IP address and port to the firewall's public WAN IP address and a unique port.

When responses are received, NAT must map each one back to the original private IP/port to reach the client. Problems here include:

1) In some IPsec flavors, any change to the source IP invalidates the IPsec integrity check value carried within the packet, so forget it.

2) In IPsec ESP tunnel mode, the source IP in the "outer packet" can be changed without invalidating the integrity check value. However, the content of the original packet - including the TCP/UDP source port - is obscured by encryption. So NAT can't do its job unless the firewall implements what is commonly referred to as a "pass-through." Firewalls with VPN pass-through can often forward IPsec-encrypted packets without breaking them.

3) But IPsec tunnels don't just happen magically - they get set up by a companion protocol called the Internet Key Exchange (IKE). VPN clients send IKE packets on UDP port 500 to authenticate, negotiate security parameters, and establish IPsec tunnels (security associations). There are several issues here that I won't get into, but you can learn more about these problems and proposed "NAT Traversal" solutions by reading these Internet Drafts:

IPsec-NAT Compatibility Requirements

Negotiation of NAT-Traversal in the IKE

UDP Encapsulation of IPsec Packets

The upshot is that different VPN products support different variations of this NAT Traversal solution to allow IPsec and IKE to pass safely through NAT devices. Both of the D-Link products that you mention appear to have some trouble with Nortel's implementation of NAT Traversal. A stateful packet inspection (SPI) firewall uses more sophisticated algorithms to determine when to get rid of UDP pseudo-sessions and associated NAT mappings. Just guessing now, but this may be why you are having a harder time with the 714P+ than the 611, which provides only simple NAT, no stateful inspection. In general, NAT traversal is NOT SUPPOSED TO require changes to NAT devices in between (like these two wireless routers). In practice, as you have found, things don't always work like they should.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network administration
Why is access denied to my Active Directory (AD) users and computers?
What network loss testing tools/methods calculate dropped packets from a PC?
Do I have to disable DHCP on my router to create a DHCP server?
What preventative maintenance procedures for network devices exist?
Is there VLAN software recommend for Realtek NICs?
How can I replicate the services of Active Directory (AD) in ADC?
Top 10 reasons why computers do not have network access to each other
Which configuration management tools map connected network devices?
How important are network infrastructure maps for engineers or admins?
How server virtualization improves efficiency in a client-server model

Wireless networking
Why is my network adapter not working after a Vista Business upgrade?
How many wireless base stations can connect to 802.11g access points?
APs drop connection in WLAN configured as a wireless mesh network
How does Wi-Fi ad-hoc mode react when 802.11n and legacy peers are present?
Can wireless adapters operate as client access points to make SoftAPs?
Will using a VPN protect me against fake wireless hotspots?
WLAN QoS and SLA monitoring with 7/24 Wireless Quality Assurance costs
How can I hide my WLAN's SSID in an Aruba AP-61?
How radio frequency (RF) of microwaves alter wireless signal strength
Stolen laptop recovery using remote access and wireless network SSIDs

Wireless LAN Deployment and Security
Combining VPN and WLAN technologies
PDA VPN options
Troubleshooting Nortel Contivity VPN over a wireless network
Using PPTP or IPsec VPN tunnels for WLAN security/gateway
How can I increase the distance of coverage of WLAN?
Comment on Apple's Airport Extreme base station
Can I push a policy (ACL) onto a pocket PC
Implementing VPN with access points (and sources for free VPN clients)
Do all 802.11b/g access points use Time Division Duplex
WLAN in planes?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts