The ranting of an IT Professional:

VPN


April 6, 2011  6:45 PM

“Error 692: Hardware Failure in the Modem” Error Message When You Dial an RAS Server



Posted by: Jason Tramer
error 692, hardware failure, hotfix, L2TP, PPTP, RAS, reboot, VPN, Windows 7

Part of troubleshooting RAS (PPTP and L2TP) VPN connections is constantly tweaking your settings (both client and server) and reconnecting. This becomes a complete pain when Windows 7 decides its sick of trying and just starts generating a error 692, forcing you to reboot before you can try...

March 8, 2011  6:30 PM

Cisco ASA: Accessing VPN networks using L2TP VPN



Posted by: Jason Tramer
ASA, inside, Ipsec, L2TP, tunnel, VPN

Troubleshooting this issue for a bit, user connects to a L2TP VPN presented by the ASA. They can connect to the inside network but not to a network connected to that ASA via IPSEC tunnel. This is actually a simple fix and enter the command:


February 25, 2011  10:25 PM

Using PAP in OSX L2TP VPN connections



Posted by: Jason Tramer
L2TP, Mac, MSCHAP, OSX, PAP, VPN

I know some people go absolutely head over heels in love with Mac's but personally I don't see the appeal. They are a complete pain IMO to configure the simplest options. For example, when you are setting up a L2TP VPN connection do you think it might be helpful to set the authentication...


December 30, 2009  2:54 PM

Allowing management access to an ASA across a site to site VPN tunnel



Posted by: Jason Tramer
access, ASA, ASDM, CLI, interface, Management, site to site, VPN

Ok, so you want to manage your ASA from a network connected via site to site VPN tunnel. No prob. Two easy steps makes this happens. First you have to add the network as an allowed access via the inside network. (I will use the 192.168.1.0/24 network in my example) From CLI it's: http...


December 1, 2009  12:46 AM

Security hole for SSL Clientless VPN



Posted by: Jason Tramer
Cisco, Security, VPN

Check out this article: http://www.theregister.co.uk/2009/11/30/vpn_authentication_weakness/ This is quite big news. Cisco has been pushing it's clientless SSL VPN pretty hard.


November 30, 2009  4:09 PM

Incompatibility on Site to site VPN tunnels between Watchguards and Cisco ASA’s



Posted by: Jason Tramer
ASA, Cisco, VPN, WatchGuard

I have been working with a client with multiple sites and up until recently they have been using Watchguards at all sites. Recently we have been switching out some of the Watchguard for Cisco ASA's but there have been a ton of site to site VPN issues. For example, a tunnel goes down, so you re-key...


November 26, 2009  10:40 PM

Cisco ASA L2TP issues with LDAP authentication



Posted by: Jason Tramer
ASA, CHAP, Cisco, Ipsec, L2TP, LDAP, PAP, PPTP, RA, Remote Access, ssl, VPN

So I configured my ASA to provide L2TP remote access VPN. I originally set it up with a local user database and it worked fine. After I decided to tie it in to LDAP so I could authenticate against Active Directory. I set up my LDAp integration and used the built-in test tool to make sure it worked,...


November 25, 2009  7:32 PM

Configuring your Cisco ASA for L2TP Remote Access



Posted by: Jason Tramer
ASA, Cisco, Ipsec, L2TP, PPTP, Remote Access, VPN

Ok bad news, ASA's do not support PPTP remote access VPN (though they can pass it through). However they will support L2TP with IPSEC VPN which windows is capable of doing. Here is a great video tutorial I used for setting it up: http://gregsowell.com/?p=805


May 27, 2009  4:13 PM

Cisco ASA – Remote access VPN user’s can’t connect to internal resources on the same network



Posted by: Jason Tramer
5510, ASA, can't connect to internal resources on the same network, Cisco, NAT, Remote Access, VPN

So I was working with a Cisco ASA 5510. The inside network was 10.0.0.0/24. I had created a  remote access vpn policy for users and set them up to receive address's on their inside network (10.0.0.0/24). While the users we able to connect fine to the vpn they were not able to ping or access any...


April 30, 2009  8:45 PM

Watchguard MUVPN not working due to Mcafee firewall



Posted by: Jason Tramer
firewall, mcaffee, VPN, WatchGuard

I hate personal firewall products but none so much as I hate mcafee. I was testing a MUVPN and the tunnell just wouldn't established. I turned that thing into swiss cheese, it shouldn't have been blocking anything but the VPN tunnel STILL wouldn't come up until I actually turned off the service....