Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

VPN is up and working but cannot access to dlink 804 site

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> VPN >> VPN is up and working but cannot access to dlink 804 site Page: [1]
Login
Message << Older Topic   Newer Topic >>
VPN is up and working but cannot access to dlink 804 site - 7.Aug.2008 5:01:30 AM   
zamacola

 

Posts: 2
Joined: 7.Aug.2008
Status: offline
I have a IPSEC Site to Site tunnel beetwin a DLink 804 and ISAServer.
From DLink network we can Access to shared folders, Terminal Server, Exchange, etc.
From ISAServer network we cannot open shared folders, access to remote PCs by Terminal Server or open http configuration page of Dlink or remote printer.
ISA server log show the following error:


Intento de conexión erróneo 28VOL-A-SV03 07/08/2008 10:40:23
Tipo de registro: Proxy web (directo)
Estado: 10065 Se ha intentado una operación de socket en un host no accesible. 
Regla: [System] Permitir todo el tráfico HTTP desde el servidor ISA hacia todas las redes (para las descargas de CRL)
Origen: Host local (80.59.188.126)
Destino: Castellana (192.168.3.1:80)
Petición: GET http://192.168.3.1/
Información de filtro: Req ID: 0f705fa0; Compression: client=No, server=No, compress rate=0% decompress rate=0%
Protocolo: http
Usuario: anonymous
 Información adicional
Agente del cliente: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Origen del objeto: Internet (El origen es Internet. El objeto se había agregado a la caché.)
Información de la caché: 0x0
Tiempo de procesamiento: 63094 Tipo MIME:

This message say something like that "you try a socket operation to an accessible host”
On DLink side, we have the following:


WAN Type: Static IP Address (V1.51)


[80.59.188.126|192.168.0.0] phase 2');L2(18000,' IKE phase2 (IPSec SA) remove : 192.168.3.0 192.168.0.0');L2(18000,' inbound SPI = 0x1100eaf3, outbound SPI = 0x4d949fcf');L2(18000,' Send IKE (INFO) : delete 217.127.197.124 -> 80.59.188.126 phase 1');L2(18000,' IKE phase1 (ISAKMP SA) remove : 217.127.197.124 80.59.188.126');L2(17000,' Send IKE M1(INIT) : 217.127.197.124 --> 80.59.188.126');L2(17000,' Receive IKE M2(RESP) : 80.59.188.126 --> 217.127.197.124');L2(17000,' Try to match with ENC:3DES AUTH:PSK HASH:SHA1 Group:Group2');L2(17000,' Send IKE M3(KEYINIT) : 217.127.197.124 --> 80.59.188.126');L2(16500,' Receive IKE M4(KEYRESP) : 80.59.188.126 --> 217.127.197.124');L2(16500,' Send IKE M5(IDINIT) : 217.127.197.124 --> 80.59.188.126');L2(16500,' Receive IKE M6(IDRESP) : 80.59.188.126 --> 217.127.197.124');L2(16500,' IKE Phase1 (ISAKMP SA) established : 80.59.188.126 217.127.197.124');L2(16000,' Send IKE Q1(QINIT) : 192.168.3.0 --> 192.168.0.0');L2(16000,' Receive IKE Q2(QRESP) : [192.168.0.0|80.59.188.126]-->[217.127.197.124|192.168.3.0]');L2(16000,' Try to match ESP with MODE:Tunnel PROTOCAL:ESP-3DES AUTH:SHA1 HASH:Others PFS(Group):Group2');L2(16000,' Send IKE Q3(QHASH) : 192.168.3.0 --> 192.168.0.0');L2(16000,' IKE Phase2 (IPSEC SA) established : [192.168.0.0|80.59.188.126][217.127.197.124|192.168.3.0]');L2(16000,' inbound SPI = 0x1400a86b, outbound SPI = 0x9da55f6');L2(15500,' IKED quick mode Notify : ISAKMP_NMT_CONNECTED');

var f=document.forms[0]
if(cur==0)f._pp.disabled=true;
if(cur==pages)f._np.disabled=true;
//-->

Display time: Thursday August 07, 2008 09:50:40

Thursday August 07, 2008 09:50:22 Send IKE (INFO) : delete [192.168.3.0|217.127.197.124]-->[80.59.188.126|192.168.0.0] phase 2
Thursday August 07, 2008 09:50:22 IKE phase2 (IPSec SA) remove : 192.168.3.0 <-> 192.168.0.0
Thursday August 07, 2008 09:50:22 inbound SPI = 0x1100eaf3, outbound SPI = 0x4d949fcf
Thursday August 07, 2008 09:50:22 Send IKE (INFO) : delete 217.127.197.124 -> 80.59.188.126 phase 1
Thursday August 07, 2008 09:50:22 IKE phase1 (ISAKMP SA) remove : 217.127.197.124 <-> 80.59.188.126
Thursday August 07, 2008 09:50:23 Send IKE M1(INIT) : 217.127.197.124 --> 80.59.188.126
Thursday August 07, 2008 09:50:23 Receive IKE M2(RESP) : 80.59.188.126 --> 217.127.197.124
Thursday August 07, 2008 09:50:23 Try to match with ENC:3DES AUTH:PSK HASH:SHA1 Group:Group2
Thursday August 07, 2008 09:50:23 Send IKE M3(KEYINIT) : 217.127.197.124 --> 80.59.188.126
Thursday August 07, 2008 09:50:23 Receive IKE M4(KEYRESP) : 80.59.188.126 --> 217.127.197.124
Thursday August 07, 2008 09:50:23 Send IKE M5(IDINIT) : 217.127.197.124 --> 80.59.188.126
Thursday August 07, 2008 09:50:23 Receive IKE M6(IDRESP) : 80.59.188.126 --> 217.127.197.124
Thursday August 07, 2008 09:50:23 IKE Phase1 (ISAKMP SA) established : 80.59.188.126 <-> 217.127.197.124
Thursday August 07, 2008 09:50:24 Send IKE Q1(QINIT) : 192.168.3.0 --> 192.168.0.0
Thursday August 07, 2008 09:50:24 Receive IKE Q2(QRESP) : [192.168.0.0|80.59.188.126]-->[217.127.197.124|192.168.3.0]
Thursday August 07, 2008 09:50:24 Try to match ESP with MODE:Tunnel PROTOCAL:ESP-3DES AUTH:SHA1 HASH:Others PFS(Group):Group2
Thursday August 07, 2008 09:50:24 Send IKE Q3(QHASH) : 192.168.3.0 --> 192.168.0.0
Thursday August 07, 2008 09:50:24 IKE Phase2 (IPSEC SA) established : [192.168.0.0|80.59.188.126]<->[217.127.197.124|192.168.3.0]
Thursday August 07, 2008 09:50:24 inbound SPI = 0x1400a86b, outbound SPI = 0x9da55f6
Thursday August 07, 2008 09:50:24 IKED quick mode Notify : ISAKMP_NMT_CONNECTED

Thursday August 07, 2008 09:50:24 IKED quick mode Notify : ISAKMP_NMT_CONNECTED
Thursday August 07, 2008 09:50:36 Receive IKE Q1(QINIT) : [80.59.188.126]-->[217.127.197.124]
Thursday August 07, 2008 09:50:36 SPD Error : not found [80.59.188.126]<->[192.168.3.0] from peer IP address 80.59.188.126
Thursday August 07, 2008 09:50:36 error = 77
Thursday August 07, 2008 09:50:37 Receive IKE Q1(QINIT) : [80.59.188.126]-->[217.127.197.124]
Thursday August 07, 2008 09:50:37 SPD Error : not found [80.59.188.126]<->[192.168.3.0] from peer IP address 80.59.188.126
Thursday August 07, 2008 09:50:37 error = 77
Thursday August 07, 2008 09:50:39 Receive IKE Q1(QINIT) : [80.59.188.126]-->[217.127.197.124]
Thursday August 07, 2008 09:50:39 SPD Error : not found [80.59.188.126]<->[192.168.3.0] from peer IP address 80.59.188.126
Thursday August 07, 2008 09:50:39 error = 77
Thursday August 07, 2008 09:50:43 Receive IKE Q1(QINIT) : [80.59.188.126]-->[217.127.197.124]
Thursday August 07, 2008 09:50:43 SPD Error : not found [80.59.188.126]<->[192.168.3.0] from peer IP address 80.59.188.126
Thursday August 07, 2008 09:50:43 error = 77
Thursday August 07, 2008 09:50:51 Receive IKE Q1(QINIT) : [80.59.188.126]-->[217.127.197.124]
Thursday August 07, 2008 09:50:51 SPD Error : not found [80.59.188.126]<->[192.168.3.0] from peer IP address 80.59.188.126
Thursday August 07, 2008 09:50:51 error = 77
Thursday August 07, 2008 09:51:07 Receive IKE Q1(QINIT) : [80.59.188.126]-->[217.127.197.124]
Thursday August 07, 2008 09:51:07 SPD Error : not found [80.59.188.126]<->[192.168.3.0] from peer IP address 80.59.188.126
Thursday August 07, 2008 09:51:07 error = 77


I think the problem is on DLink. I've reported the 77 error to DLink but I have no response except to upgrede firmware from 1.44 to 1.51. The problems persist.
 
Any help will be appreciate. Best regards.

< Message edited by zamacola -- 7.Aug.2008 5:21:33 AM >
Post #: 1
RE: VPN is up and working but cannot access to dlink 80... - 8.Aug.2008 11:04:19 AM   
justmee

 

Posts: 505
Joined: 14.May2007
Status: offline
Hi Fernando,
Looking to your logs:
on ISA:
Local: 192.168.0.0/24
Remote: 192.168.3.0/24
IKE: PSK, DH Group2, 3DES, SHA-1
ESP: PFS DH Group2, 3DES, SHA-1,

Dlink:
Local:192.168.3.0/24
Remote:192.168.0.0/24
IKE: PSK, DH Group2, 3DES, SHA-1
ESP: PFS DH Group2, 3DES, SHA-1,

IKE MM and QM for the above settings are successful, at least according to the Dlink. You end up with two SA's inbound and outbound.

The Dlink tells ISA to delete the established IPsec and IKE SAs.
Then here we go again.
After that it appears that ISA tries to establish an IPsec SA for its public IP address and the remote net.
You only have SAs for the the proxy identities 192.168.0.0/24 and 192.168.3.0/24.

So:
- what network relationship you have on ISA between the local network and the remote site ?
It suppose to be a route relationship and not NAT.
- are you testing from ISA itself. Don't do that, test from a host behind ISA to a host behind Dlink and vice-versa. If you really want to test from ISA itself, then read this:
http://www.isaserver.org/tutorials/Troubleshooting-IPSec-Tunnel-Mode-Scenarios.html
- also, if you use the web proxy on ISA(your local clients are Web proxy clients) for HTTP connection to access hosts located on the remote network, I think you need to make the required changes as suggested in the above article.

Regards,
J

< Message edited by justmee -- 8.Aug.2008 11:08:58 AM >

(in reply to zamacola)
Post #: 2
RE: VPN is up and working but cannot access to dlink 80... - 11.Aug.2008 12:34:06 PM   
zamacola

 

Posts: 2
Joined: 7.Aug.2008
Status: offline
Hi justme:

First of all, thanks for your help.

- I have a ROUTE relationship from DLink to Internal network.
- I`m also testing from a member server (isaserver network).I try to open 192.168.3.1 (Dlink IP) DLink configuration page and 192.168.3.30 printer configuration page, also I try to access by terminal server (remote desktop connection) to 192.168.3.50 (It's available from local network, I tested it). I have the same results.
- The web proxy on ISA is up. I have the external IP address of the opposing ISA firewall into the Addresses tab of the connection. But on DLink side, I don't know where I must especify the external IP address or if it's included by itself.

C:\Documents and Settings\Administrador>netsh ipsec dynamic show qmfilter all
Filtros de modo rápido(Transporte):Genérico
-------------------------------------------------------------------------------
Nombre de filtro            : L2TP Server Filter1
Tipo de conexión        : ALL
Dirección de origen    : <Cualquier dirección IP>  (0.0.0.0        )
Dirección de destino   : <Mi dirección IP>   (255.255.255.255)
Protocolo              : UDPPuerto Orig: 0     Puerto Dest: 1701
Reflejado              : sí
Directiva de modo rápido      : L2TP Optional Encryption Quick Mode Policy
Acción de entrada      : Negotiate
Acción de salida       : Negotiate

-------------------------------------------------------------------------------
Nombre de filtro            : L2TP Server Inbound Filter
Tipo de conexión        : ALL
Dirección de origen    : <Cualquier dirección IP>  (0.0.0.0        )
Dirección de destino   : <Mi dirección IP>   (255.255.255.255)
Protocolo              : UDPPuerto Orig: 1701  Puerto Dest: 1701
Reflejado              : no
Directiva de modo rápido      : L2TP Optional Encryption Quick Mode Policy
Acción de entrada      : Negotiate
Acción de salida       : Negotiate

-------------------------------------------------------------------------------
Nombre de filtro            : L2TP Server Inbound Filter
Tipo de conexión        : ALL
Dirección de origen    : <Cualquier dirección IP>  (0.0.0.0        )
Dirección de destino   : <Mi dirección IP>   (255.255.255.255)
Protocolo              : UDPPuerto Orig: 1701  Puerto Dest: 0
Reflejado              : no
Directiva de modo rápido      : L2TP Optional Encryption Quick Mode Policy
Acción de entrada      : Negotiate
Acción de salida       : Negotiate

-------------------------------------------------------------------------------
Nombre de filtro            : L2TP Server Outbound Filter
Tipo de conexión        : ALL
Dirección de origen    : <Mi dirección IP>   (255.255.255.255)
Dirección de destino   : <Cualquier dirección IP>  (0.0.0.0        )
Protocolo              : UDPPuerto Orig: 1701  Puerto Dest: 1701
Reflejado              : no
Directiva de modo rápido      : L2TP Optional Encryption Quick Mode Policy
Acción de entrada      : Negotiate
Acción de salida       : Negotiate

-------------------------------------------------------------------------------
Nombre de filtro            : L2TP Server Outbound Filter
Tipo de conexión        : ALL
Dirección de origen    : <Mi dirección IP>   (255.255.255.255)
Dirección de destino   : <Cualquier dirección IP>  (0.0.0.0        )
Protocolo              : UDPPuerto Orig: 0     Puerto Dest: 1701
Reflejado              : no
Directiva de modo rápido      : L2TP Optional Encryption Quick Mode Policy
Acción de entrada      : Negotiate
Acción de salida       : Negotiate

5 filtros genéricos
Filtros de modo rápido(Túnel):Genérico
-------------------------------------------------------------------------------
Nombre de filtro            : IPSec{58AE5E54-339A-4E45-9FEB-08A228210E06}
Tipo de conexión        : ALL
Dirección de origen    : 192.168.0.0       (255.255.255.0  )
Dirección de destino   : 192.168.3.0       (255.255.255.0  )
Origen de túnel        : <Cualquier dirección IP>
Destino de túnel       : 217.127.197.124
Protocolo              : ANYPuerto Orig: 0     Puerto Dest: 0
Reflejado              : no
Directiva de modo rápido      : ISA Server Castellana QM Policy
Acción de entrada      : Negotiate
Acción de salida       : Negotiate

-------------------------------------------------------------------------------
Nombre de filtro            : IPSec{0BCD8CA1-1F91-488C-9EE2-097628B653FF}
Tipo de conexión        : ALL
Dirección de origen    : 192.168.3.0       (255.255.255.0  )
Dirección de destino   : 192.168.0.0       (255.255.255.0  )
Origen de túnel        : <Cualquier dirección IP>
Destino de túnel       : 80.59.188.126
Protocolo              : ANYPuerto Orig: 0     Puerto Dest: 0
Reflejado              : no
Directiva de modo rápido      : ISA Server Castellana QM Policy
Acción de entrada      : Negotiate
Acción de salida       : Negotiate

-------------------------------------------------------------------------------
Nombre de filtro            : IPSec{345A9756-8BEF-4501-9C47-BDDC3631A1FD}
Tipo de conexión        : ALL
Dirección de origen    : 192.168.0.0       (255.255.255.0  )
Dirección de destino   : 217.127.197.124   (255.255.255.255)
Origen de túnel        : <Cualquier dirección IP>
Destino de túnel       : 217.127.197.124
Protocolo              : ANYPuerto Orig: 0     Puerto Dest: 0
Reflejado              : no
Directiva de modo rápido      : ISA Server Castellana QM Policy
Acción de entrada      : Negotiate
Acción de salida       : Negotiate

-------------------------------------------------------------------------------
Nombre de filtro            : IPSec{E966B8BE-B792-46C2-9F31-509AA58F7B42}
Tipo de conexión        : ALL
Dirección de origen    : 217.127.197.124   (255.255.255.255)
Dirección de destino   : 192.168.0.0       (255.255.255.0  )
Origen de túnel        : <Cualquier dirección IP>
Destino de túnel       : 80.59.188.126
Protocolo              : ANYPuerto Orig: 0     Puerto Dest: 0
Reflejado              : no
Directiva de modo rápido      : ISA Server Castellana QM Policy
Acción de entrada      : Negotiate
Acción de salida       : Negotiate

-------------------------------------------------------------------------------
Nombre de filtro            : IPSec{683382D3-07CF-47BB-858B-23EFED835857}
Tipo de conexión        : ALL
Dirección de origen    : 80.59.188.126     (255.255.255.255)
Dirección de destino   : 192.168.3.0       (255.255.255.0  )
Origen de túnel        : <Cualquier dirección IP>
Destino de túnel       : 217.127.197.124
Protocolo              : ANYPuerto Orig: 0     Puerto Dest: 0
Reflejado              : no
Directiva de modo rápido      : ISA Server Castellana QM Policy
Acción de entrada      : Negotiate
Acción de salida       : Negotiate

-------------------------------------------------------------------------------
Nombre de filtro            : IPSec{A5279D2D-2887-49D0-97AC-C00EF5E744D4}
Tipo de conexión        : ALL
Dirección de origen    : 192.168.3.0       (255.255.255.0  )
Dirección de destino   : 80.59.188.126     (255.255.255.255)
Origen de túnel        : <Cualquier dirección IP>
Destino de túnel       : 80.59.188.126
Protocolo              : ANYPuerto Orig: 0     Puerto Dest: 0
Reflejado              : no
Directiva de modo rápido      : ISA Server Castellana QM Policy
Acción de entrada      : Negotiate
Acción de salida       : Negotiate

-------------------------------------------------------------------------------
Nombre de filtro            : IPSec{C2D4796F-0252-4E82-9896-5F30F37640A5}
Tipo de conexión        : ALL
Dirección de origen    : 80.59.188.126     (255.255.255.255)
Dirección de destino   : 217.127.197.124   (255.255.255.255)
Origen de túnel        : <Cualquier dirección IP>
Destino de túnel       : 217.127.197.124
Protocolo              : ANYPuerto Orig: 0     Puerto Dest: 0
Reflejado              : no
Directiva de modo rápido      : ISA Server Castellana QM Policy
Acción de entrada      : Negotiate
Acción de salida       : Negotiate

-------------------------------------------------------------------------------
Nombre de filtro            : IPSec{29F96951-3DEF-407E-A659-7C9E14D4E1BE}
Tipo de conexión        : ALL
Dirección de origen    : 217.127.197.124   (255.255.255.255)
Dirección de destino   : 80.59.188.126     (255.255.255.255)
Origen de túnel        : <Cualquier dirección IP>
Destino de túnel       : 80.59.188.126
Protocolo              : ANYPuerto Orig: 0     Puerto Dest: 0
Reflejado              : no
Directiva de modo rápido      : ISA Server Castellana QM Policy
Acción de entrada      : Negotiate
Acción de salida       : Negotiate

8 filtros genéricos

Regards

(in reply to justmee)
Post #: 3
RE: VPN is up and working but cannot access to dlink 80... - 11.Aug.2008 4:45:15 PM   
justmee

 

Posts: 505
Joined: 14.May2007
Status: offline
Hi Fernando,
I have no clue about Dlink. Never used them.
If that was a Cisco router for example, I could tell you what crypto acl to add on it, but I don't know with the Dlink.
The IPsec filters on ISA seem good, although my spanish is not that good.

So you cannot ping from a host behind ISA to a host behind Dlink ?
When you ping like so, what do the logs on ISA tell you ?
Do you have the required access rule on ISA, from Internal to remote net and vice-versa ?
If you have a route network relationship on ISA, between Internal and remote net, that's good.

If you want to access a server on the remote network, from a host behind ISA, using HTTP, set this host, for the tests, as SecureNat client. Do not use the web proxy on ISA. When you use the proxy on ISA, I think the packets get sourced from ISA itself, and you do not have the needed "IPsec filters" on Dlink.

Your Dlink logs show that IKE QM negotiations went fine, so theoretically you had the required "IPsec filter" on Dlink too for "normal" traffic, say from a host behind ISA to a host behind Dlink and vice-versa.

If you can access from a host behind Dlink a host behind ISA, one part is working, we need to figure it out what happens with the packets coming from the opposite direction.

Regards,
J

(in reply to zamacola)
Post #: 4

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> VPN >> VPN is up and working but cannot access to dlink 804 site Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts