|
spouseele -> RE: SonicWall Global VPN Client through ISA 2000 (9.Nov.2006 3:11:57 PM)
|
Hi Steven, if you look in the external trace and compare it with the internal one (filtered on ip.addr == 217.40.216.138), you can see that the IKE packets are indeed sent by the ISA server with as source IP the primary IP address assigned to the ISA external interface and a source port different from UDP 500. However, I can make the folllowing two comments on it: - The two IP fragments we saw on the internal network are now combined by ISA server into one non-fragmented IP packet. The content of the packet (the IKE packet) is however the same, including the NAT-T capability proposal.
- I see each time two identical packets with an interval of only a 0.050 msec (frame 213/214, 887/888, 1531/1532, etc...). Unless it is an Ethereal/Wireshark capture issue, that doesn't sound good!
Note: if possible, disable IP routing on ISA (IP Packet Filters properties) and see if it solves that problem of 'duplicating' packets. If not, I suggest you call Microsoft PSS to resolve that problem. Nevertheless, the IKE packets are sent by the ISA server. So, why doesn't the remote VPN gateway respond? Does the remote box accept IKE packets with a source port different from UDP port 500? That's the only reason I could think of! HTH Stefaan
|
|
|
|