Re: VPN over UMTS



Frank Winkler schrieb:
Hi guys !

I'm not sure if the USA group can give any input to this or if I have a somehow European problem as it's related to a UMTS connection. Our company has some "try and buy" UMTS boxes from the German provider T-Mobile. In the default configuration, they assign private IP addresses and apparently do NAT for Internet access. In this setup, the Cisco VPN client does not work but as soon as I'm requesting a public address (this can be done in the software), things work fine.
Does anybody know why it doesn't work with the private address and NAT? It should be quite the same as with NAT behind a DSL router (which also works), shouldn't it? We'd prefer the NAT thing fort security reasons.

I have some road warriors with T-Mobile UMTS cards and Cisco VPN clients working.

With Vodafone cards I regularly have timeouts after about 10 minutes. Vodafone offers a public IP address to the client and the VPN Client does NOT use udp encapsulation for NAT/PAT traversal. It seem that Vodafone does not count the esp protocol for their idle-timeout.

I don't have such problem with the T-Mobile cards (at least at the moment)

I'm terminating the VPN clients on an IOS router.

--
Uli
.



Relevant Pages

  • Re: Cant get L2TP VPN working with NAT...PPTP works fine
    ... My wife uses a VPN client over the same network connection that I use. ... The second I put my pc behind a router with nat (netgear ...
    (microsoft.public.win2000.networking)
  • Re: Using Cisco VPN over a SBS 2003 network
    ... You'll have to examine the VPN client & server configuration, but the defaults for both are to use "native" IPSec, which does not ... tolerate NAT. ... IPSec NAT-T to change the source port. ... Incompatibility between fixed IKE source ports and NAPT. ...
    (microsoft.public.windows.server.sbs)
  • Re: Connection to SonicWall VPN through Linux IPTABLES Firewall/Proxy
    ... >> unable to connect to a SonicWall VPN server from behind that box. ... Given that all NAT traffic is going to ... I don't think that's actually required when the packets are being ... > I use a Cisco VPN client through my firewall without a problem. ...
    (comp.security.firewalls)
  • Watchguard VPN client through Firewall-1 v4.1
    ... Quick question to see if this is possible before I go spending lots of time ... Locally I have a Windows XP client, ... We are using NAT and the VPN/Firewall at the other end also uses NAT is this ... PS I tried a the Cisco VPN client to a PIX and saw similar problems. ...
    (comp.security.firewalls)
  • VPN over UMTS
    ... I'm not sure if the USA group can give any input to this or if I have a somehow European problem as it's related to a UMTS connection. ... they assign private IP addresses and apparently do NAT for Internet access. ...
    (comp.dcom.sys.cisco)