If You use NetGear with ModeConfig you must use XAUTH because NetGear has bug 
in their products (only NetScreen works OK on configuration with modeconfig and 
xauth disabled)

Next basic thing is that ModeConfig IP pull must be different of LAN and WAN so 
You can't use the same subment 192.168.1.x
Change mode-config adresses to 192.168.2.x and it will be fine (NetGear has 
default routing so You don't need to change anything on clients computers)

Regards,
 Michal Wegrzyn
  ----- Original Message ----- 
  From: [email protected] 
  To: [email protected] 
  Sent: Sunday, May 09, 2010 6:14 PM
  Subject: Re: [vpn-help] VPN not passing traffic using Shrew Client


  Hi Kevin,
  Thanks so much for your response. 

  To your post:

  1) I do not have overlapping local LAN IP address ranges.
  In fact, my local LAN address is 10.0.0.x and the remote lan address (behind 
the VPN router) is in the 192.168.1.175 -to-192.168.1.195 range. So no problem 
there.
  So listed:
  192.168.1.1 is the VPN's local network gateway address.
  192.168.1.175 thru 195 is the DHCP address range as set up in the Netgear 
mode-config for VPN clients connecting.
  255.255.255.0 is the network mask used by VPN and client so that they match 
on both ends.

  The WAN address is NOT static unfortunately as Comcast refused the business 
owner. As a workaround, we're using dyndns.org.

  2) I will uninstall 2.1.5 in favor of the 2.1.6 beta and see if this helps.
  Is there any log file or any other source of information that I could post 
that would perhaps give greater visibilty into the issue?

  Thanks again,
  Mike

   






  -----Original Message-----
  From: kevin shrew-vpn <[email protected]>
  To: [email protected]
  Sent: Sun, May 9, 2010 11:27 am
  Subject: Re: [vpn-help] VPN not passing traffic using Shrew Client


On Sun, 09 May 2010 10:12:12 -0400
[email protected] wrote:

> 
> I am running Shrew Client (2.1.5) on Windows XP connecting to a
> Netgear VPN Prosafe FVS318G at a remote site. I have configured the
> client according to Shrew's "How-To" for a similar model Netgear
> Prosafe VPNs. 
> 
> The Tunnel connection succeeds and I can see in the VPN log (on the
> prosafe router) that the SA Connection is also established
> successfully. On the VPN client side the Shrewsoft VPN trace output
> shows that the SA is Mature. The problem is that when I ping the VPN
> router's LAN address (192.168.1.1) ping returns no hits. Essentially
> the packets are being dropped.
> 

Hi Mike, I can think of two reasons it might not work.  

First, since your VPN gateway uses private addresses 192.168.1.1, is it possible
that you have overlapping private subnets at both ends of the tunnel?
Try to change one of your address ranges if they are overlapping.

Secondly, in Shrew 2.1.5, if you configure the Policy such that the VPN
gateway IP is in the tunnel range, Shrew will try to tunnel the traffic
destined for the gateway IP.  The later betas of 2.1.6 resolve this
issue.
_______________________________________________
vpn-help mailing list
[email protected]
http://lists.shrew.net/mailman/listinfo/vpn-help


------------------------------------------------------------------------------


  _______________________________________________
  vpn-help mailing list
  [email protected]
  http://lists.shrew.net/mailman/listinfo/vpn-help
_______________________________________________
vpn-help mailing list
[email protected]
http://lists.shrew.net/mailman/listinfo/vpn-help

Reply via email to