VPN router w/ client software

rustynails

Banned
Jun 22, 2005
115
0
0
Ive been using watchguards 6tc with the safenet vpn client to connect some of my customers remotely. I was wondering what others are using out there. Recently it has come to light that the 6tc from watchguard has compatibility problems with motorola SB5120 cable modems, I can not receive DHCP nor will a static address work on the wan port. Ive tried to different modems and 2 different 6tc. Both funtion correctly when indepent of each other, in other words i can get a DHCP address from a linksys, i can also get the linksys to supply a DHCP address to the 6tc. Any suggestions out there?

~n
 

DarkJuJu

Member
Dec 30, 2003
40
0
0
If all your customers are using WG soho's i would buy a cheap used fireboxII or III and setup
DVCP VPNs to your customers and a PPTP to the Firebox so you would have access from anywere. I have a few older fireboxes if your interested.
 

Crusty

Lifer
Sep 30, 2001
12,684
2
81
We use a Firebox III/700 with a combination of SOHO 6's for our branch offices and for at home support people. We also have a few laptops that use the WinXP vpn client, and we have an IPSEC tunnel to another Firebox that we use for CCA
 

Woodie

Platinum Member
Mar 27, 2001
2,747
0
0
Nortel client & switch, migrating to Cisco client & concentrator. The endpoints are >95% clients, while the rest are gateways to concentrator.
 

cmetz

Platinum Member
Nov 13, 2001
2,296
0
0
Watchgard is garbage. I can't rip that stuff out fast enough. Most times I'm able to do so, the people who own the gear won't let me give it the violent destruction it so richly deserves. Get rid of it, destroy it, make your life easier.

Anyway, I digress...

Cisco's Windows VPN client is the best by a lot. It's the most compatible client I've seen, and it gets things right like handling Windows login after the VPN connects. I can't strongly enough recommend the Cisco VPN client for Windows.

Head-ends are a bit trickier. The PIX 501/506E are cheap and get the job done at the low end, though they've got a lot of quirks. They're also now a dead platform. The Cisco VPN Concentrator series is interesting if you have a really huge budget, but if you have a really huge budget you also have a lot of other good options to consider (every vendor loves the customers with really huge budgets . In the middle, any router with IOS can run the firewall/IPsec image, but you really want a crypto accelerator too. And only a few of their accelerators support AES encryption, which I consider a mandatory feature in any new VPN purchase. The Cisco ISR 800/1800/2800/3800 series is the official Cisco answer to the problem, and they have good specs and good pricing. What they're bad at is QA, I've seen a whole lot of bugs on that platform that never ever should have made it out the door, and I'm not seeing Cisco make enough progress towards getting those boxes where they need to be. So the moral of this story is, with Cisco, you have to pick your pain on the head-end.

My personal experience is that I'd rather have my pain on the server side and the client side be smooth. One of those is a lot easier for me to debug, and there's a whole lot fewer of them to debug, too.
 

rustynails

Banned
Jun 22, 2005
115
0
0
Thanks for your responses.

Anyhow I finally convinced Cox to come out and take a look, the tech happened to have another cable modem (webstar) to put in place. The watchguard took just fine. So there is a hardware compatiblity issue with new SB5120 (these enable the 1mb upstream). The cox tech stated that they had tier 1 support to motorola and will submit this issue. We'll see...
 

cmetz

Platinum Member
Nov 13, 2001
2,296
0
0
If the 5120 is just a modem (and not also a SOHO router), it's very odd that it would be the culprit. This would lead me to believe that the Motorola cable modem folks are still clueless. (I know they sure were in the past...)
 

rustynails

Banned
Jun 22, 2005
115
0
0
Well,

That just it. 2 5120 and 2 watchguards and still no go. Independently of each other they both seemed to work fine. Additionally, when the tech came out he mentioned that the last time, a couple of months ago, he saw the soho they could not get it to work either. I convinced him to try another modem (since they would not let me activate my own on a business account) and bam functioning perfectly. Luckily my client only has a 512 up.

This is one of those thing that is very hard to troubleshoot, because it not some programming issue, fixed by some clicking on a web gui.

~n
 

DarkJuJu

Member
Dec 30, 2003
40
0
0
Originally posted by: cmetz
Watchgard is garbage. I can't rip that stuff out fast enough. Most times I'm able to do so, the people who own the gear won't let me give it the violent destruction it so richly deserves. Get rid of it, destroy it, make your life easier.

Anyway, I digress...

Cisco's Windows VPN client is the best by a lot. It's the most compatible client I've seen, and it gets things right like handling Windows login after the VPN connects. I can't strongly enough recommend the Cisco VPN client for Windows.

Head-ends are a bit trickier. The PIX 501/506E are cheap and get the job done at the low end, though they've got a lot of quirks. They're also now a dead platform. The Cisco VPN Concentrator series is interesting if you have a really huge budget, but if you have a really huge budget you also have a lot of other good options to consider (every vendor loves the customers with really huge budgets . In the middle, any router with IOS can run the firewall/IPsec image, but you really want a crypto accelerator too. And only a few of their accelerators support AES encryption, which I consider a mandatory feature in any new VPN purchase. The Cisco ISR 800/1800/2800/3800 series is the official Cisco answer to the problem, and they have good specs and good pricing. What they're bad at is QA, I've seen a whole lot of bugs on that platform that never ever should have made it out the door, and I'm not seeing Cisco make enough progress towards getting those boxes where they need to be. So the moral of this story is, with Cisco, you have to pick your pain on the head-end.

My personal experience is that I'd rather have my pain on the server side and the client side be smooth. One of those is a lot easier for me to debug, and there's a whole lot fewer of them to debug, too.

another clueless koolaid drinking cisco clone.
 

rustynails

Banned
Jun 22, 2005
115
0
0
Darkjuju,

Are you able to connect mobile users to the 6tc using only the windowXP vpn client. Ive tried and had no success, the parameters just dont seem to be the same; for what the 6tc is requiring.
 

SaigonK

Diamond Member
Aug 13, 2001
7,482
3
0
www.robertrivas.com
Nortel Contivity box, you name the model and I have it setup somewhere.
Mostly 1100 series units for our branch office tunnels, our major sites have either 1740's or 2700's.

 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |