06-27-2012 08:26 AM
I'm configuring a RV042 and have some questions;
1) Do I understand correctly that PAT rules (created under uPnP) bypass the firewall rules? I need to filter some PAT connections on originating IP and that does not seem to be an option. I tried creating a firewall rule for WAN->LAN to the internal IP configured in the PAT entry but that does not seem to matter, I can connect anyway. Is their a way to accomplish this?
2) QuickVPN does not seem to work for me I get an error and no connection, yet the management webpage of the RV042 shows this user as connected?
Log shows:
2012/06/27 16:20:26 [STATUS]OS Version: Windows XP
2012/06/27 16:20:26 [STATUS]Windows Firewall is OFF
2012/06/27 16:20:26 [STATUS]One network interface detected with IP address 192.168.2.8
2012/06/27 16:20:26 [STATUS]Connecting...
2012/06/27 16:20:26 [DEBUG]Input VPN Server Address = x.x.x.x.
2012/06/27 16:20:26 [STATUS]Connecting to remote gateway with IP address: x.x.x.x
2012/06/27 16:20:26 [WARNING]Server's certificate doesn't exist on your local computer.
2012/06/27 16:20:29 [STATUS]Remote gateway was reached by https ...
2012/06/27 16:20:29 [STATUS]Provisioning...
2012/06/27 16:20:29 [WARNING]Failed to connect.
Wget_error.txt shows:
--16:20:29-- https://user:*password*@x.x.x.x:60443/StartConnection.htm?version=1?IP=192.168.2.8?PASSWD=*password*?USER=user
=> `C://Program Files//Cisco Small Business//QuickVPN Client//vpnserver.conf'
Connecting to x.x.x.x:60443... connected.
HTTP request sent, awaiting response... 200 OK
Length: unspecified [text/html]
0K 164.06 KB/s
If I understand correctly the missing server certificate should not keep you from connecting, you just can't validate the connection is to the correct VPN server. The subnet I'm connecting to is different from the subnet I start the VPN connection from.
Thoughts?
Thanks, Peter
06-27-2012 10:32 AM
Here you can find an example about how to add access rules on top of a port forwarding rule.
https://supportforums.cisco.com/message/3453760#3453760
For the QuickVPN issue, it's more effective if you could call the Support center for assistance.
Meanwhile it's useful to see the VPN logs on RV042, and know the internet connection type of the RV042.
07-02-2012 12:26 AM
Thanks, I'll have a go with the rules and post the VPN logs ASAP.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide