cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
18918
Views
5
Helpful
6
Replies

Cisco VPN Clients service ports that needed

cindylee27
Level 1
Level 1

Hi Experts,

I would like to check what ports are needed to establish a complete VPN and also to complete the connection to the GFTP Server.

What happened is , the VPN connection able to establish but as the corporate firewall has open 500/udp for this vpn connection, but when trying to connect to the GFTP Server using port 21/tcp or 22/tcp, it is not able to go through.

Can i know what other service ports needed?

Thanks in advanced.

cindy

6 Replies 6

5220
Level 4
Level 4

Hi Cindy,

The UDP 500 (ISAKMP) port is used only for the first phase of the VPN tunnel.

Depending on your configuration you also need to open UDP 4500 (NAT-T port used for data traffic behind NAT systems), UDP 10000 (old NAT-T port used by Cisco sometimes) and IP 50 protocol (raw ESP packes when no NAT-T is negociated).

This will do.

Please rate if this helped.

Regards,

Daniel

Thanks Daniel.

What time of configuration you referring to here?

Thanks again,

cindy

Hi Cindy,

The Access-list will need to allow the VPN traffic over the Internet on ports UDP 500, 10000, 4500 and IP 50.

On your Internal network, behind the VPN box you need to enable the application ports: TCP 22, TCP 21, TCP 20 and so on.

Please rate if this helped.

Regards,

Daniel

Daniel,

Thanks..What i dun understand is..why the firewall still can detect the ports 4500/tcp even though the VPN tunnel has been established?

Thanks,

Regards,

cindy

Hi Cindy,

It is possible that the VPN box is configured for NAT-T over TCP.

You can open the TCP 4500 also on the firewalls.

Please rate if this helped.

Regards,

Daniel

a.alekseev
Level 7
Level 7

Do you have access to any other Servers through the VPN connection?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: