08-10-2004 06:51 PM - edited 02-21-2020 01:17 PM
We started testing Windows XP SP2 last week and have run into an interesting issue. If you enable the XP SP2 Firewall services it will disrupt Cisco VPN from establishing a connection over TCP. I've created an exception for the application, but that doesn't resolve the issues.
Note: if you change the connection to UDP/10000 it works just fine, but IPSec thru NAT over TCP/443 will not work.
Using "capture" on my PIX i can compare a successful connection (firewall off) and a failed connection (firewall on). On the failed attempt the ACK packet from the host to the VPN concentrator is blocked. Unfortunately the winXP debugging is essentially useless.
Has anyone run into a similar issue? Any assistance would be appreciated.
Solved! Go to Solution.
08-11-2004 06:20 PM
Create an exception in the Windows Firewall to allow port 62515/udp. The scope should be any computer. It is my understanding that Cisco is working on an updated version of the client that will address this, but this should work in the interim.
08-11-2004 06:20 PM
Create an exception in the Windows Firewall to allow port 62515/udp. The scope should be any computer. It is my understanding that Cisco is working on an updated version of the client that will address this, but this should work in the interim.
08-11-2004 06:28 PM
Thanks - that did the trick! bit of an ugly/odd workaround, but it worked. Do you happen to know what the requirement for this exception is based on?
08-16-2004 09:10 PM
What version client are you using?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide