Netgear FVS318 v1 Firmware 2.4 VPN to Cisco ASA

View: New views
6 Messages — Rating Filter:   Alert me  

Netgear FVS318 v1 Firmware 2.4 VPN to Cisco ASA

by Jeremy Sutton-2 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

I have a client using a FVS318 v1 firmware 2.4 router trying to connect to a Cisco ASA.  I am the administrator of the Netgear but the administrator of the Cisco ASA can't get his end configured to communicate with the Netgear.  P1 establishes but P2 does not.  Anyone have any suggestions I can pass along to him.  The FVS318 connects fine to another FVS318 but not to his Cisco.  Any help will be greatly appreciated.  Thank you!

Jeremy Sutton
President
Tech Gooroos Technology Consulting, Inc.
p: 919-373-4414
c: 919-413-2463
f: 919-510-6254




_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

Re: Netgear FVS318 v1 Firmware 2.4 VPN to Cisco ASA

by Christopher J. Wargaski :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Jeremy--

   Try with a simple configuration for phase 2, say 3DES and SHA-1, without PFS. Then work your way up to AES-256

cjw


On Mon, May 4, 2009 at 10:38 AM, Jeremy Sutton <jsutton@...> wrote:
I have a client using a FVS318 v1 firmware 2.4 router trying to connect to a Cisco ASA.  I am the administrator of the Netgear but the administrator of the Cisco ASA can't get his end configured to communicate with the Netgear.  P1 establishes but P2 does not.  Anyone have any suggestions I can pass along to him.  The FVS318 connects fine to another FVS318 but not to his Cisco.  Any help will be greatly appreciated.  Thank you!

Jeremy Sutton
President
Tech Gooroos Technology Consulting, Inc.
p: 919-373-4414
c: 919-413-2463
f: 919-510-6254




_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

Re: Netgear FVS318 v1 Firmware 2.4 VPN to Cisco ASA

by Ove Fagerheim :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Melding
If you have checked all the policy parameters, including timeouts, it might be a NAT problem.
 

Ove Fagerheim

Helgelandskraft AS

-----Opprinnelig melding-----
Fra: firewall-wizards-bounces@... [mailto:firewall-wizards-bounces@...] På vegne av Jeremy Sutton
Sendt: 4. mai 2009 17:39
Til: firewall-wizards@...
Emne: [fw-wiz] Netgear FVS318 v1 Firmware 2.4 VPN to Cisco ASA

I have a client using a FVS318 v1 firmware 2.4 router trying to connect to a Cisco ASA.  I am the administrator of the Netgear but the administrator of the Cisco ASA can't get his end configured to communicate with the Netgear.  P1 establishes but P2 does not.  Anyone have any suggestions I can pass along to him.  The FVS318 connects fine to another FVS318 but not to his Cisco.  Any help will be greatly appreciated.  Thank you!

Jeremy Sutton
President
Tech Gooroos Technology Consulting, Inc.
p: 919-373-4414
c: 919-413-2463
f: 919-510-6254




_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

Re: Netgear FVS318 v1 Firmware 2.4 VPN to Cisco ASA

by Lord Sporkton :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Some parts of this message have been removed. Learn more about Nabble's security policy.
Melding

Out of curiousity, how did you deal with the srcid and dstid?

Last I worked on a Netgear FVS318 it wanted to use name based IDs for the VPN, and I have never been able to get named based vpns to work on a cisco router.

Would you mind posting up both sides of this config if you have found a way to do this?

 

As far as your question:

Is one end on a dynamic IP?

Are you using a range or a network on the FVS side when you define interesting traffic?

Is PFS turned on, on either side? I remember the FVS turning it on by default and the cisco turning it off by default.

 

 

 

From: firewall-wizards-bounces@... [mailto:firewall-wizards-bounces@...] On Behalf Of Ove Fagerheim
Sent: Monday, May 04, 2009 10:47 PM
To: jsutton@...; Firewall Wizards Security Mailing List
Subject: Re: [fw-wiz] Netgear FVS318 v1 Firmware 2.4 VPN to Cisco ASA

 

If you have checked all the policy parameters, including timeouts, it might be a NAT problem.

 

Ove Fagerheim

Helgelandskraft AS

-----Opprinnelig melding-----
Fra: firewall-wizards-bounces@... [mailto:firewall-wizards-bounces@...] På vegne av Jeremy Sutton
Sendt: 4. mai 2009 17:39
Til: firewall-wizards@...
Emne: [fw-wiz] Netgear FVS318 v1 Firmware 2.4 VPN to Cisco ASA

I have a client using a FVS318 v1 firmware 2.4 router trying to connect to a Cisco ASA.  I am the administrator of the Netgear but the administrator of the Cisco ASA can't get his end configured to communicate with the Netgear.  P1 establishes but P2 does not.  Anyone have any suggestions I can pass along to him.  The FVS318 connects fine to another FVS318 but not to his Cisco.  Any help will be greatly appreciated.  Thank you!

Jeremy Sutton
President
Tech Gooroos Technology Consulting, Inc.
p: 919-373-4414
c: 919-413-2463
f: 919-510-6254


No virus found in this incoming message.
Checked by AVG - www.avg.com
Version: 8.5.287 / Virus Database: 270.12.18/2096 - Release Date: 05/04/09 17:51:00


_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

Re: Netgear FVS318 v1 Firmware 2.4 VPN to Cisco ASA

by Orca-4 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Some parts of this message have been removed. Learn more about Nabble's security policy.
Jeremy,

If the ASA side is using the ASDM it likes to turn on PFS (Perfect Forward Secrecy), which is almost always overlooked, and will cause a P2 failure.

-----Opprinnelig melding-----
Fra: firewall-wizards-bounces@... [mailto:firewall-wizards-bounces@...] På vegne av Jeremy Sutton
Sendt: 4. mai 2009 17:39
Til: firewall-wizards@...
Emne: [fw-wiz] Netgear FVS318 v1 Firmware 2.4 VPN to Cisco ASA

I have a client using a FVS318 v1 firmware 2.4 router trying to connect to a Cisco ASA.  I am the administrator of the Netgear but the administrator of the Cisco ASA can't get his end configured to communicate with the Netgear.  P1 establishes but P2 does not.  Anyone have any suggestions I can pass along to him.  The FVS318 connects fine to another FVS318 but not to his Cisco.  Any help will be greatly appreciated.  Thank you!

Jeremy Sutton
President
Tech Gooroos Technology Consulting, Inc.
p: 919-373-4414
c: 919-413-2463
f: 919-510-6254


No virus found in this incoming message.
Checked by AVG - www.avg.com
Version: 8.5.287 / Virus Database: 270.12.18/2096 - Release Date: 05/04/09 17:51:00



Hotmail® has a new way to see what's up with your friends. Check it out.
_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

Re: Netgear FVS318 v1 Firmware 2.4 VPN to Cisco ASA

by Jeremy Sutton-2 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Some parts of this message have been removed. Learn more about Nabble's security policy.

Thank you for your response!  The ASA is configured by a 3rd party and they finally got in contact with Cisco and they fixed the ASA for them.  I will look and see if they happened to turn on PFS.  Thank you again!

 


From: firewall-wizards-bounces@... [mailto:firewall-wizards-bounces@...] On Behalf Of orca
Sent: Tuesday, May 05, 2009 3:23 PM
To: firewall-wizards@...
Subject: Re: [fw-wiz] Netgear FVS318 v1 Firmware 2.4 VPN to Cisco ASA

 

Jeremy,

If the ASA side is using the ASDM it likes to turn on PFS (Perfect Forward Secrecy), which is almost always overlooked, and will cause a P2 failure.

-----Opprinnelig melding-----
Fra: firewall-wizards-bounces@... [mailto:firewall-wizards-bounces@...] På vegne av Jeremy Sutton
Sendt: 4. mai 2009 17:39
Til: firewall-wizards@...
Emne: [fw-wiz] Netgear FVS318 v1 Firmware 2.4 VPN to Cisco ASA

I have a client using a FVS318 v1 firmware 2.4 router trying to connect to a Cisco ASA.  I am the administrator of the Netgear but the administrator of the Cisco ASA can't get his end configured to communicate with the Netgear.  P1 establishes but P2 does not.  Anyone have any suggestions I can pass along to him.  The FVS318 connects fine to another FVS318 but not to his Cisco.  Any help will be greatly appreciated.  Thank you!

Jeremy Sutton
President
Tech Gooroos Technology Consulting, Inc.
p: 919-373-4414
c: 919-413-2463
f: 919-510-6254

No virus found in this incoming message.
Checked by AVG - www.avg.com
Version: 8.5.287 / Virus Database: 270.12.18/2096 - Release Date: 05/04/09 17:51:00

 


Hotmail® has a new way to see what's up with your friends. Check it out.


_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards