Cable Modems Comcast "business" cable internet; blocking IPSec ISAKMP?

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Comcast "business" cable internet; blocking IPSec ISAKMP? Howard Beale 12-06-05
Posted by Howard Beale on December 6, 2005, 8:43 pm
Please log in for more thread options


Has anyone heard of this actually happening? Googling it brings up a fair
amount of armwaving about this topic circa 2002, but nothing recently.

I have a client with this service at their remote office; their previous
IPSec setup was flakey and we replaced their firewalls on both ends with new
equipment, but when I installed this I've noticed that the tunnel cannot be
brought up with requests from their home office -- it appears that the
ISAKMP packets originating in the home office simply go nowhere.

But if the tunnel is brought up with keying initiated at the remote office,
it works just fine. We verified this behavior by building a second tunnel
to the remote office from our office.

I can only think of two explanations for this phenomena: Comcast is
deliberately blocking inbound ISAKMP packets to mangle IPSec tunnels, or the
cable modem itself has some filtering enabled, blocking these inbound
packets.





Posted by Colin on December 7, 2005, 8:18 pm
Please log in for more thread options



> Has anyone heard of this actually happening? Googling it brings up a
> fair amount of armwaving about this topic circa 2002, but nothing
> recently.
>
> I have a client with this service at their remote office; their
> previous IPSec setup was flakey and we replaced their firewalls on
> both ends with new equipment, but when I installed this I've noticed
> that the tunnel cannot be brought up with requests from their home
> office -- it appears that the ISAKMP packets originating in the home
> office simply go nowhere.
>
> But if the tunnel is brought up with keying initiated at the remote
> office, it works just fine. We verified this behavior by building a
> second tunnel to the remote office from our office.
>
> I can only think of two explanations for this phenomena: Comcast is
> deliberately blocking inbound ISAKMP packets to mangle IPSec tunnels,
> or the cable modem itself has some filtering enabled, blocking these
> inbound packets.
>
>
>
>





Posted by Quaoar on December 9, 2005, 6:28 pm
Please log in for more thread options



> Has anyone heard of this actually happening? Googling it brings up a
> fair amount of armwaving about this topic circa 2002, but nothing
> recently.
>
> I have a client with this service at their remote office; their
> previous IPSec setup was flakey and we replaced their firewalls on
> both ends with new equipment, but when I installed this I've noticed
> that the tunnel cannot be brought up with requests from their home
> office -- it appears that the ISAKMP packets originating in the home
> office simply go nowhere.
>
> But if the tunnel is brought up with keying initiated at the remote
> office, it works just fine. We verified this behavior by building a
> second tunnel to the remote office from our office.
>
> I can only think of two explanations for this phenomena: Comcast is
> deliberately blocking inbound ISAKMP packets to mangle IPSec tunnels,
> or the cable modem itself has some filtering enabled, blocking these
> inbound packets.
>
>
>

Take this to the Comcast hsi forum at www.dslreports.com .

Q




Similar ThreadsPosted
Comcast "business" cable internet; blocking IPSec ISAKMP? December 6, 2005, 8:43 pm
"Cable, Internet, Wireless Hurt The Value of Old Networks, Threaten a Business Model" September 1, 2004, 5:36 am
CISCO UBR900 and IPSEC (Cable One) March 1, 2005, 8:47 pm
IPsec passthru on Motorola SBG 900 July 19, 2005, 9:39 pm
smc8013wg - comcast business February 23, 2005, 10:06 am
comcast business service, teaming February 20, 2006, 8:18 pm
Comcast (seattle area) and port blocking September 18, 2004, 10:28 pm
Cox Business (or any cable provider for that matter): Possible to Interchance Upstream and Downstream? February 21, 2006, 1:47 pm
Cox Business Service and my Linksys BEFCMU10 ver.3 February 27, 2006, 10:43 pm
Cox Business Service and my Linksys BEFCMU10 ver.3 February 27, 2006, 11:30 pm
Cox Business Service and my Linksys BEFCMU10 ver.3 February 27, 2006, 11:40 pm
Comcast Internet Cable in San Francisco September 23, 2004, 4:10 am
basic cable free with comcast internet? July 27, 2004, 9:50 am
Optimum Online blocking my Linksys router??? October 5, 2004, 4:58 pm
Can't get internet using Comcast cable modem and Lynksys WRT54G router January 30, 2006, 12:32 am