I have a remote office with 2 people that make VPN connection back to corporate office through a DSL line. The problem is that only one person can make VPN connection at a time. As soon as the next person try to connect, the first person got disconnected. I have IPSEC over UDP configured on the concentrator at corporate. Please help.
Simultaneous VPN connection
Sep 16, 2005
6 Replies
I don't if what I tell you is correct but do those employees uses vpnclient and they present themsel to the concetrator with the same public IP address? If this the case you shoul consider to build a LAN to LAN tunnel.
Let me know.
Alex.
Yes..they come out of the router there as 1 single IP. I know the problem is that when they come out, the router assign a UDP port 500 for all connection. So there is a conflict if the second connection comes up. The Netgear box that we have there doesn't have a feature that assign different port for differnet computer. I am not sure others commercial router/dsl router out there have this feature.
I'm quite sure that there is not PAT (Port Address Translation) for UDP protocol or IPsec requires that both transmitting and receiving port must be UDP 500 on the same port, but the server should discard incoming ones as "malformed" or something like that. Having more than one PC that must connect safely with devices behind the "VPNserver" should tell you that you need LAN to LAN configuration.
Alex.
In article , navcole wrote: :I have a remote office with 2 people that make VPN connection back to :corporate office through a DSL line. The problem is that only one :person can make VPN connection at a time. As soon as the next person :try to connect, the first person got disconnected. I have IPSEC over :UDP configured on the concentrator at corporate. Please help.
You do not indicate what your VPN termination device is, nor what your VPN client is.
If you are using Cisco's VPN software client, and you are using recent (within last year or so) software versions of a PIX, VPN3000, or IOS router, as the termination point, then all you should need to do is enable isakmp nat-traversal on the termination point.
If your Netgear box at the remote office proves not to be able to cope with two different internal hosts using the same internal source port, then it needs to be replaced anyhow, even without VPNs.
The answer below is correct, you need 2 real IP's. Or a Lan to Lan tunnel. You can only have one IPSEC tunnel per IP.
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required