BEFSX41 VPN

May 09, 2005 5 Replies

I'm considering setting up a VPN from my work to my home computer. I'm wondering about Linksys BEFSX41 as the router/vpn endpoint.



Anyone know if the following setup will work?



Home conntection will listen for connection from work 100% of the time. Home network connects to Cox cable system Router has dynamic address managed through dyndns.org (this currently works fine) Setting up 3DES, SHA-1 with perfect forward secrecy



Work connection is behind a Cisco firewall. I don't have any more details (e.g. I don't know if it is set to allow IPSEC passthrough)



BEFSX41 will assume MAC address of my desktop computer for connecting to work LAN. My desktop computer will be NAT'd behind the Linksys. Identical configuration to the home BEFSX41 with the exception that they use different interior LAN subnets (one is 192.168.5.0, other is 192.168.15.0 and they both have masks of 255.255.255.0)



Prior to connecting to the actual networks I will connect both routers to the same switch at home to ensure they connect to each other in the simplest network possible-- yes, I know I will have to configure static IP addresses for the pseudo-WAN interfaces).



Does this arrangement sound like it has a prayer of working? Any suggestions?


In article , Curt Will wrote: :I'm considering setting up a VPN from my work to my home computer. I'm :wondering about Linksys BEFSX41 as the router/vpn endpoint.

I've been hearing some murmers that the BEFSX41 has firmware issues that aren't getting resolved -- that and that their power filtering is somewhat fragile.

My own experience is that a BEFSX41 link will freeze a TCP connection once to twice a day... leaving all the other connections to the same location intact. It appears to be associated with the IPSec session dropping... but why would all the other active TCP sessions continue fine and just one hang? And it's always the active session too, the one you're busy transfering data with or typing into...

IMHO, spend the extra money and get the BEFVP41 -- faster, 70 tunnels instead of 2, and hasn't dropped a single connection on me yet.

:BEFSX41 will assume MAC address of my desktop computer for connecting to :work LAN.

Why bother with that detail unless you are planning to do an end-run around established security policy?

:Does this arrangement sound like it has a prayer of working?

Yeah, it should work, if you can get the IPSec through the work firewall and if Cox doesn't block the incoming packets.

Neither the FSX nor FVP support NAT-T, so your workplace would have to be doing one-to-one (or else static) NAT for your work system -- if your workplace is doing many-to-one (PAT, port address translation) then without NAT-T you can't make it work as your work's firewall wouldn't know which interior system to forward the ESP (IP Protocol 50) packets to. ESP has no ports to be port-translated...

Here is where you need to STOP - it appears that your IT department already has a security method implemented and that you are not in charge of the company network.

IPSec pass through does not normally work INBOUND on any real firewall, meaning it's disabled. Also, outbound VPN connections would also be disabled except to business partners or CIO's and such.

Not really, you need to have them setup with two public IP addresses (one for each, on the WAN side) and then setup the units to call each others IP. In many cases, the Linksys on the dynamic address will time- out, even with the keep-alive setting enabled, and the tunnel will die unless the HOME PC keeps traffic flowing to the company network after the key lifetime.

What you really need to be doing is asking your company IT people to help you setup a workable connection.

My guess is that you don't really want to involve them as most IT people know better than to connect a home users computer to the company network, unless the company provided the computer and locked it down/secured it.

In article , Walter Roberson wrote: :I've been hearing some murmers that the BEFSX41 has firmware issues :that aren't getting resolved

:My own experience is that a BEFSX41 link will freeze a TCP connection :once to twice a day...

:IMHO, spend the extra money and get the BEFVP41 -- faster, 70 tunnels :instead of 2, and hasn't dropped a single connection on me yet.

It figures. Within a day of writing that, my BEFVP41 froze two connections within a few minutes of each other [leaving the other connections alone.]

I see from my PIX [VPN endpoint] logs that the SA (Security Association) just suddenly gets deleted with no reason given; the BEFVP41 end point might not be completely aware of it as it sends a couple of packets that the PIX rejects has having the old [no longer valid] SPI. That happens in the same one second interval as the teardown, so I could be projecting too much into those stray packets.

With the evidence I have now, it is not certain as to whether the BEF{SX,VP}41 are at fault or the PIX. I never saw such a problem when I was using a PIX 501 from the same location, but there's always bit-rot to consider.

Don't they usually put the VPN'ed home networks in the DMZ zone or a special segment that still has to pass through their [other] firewall, AV scanning, etc., like they should be doing with the laptops?

You would hope so, but you never know.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required