PDA

View Full Version : VPN Issue


zeddjb
August 19th, 2008, 10:38 PM
I'm new to both ESET and VPN's. I really like ESET and I don't want to uninstall it.

My problem is this:

I use the built-in Microsoft VPN server. When ESET firewall is enabled, traffic can not come through the VPN server; however, as soon as I disable the firewall, traffic can resume. I'm not exactly sure how to set up the rules to use VPN. I did set up one rule to allow ports 500 & 1723 through but that didn't seem to help.

Any help with this would be great.

shansmi
August 20th, 2008, 12:02 AM
try putting the firewall in interactive mode and let it learn the application - remember to allow and save your choices.

zeddjb
August 20th, 2008, 06:22 PM
Thanks for the prompt reply.

The firewall is in interactive already. By default, it is in automatic mode and for that reason I checked some of the rules that were automatically created. I disabled all of them and then tried the VPN connection again and still nothing.

Anything else maybe you can think of?

Fajo
August 20th, 2008, 08:22 PM
-{ Quote: "Thanks for the prompt reply.

The firewall is in interactive already. By default, it is in automatic mode and for that reason I checked some of the rules that were automatically created. I disabled all of them and then tried the VPN connection again and still nothing.

Anything else maybe you can think of?" }-


If its a Static incoming IP addy you can make a rule for it to Allow/Allow All. but this only works if the IP addy don't change every time you use the computer.

zeddjb
August 21st, 2008, 08:44 AM
It is a static IP since I run a few different services such as FTP, VNC and VPN now.

Above I did explain that I made a rule to allow ports 500 & 1723 ( vpn ports ) to allow them both ways. I don't want to open all ports to that IP because I don't want it to become a honeypot.

I also disabled all all the current rules just to make sure any rules weren't created to block it without me knowing; but that didn't help.

Fajo
August 21st, 2008, 03:20 PM
-{ Quote: "It is a static IP since I run a few different services such as FTP, VNC and VPN now.

Above I did explain that I made a rule to allow ports 500 & 1723 ( vpn ports ) to allow them both ways. I don't want to open all ports to that IP because I don't want it to become a honeypot.

I also disabled all all the current rules just to make sure any rules weren't created to block it without me knowing; but that didn't help." }-

Interesting.. I have VNC on my server as well as VPN. its letting me Thur just fine. I cant think of why yours is not. there has to be a rule set we are missing.

Just out of curiosity is the other computer behind a Network or router Firewall. that is off your system that could be conflicting I know you said it works with Eset Firewall disabled but im wondering when its enabled maybe something that eset needs is bein blocked by the other firewall. its a long shot but worth a look.

I also found this port online that Microsoft says is needed for outbound. on VPN Networks

add port 443 to 443 to the TCP outbound

zeddjb
August 21st, 2008, 03:38 PM
It is behind a router/firewall. I took it off that and connected directly through my gateway and it still does not want to connect.

As for the rules, I did disable all of them and also tried it thinking that there might have been one automatically created, but still nothing.

But like you said, you have both VNC and a VPN and you are getting it to work just fine. I'm not running a domain, just a simple 5 computer workgroup. The Windows Firewall is disabled; I use dyndns.org for a DNS. The problem has to be in ESET somewhere, I don't think it would be a zone setting.

I really appreciate you helping me out with this. Even if we don't find an answer at leaste we tried :D

Fajo
August 21st, 2008, 03:50 PM
-{ Quote: "It is behind a router/firewall. I took it off that and connected directly through my gateway and it still does not want to connect.

As for the rules, I did disable all of them and also tried it thinking that there might have been one automatically created, but still nothing.

But like you said, you have both VNC and a VPN and you are getting it to work just fine. I'm not running a domain, just a simple 5 computer workgroup. The Windows Firewall is disabled; I use dyndns.org for a DNS. The problem has to be in ESET somewhere, I don't think it would be a zone setting.

I really appreciate you helping me out with this. Even if we don't find an answer at leaste we tried :D" }-


If you Google vpn and firewalls you will find out very quickly you are not alone. :-\

zeddjb
August 21st, 2008, 04:01 PM
Indeed, but I cannot find a decent bit of help from any of those sites. In fact, I looked through there before I came here to try and figure it out.

I'll just keep at it until I find a solution. If this thread stays open, I'll post a solution when I come to it. If you find one or anymore ideas, feel free to email me: zedd@charter.net.

Thanks

tosbsas
August 21st, 2008, 07:50 PM
Just wanted to add something

I use openvpn and can't connect either. Only way to do it is turning off eset firewall, connect and turn it on again - than it works here

Dynamic IP

Ruben

tosbsas
September 5th, 2008, 06:54 PM
Again

05.09.2008 17:38:14 Communication denied by rule 192.168.12.10:138 192.168.12.11:138 UDP Block outgoing NETBIOS requests System NT-AUTORITÄT\SYSTEM
05.09.2008 17:38:14 Communication denied by rule 192.168.12.10:137 192.168.11.4:137 UDP Block NETBIOS Name Service requests System NT-AUTORITÄT\SYSTEM
05.09.2008 17:38:14 Communication denied by rule 192.168.12.10:137 192.168.11.4:137 UDP Block NETBIOS Name Service requests System NT-AUTORITÄT\SYSTEM

this is what I get when interactive filtering is enabled, on automatic I get the same, but I can connect

automatic
05.09.2008 17:52:29 Communication denied by rule 192.168.12.10:137 192.168.11.4:137 UDP Block NETBIOS Name Service requests System NT-AUTORITÄT\SYSTEM
05.09.2008 17:52:27 Communication denied by rule 192.168.12.10:137 192.168.11.4:137 UDP Block NETBIOS Name Service requests System NT-AUTORITÄT\SYSTEM
05.09.2008 17:52:26 Communication denied by rule 192.168.12.10:137 192.168.11.4:137 UDP Block NETBIOS Name Service requests System NT-AUTORITÄT\SYSTEM
05.09.2008 17:52:20 Communication denied by rule 192.168.12.10:137 192.168.11.4:137 UDP Block NETBIOS Name Service requests System NT-AUTORITÄT\SYSTEM

Ruben

tosbsas
September 10th, 2008, 09:03 AM
why is there no answer from eset here? So far support has been spotless

Ruben

kC_
September 10th, 2008, 01:16 PM
cant connect to standard windows pptp vpn here with ess on client..

comes up with "Error 800" and then tried to redial..

as soon as i disable ess firewall, VPN is fine

this is on interactive mode.. there is no pop ups of any kind.. it just gets blocked

zeddjb
September 14th, 2008, 04:24 PM
I am still having the same problem and I have not found a solution. I have contacted ESET and they helped me twice with emails, but then just stopped. I'm not very impressed by the customer support and as a result I will probably not use ESET ever again.

I do not have the time to figure out this problem myself as I work full time and go to school full time. I hope someone can find an answer and post it here. I will periodically check back in hopes some has.

Thanks and sorry

Fajo
September 14th, 2008, 04:30 PM
-{ Quote: "I am still having the same problem and I have not found a solution. I have contacted ESET and they helped me twice with emails, but then just stopped. I'm not very impressed by the customer support and as a result I will probably not use ESET ever again.

I do not have the time to figure out this problem myself as I work full time and go to school full time. I hope someone can find an answer and post it here. I will periodically check back in hopes some has.

Thanks and sorry" }-

Sorry bro. I wish I had more Answers but I don't. sense the last we chatted I have changed AV's my self so am unable to help you feather bro sorry. :'(