Wilders Security Forums  

Go Back   Wilders Security Forums > Official LooknStop Firewall Forum > LnS English Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 5th, 2005, 01:42 PM
admash's Avatar
admash admash is offline
Infrequent Poster
 
Join Date: Feb 2005
Posts: 7
Default How to set for VPN?

I am using looknstop version 2.05.

I use findnot.com's vpn service, and when i try to connect, looknstop doesnt give me the option to allow or block the connection, it just doesn't allow the connection. Also, even though I have disabled the audio alarm, It continually sounds as i am trying to connect. the only way I could get it to go through is by turning off the internet filtering rule "all other packets" at the bottom of the list.

What is the best and most secure way to configure looknstop?

thanks
A.
  #2  
Old February 5th, 2005, 06:25 PM
qvpn
 
Posts: n/a
Question Re: How to set for VPN?

I am also trying to find out how to connect to findnot using VPN through Zone Alarm free V5. It just never gets through ? Anybody know why this is as i dont have any problems with ZA otherwise.
  #3  
Old February 6th, 2005, 12:31 AM
CrazyM's Avatar
CrazyM CrazyM is offline
Firewall Moderator
 
Join Date: Feb 2002
Location: BC, Canada
Posts: 2,433
Default Re: How to set for VPN?

Hi admash

... and welcome to Wilders

Quote:
Originally Posted by admash
the only way I could get it to go through is by turning off the internet filtering rule "all other packets" at the bottom of the list.
Do your logs indicate what is being blocked by the "all other packets" rule that you may need to permit?

Regards,

CrazyM
__________________
"The best thing we can do in cyberspace is exactly what we do in the real world: do our best to manage the risks."
- Bruce Schneier
  #4  
Old February 6th, 2005, 06:41 AM
Frederic Frederic is offline
LnS Moderator
 
Join Date: Jan 2003
Location: France
Posts: 4,354
Default Re: How to set for VPN?

Hi admash,

Yes, having the blocked packets from the log would help to know what needs to be allowed.

Very often VPN are using IP Protocol 47. A specific rule for that is available here:
http://www.looknstop.com/En/rules/rules.htm#VPN

Another set of rules for specific VPN are also available here:
http://looknstop.soft4ever.com/Rules/NortelVPN.rie

Regards,

Frederic
  #5  
Old February 7th, 2005, 04:57 AM
admash's Avatar
admash admash is offline
Infrequent Poster
 
Join Date: Feb 2005
Posts: 7
Default Re: How to set for VPN?

Thanks to all for your help.

Here is a sample from the log:

02-07-05,03:39:53 U-2 'All other packets ' 193.151.75.22 IP Protocol:47
02-07-05,03:39:53 D-3 'All other packets ' 193.151.75.22 IP Protocol:47
02-07-05,03:39:55 U-4 'All other packets ' 193.151.75.22 IP Protocol:47
02-07-05,03:39:56 D-5 'All other packets ' 193.151.75.22 IP Protocol:47

I have downloaded the Protocol 47 rule, and I am now able to connect, however, I am now getting another message in the log:

02-07-05,03:49:09 U-18 'All other packets ' 224.0.0.22 IGMP Data:148 4 0 0
02-07-05,03:49:09 U-19 'All other packets ' 224.0.0.22 IGMP Data:148 4 0 0
02-07-05,03:49:09 U-20 'All other packets ' 224.0.0.22 IGMP Data:148 4 0 0
02-07-05,03:49:09 U-21 'All other packets ' 224.0.0.22 IGMP Data:148 4 0 0
02-07-05,03:49:09 U-22 'UDP : Any other UDP pack' 239.255.255.250 UDP Ports Dest:1900

What do I need to do next?
  #6  
Old February 8th, 2005, 04:30 AM
Xyzzy's Avatar
Xyzzy Xyzzy is offline
Regular Poster
 
Join Date: Jan 2005
Location: Poland
Posts: 67
Default Re: How to set for VPN?

Try reading post "Configuring LnS for routers" (a sticky one, at the beginning of the posts list).

X.
  #7  
Old February 8th, 2005, 08:59 AM
Thomas M's Avatar
Thomas M Thomas M is offline
Frequent Poster
 
Join Date: Jan 2003
Posts: 353
Default Re: How to set for VPN?

Quote:
Originally Posted by admash
What do I need to do next?

admash,
Right now I am also fighting with some proper rules for my new Cisco-VPN client. And I do see these UDP port 1900 blocks also.

Hopefully tomorrow I try posting my rules here....

Be patient
Thomas
  #8  
Old February 8th, 2005, 01:43 PM
Frederic Frederic is offline
LnS Moderator
 
Join Date: Jan 2003
Location: France
Posts: 4,354
Default Re: How to set for VPN?

Quote:
Originally Posted by admash
I have downloaded the Protocol 47 rule, and I am now able to connect, however, I am now getting another message in the log:

02-07-05,03:49:09 U-18 'All other packets ' 224.0.0.22 IGMP Data:148 4 0 0
02-07-05,03:49:09 U-19 'All other packets ' 224.0.0.22 IGMP Data:148 4 0 0
02-07-05,03:49:09 U-20 'All other packets ' 224.0.0.22 IGMP Data:148 4 0 0
02-07-05,03:49:09 U-21 'All other packets ' 224.0.0.22 IGMP Data:148 4 0 0
02-07-05,03:49:09 U-22 'UDP : Any other UDP pack' 239.255.255.250 UDP Ports Dest:1900

What do I need to do next?
Usually blocking these packets has no consequence.
If you have a lot of these packets in the log, you can try to create a rule that will silently drop them. Otherwise you can simply let this happening.

Frederic
  #9  
Old February 10th, 2005, 03:14 AM
Thomas M's Avatar
Thomas M Thomas M is offline
Frequent Poster
 
Join Date: Jan 2003
Posts: 353
Default Re: How to set for VPN?

Quote:
Originally Posted by Thomas M
admash,
Be patient
Thomas

admash,
Since there is so much "official" work to do at the moment, I don't get a minute to play with the VPN client config in LnS. Sorry!

Maybe you solved the problem already by yourself ??

Thomas
  #10  
Old February 10th, 2005, 04:36 AM
admash's Avatar
admash admash is offline
Infrequent Poster
 
Join Date: Feb 2005
Posts: 7
Default Re: How to set for VPN?

I am still 'playing' with it myself. I am a bit of a novice, but am eager to learn. All of your help is appreciated.

__________________
Cheeze stinks, but it sells!
  #11  
Old March 5th, 2005, 09:41 AM
footbag
 
Posts: n/a
Default Re: How to set for VPN?

To set Zone Alarm to allow you access to findnot, go to the Log Viewer in the Alerts and Logs section. Switch it to Firewall mode using the dropdown. You should see attempts to reach an IP address starting 193.xxx.xxx.xxx. Right button click, then select Add to add it to your trusted zone.

You will probably need to add more than one address, I added two and all was then well. If you move between findnot servers, you will need to add all the IP addresses you use.
 

Wilders Security Forums > Official LooknStop Firewall Forum > LnS English Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:27 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums