Vpn issue mac issue

We have a strange issue for one of our customers that recently migrated to our internet service.
They are trying to vpn to an external ip address not controlled by ourselves. The issue is only on one subnet and isolated to Mac’s, PCs in the same subnet also work fine. They were able to vpn from the MACs before they migrated to our INET solution. They previously used a checkpoint FW for their outside NAT and firewall and now are using a failover pair of asa 5510s. I have packet traced out the firewall and there should be nothing blocked. UDP ports 500 and 4500 are open to the destination ips from the correct subnets. All other subnets with Windows PCs can vpn out to external ip without issue. The users in that subnet with the MACs can also browse internet fine so the routing and nat overloading is also ok
When they try to initiate a connection from the macs i can see the connection/xlate coming in from a source port of  udp 4500/500 and also a destination of udp 4500/500 instead of a random source port. Just this evening we managed to get one device connected but no others. Would the fact that the source port is claiming 500 and 4500 stop the other macs using the same source ports at the same time to connect out?
They are using the onboard mac vpn client, he can’t get the Cisco one working at the minute.
connections:
UDP OUTSIDE:external ip/4500 INSIDE:192.168.32.157/4500, mac connections
UDP OUTSIDE:external ip/4500 INSIDE:192.168.32.12/4500,
UDP OUTSIDE:external ip/4500 INSIDE:192.168.4.23/2672, pc connections
UDP OUTSIDE:external ip/4500 INSIDE:192.168.4.23/2672
UDP PAT from INSIDE:192.168.32.12/4500 to OUTSIDE:Outside Address/4500 flags ri idle 0:01:15 timeout 0:00:30
UDP PAT from INSIDE:192.168.32.12/500 to OUTSIDE:Outside Address/500 flags ri idle 0:01:15 timeout 0:00:30
Any help would be appreciated, bit of a strange one

Brian,
Most Cisco devices will want to do negotiation source and destined port of UDP/500 or UDP/4500.
It should not matter whethere there are multiple connections unless there  something "smart" on the path.
On ASA we have this functionality:
http://www.cisco.com/en/US/docs/security/asa/asa84/command/reference/i2.html#wp1761012
You might want to check if it's enabled or disabled.
I'm not sure why only Mac clients would be affected, that's odd. Typically Cisco clients and Mas' built in client are behaving almost in the same way during negotiation.
I think it might make sense to have our TAC investiagte the firewall if you're out of ideas ;-)
M.

Similar Messages

  • Which is better for solving Mac issues

    I have been experiencing Kernel Panics and program crashes. I want something that is good for testing hardware and OS issues. Can either of these find corrupted data files? I am looking at two utilities for purchase. Which is better for solving Mac Issues?
    TechTool Pro
    or
    Disk Warrior?

    When you say "complete bootable backup" do you mean that it contains the OS + all my applications? Basically a clone of the start-up?
    Yes, you have that very clear. I use Tri-backup or CCC for this normally, but there are other options.
    If I have this clone, and I start getting issues on my Mac, I can Zero the HD and reinstall the OS via the clone (including all the applications)?
    Yes, and if pressed for time you can just keep working off the Clone.
    I can Zero the HD and reinstall the OS via the clone (including all the applications)?
    Yep, right back to 100%, excluding HW issues.
    With all my software... it takes a day to reinstall all of it to a complete image.
    Yes, the only sensible thing is a Clone... or two. Most problems can be overcome by simply Verifying/Repairing the HD once in awhile, Repairing Permissions before and after every update/upgrade, and turning off Auto Updates in SW Update CP... wait a couple of weeks and check these forums for the number of problems with any update.
    PS. DiskWarrior has saved me hundreds of times from having to do complete new Installs or cloning back of Installs, I figure that's saved me 10's of thousands of hours & grief... I appreciate Alsoft so much that I don't even go for the generous upgrade offers on new versions... I just buy the new version completely at Retail.
    PPS. Funny thing, you'll read something like DiskWarrior is a one Pony Dog Show or something... just does one thing... I just have to laugh outloud... Yeah, the one thing is... cure my incurable Mac Problems 99.9% of the time!

  • I am running 10.8 and I am trying to get a E-mu 1x1 midi/usb connector to work with my keyboards. It's not working with any keyboard at all. I believe it is a Mainstage/Mac issue. Mainstage can recognize the the interface but it won't work.

    I am running 10.8 and I am trying to get a E-mu 1x1 midi/usb connector to work with my keyboards. It's not working with any keyboard at all. I believe it is a Mainstage/Mac issue. Mainstage can recognize the the interface but it won't work.

    Here are two screen shots to show you what I am seeing.  The first screen shot shows it allowing me to select (highlighted in blue) my admin user (which is what I am locced in as).  The second screen shot shows it allowing me to select the "Guest" user (highlighted in blue).  However when I click on the user "Orion" nothing happens.  It will not change to highlight that user.

  • Error opening  document. file is damaged  Would this be an Adobe issue or a MAC issue?

    I cannot open PDFs attached to my Mac Mail messages. The following pops up:"There was an error opening this document. The file is damaged and could not be repaired." Would this be an Adobe issue or a MAC issue?

    It very possibly can be an email issue. Some email providers encode files to make transfer faster. When pdf files are decoded, it could break them.
    The first thing to try if you haven't already is to save the attachment (without trying to open it) to your desktop and THEN try to open it. Another would be to have whomever is sending the files to you, Zip them first.

  • TS4051 This MacBook Pro (circa 2011) is the second Apple laptop with the same issue.  When I change sites (or at least many of them), the Mac issues a single chime.  I do not have any clue what this might be ... or if it even needs repairing if I can stan

    This MacBook Pro (circa 2011) is the second Apple laptop I have owned with the exact same issue.  When I change sites (or at least many of them), the Mac issues a single chime.  I do not have any clue what this might be ... or if it even needs repairing if I can stand the chime.
    If anyone has any ideas, I surely would love to hear!  Many thanks!
    Madelaine

    This is the Mac Pro (desktop workstation) forum.  You will probably get more meaningful results here:
    MacBook Pro: Notebooks: Apple Support Communities
    good luck

  • Spry Menu Bar Mac Issue

    Hello,
    Link:
    http://www.therockchurch.tv/about_trc.html#welcome
    Issue: Mac Safari doesn't like the spry menu bar. The sub
    menus disappear and flicker. Everything works fine on all browsers
    using widows including safari for windows. The menu just doesn't
    like mac. Any help?
    -R

    "kinblas" <[email protected]> wrote in
    message
    news:f7rdd2$7ri$[email protected]..
    > Hmm, I'm not seing any flashing on that page on my Mac
    with Safari. It
    > looks
    > pretty good.
    >
    > I am seeing it on your homepage:
    >
    >
    http://www.throckchurch.tv
    >
    > but it looks like it is due to the fact that Safari is
    struggling to keep
    > up
    > with rendering all that Flash animation on your page.
    >
    > On windows with FireFox, the homepage is starving the
    browser and pegging
    > my
    > CPU at 100%.
    In IE7 Vista, my CPU is pegged at 22%. I do not run flash in
    Firefox because
    of its rendering engine issues, so that might be an issue
    there. Safari has
    known issues rendering CSS hovers on top of flash. The
    workaround is to
    remove hovers or live with it.
    Al Sparber - PVII
    http://www.projectseven.com
    Extending Dreamweaver - Nav Systems | Galleries | Widgets
    Authors: "42nd Street: Mastering the Art of CSS Design"

  • Cisco VPN on Mac existing with Apani

    Hello:
    I recently installed Apani VPN ( a Mac client for Nortel Contivity connections that connects through a browser) on the same machine with my Cisco VPN. Now for my customers with Cisco VPN connections I fail to connect with this error:
    51     11:12:50.183  09/16/2011  Sev=Critical/1          CVPND/0xC3400003
    Function SocketApiBind() failed with an error code of 0xFFFFFFFF(ike-init-state.cpp:402)
    52     11:12:50.183  09/16/2011  Sev=Critical/1          CVPND/0x43400012
    Unable to bind to IKE port.  This could be because there is another VPN client installed or running.  Please disable or uninstall all VPN Clients other than the Cisco VPN Client.
    Only problem is I cannot find this process in my Activity Monitor--I'm not sure what the process is. The is no application that I can see in my "Applications Folder".  I haven't been able to get help from Apani. I have tried uninstalling and reinstalling Cisco but no joy.
    Any idea how I can get cisco taking over again? If I have to choose between the two it is more important to get CIsco working. I am running a Macbook with OS 10.6.8.
    Thanks.

    Apple's support section (http://docs.info.apple.com/article.html?artnum=306256) says "How to enable Cisco VPN connections
    You should use Cisco's VPN client software to establish a Cisco VPN connection via an AirPort Extreme base station. Note: In the Cisco VPN client preferences, make sure the "NAT-T" option is enabled.
    Note: Some corporate firewall configurations may cause issues with the Cisco VPN software.
    Please contact AppleCare support if you are unable to contact a Cisco VPN server via Cisco VPN client software and an AirPort Extreme base station.
    I'm experiencing the same thing. DellLatitude D610. Netgear rangemax wireless PC card (WPN511). I can connect to the internet but I try to vpn into work I get half way through the connection process and get an error which states" Secure VPN Connection terminated locally by the Client. Reason 412: The remote peer is no longer responding. I've spent 2 hours trying different settings. I really want to stick w/the apple product but will have to return it if I can't get it to work. I need cisco vpn via wintel for work.

  • How to set up VPN using MAC OSX 10.4.11, Please help I need someone to help me set up VPN using regular DSL connection on my home so someone can help me troubleshoot my XSAN system remotely. THANKS

    Hello,
    I'm having trouble setting up a VPN using MAC OSX 10.4.11 Server. I have and XSAN system and one of my volumes has been down for quite a while now. There is a very kind MAC IT professional that is willing to help be troubleshoot my system but he needs to be able to access my system remotely. I am able to connect the MDC to DSL but I haven't been able to set up the VPN. Please help, this is an emergency. Thanks!
    Marco

    have you forwared the ports on your router? Why not let him in via teamviewer? its free and mac compatable

  • Can i use VPN on Mac Pro and if so what version do i need?

    VPN for Mac Book Pro what version is need?

    Depends on the VPN you want to connect to, ie its protocol (IpSec, SSH, L2F, etc...). SSH isn't VPN per se, just a secure method of encapsulating data before transmission, but basically, some VPN clients are compatible with some VPN protocols, not all of them.

  • Canon IR c1028 - USB and Mac issues

    I have a Canon IR c1028:
    http://www.usa.canon.com/cusa/support/office/color_imagerunner_copiers/color_imagerunner_c1030_c1031...
    I have it USB attached and Network attached. The network attached prinitng works fine but one of my home compouters is habitually attached to my coprporate VPN and so I use USB attachment. I have recently started having issues with printing from the MacBook which runs YOSEMITE as follows:
    1. Instal the printer using the driver from the above link (printer appears to be connected and online)
    2. Send print job to printer....printer makes a sound in recognition but if you watch the print queue from the Mac you see a cycle of:
    Priniting
    The printer is not connected
    The printer is offline
    This repeats every time and it does not resolve if you delete the printer and even if you reset the printer subsystem before re-installing
    Thanks for ideas ? 

    Hi, bluemoon.  Thanks for posting!
    While our forum community members are welcome to chime in, Canon does not provide direct support for imageRUNNER series products. Instead, your dealer will be able to help you! If you don't have a dealer, please call us at 1-800-OK-CANON (1-800-652-2666) and we will be happy to provide you with the names of dealers in your area!
    We hope this helps!

  • VPN device profiling issue ISE In Line with ASA

    Hi all,
    We have an inline posture ISE which is acting as a radius server for authenticating VPN client through our ASA.
    However because VPN client do not send thier MAC like they do when wireless and wired clients, the ISE cannot profile based on MAC as it dOes by default.
    Has anyone come accross this issue and have another way of profiling VPN devices?
    Thanks
    Mario

    Please review the below links which might be helpful :
    http://www.cisco.com/en/US/products/ps11640/products_configuration_example09186a0080bea904.shtml
    http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_ipep_deploy.html

  • VPN over Internet Issues

    I have a Mac OS X Server with VPN (L2TP and PTP) enabled. I am able to connect to the VPN service from my iMac (I also tried another computer) from within my LAN, but VPN over LAN isn't very useful, of course.
    The problem is, I cannot connect to the VPN by typing in my public IP (with the rest of the settings the same) instead of the private IP. I've enabled port forwarding for UDP 1701, 4500, and 500, and TCP 1723. I also tried making my Mac OS X Server machine (a Mac Mini) a DMZ host, and that didn't work. I turned my router's firewall off, too.
    So if I can connect to my VPN locally but not over the Internet even though I've enabled a DMZ host, which shouldn't fail, some setting must be wrong somewhere. Does anyone know what it could be?
    By the way, the Mini is on WiFi for now (we recently got it and haven't set up a place for it yet).

    Jeff: Sorry to sound inexperienced, but I can't find a VPN or network related log in Console. Which one is it? Anyway, I doubt that it's the connection settings but something with my router. I know all routers are different, but I was wondering if there was some generic problem with VPN and routers. Strangely enough, my other services work on the server (HTTP, AFP, SSH, VNC) by port forwarding. Again, DMZ hosting did NOT solve the problem, so I'm guessing that there's more to do if you want VPN???
    Basically (to anyone), my VPN works fine over the network, so my settings must be correct, and I am almost sure that when I connect over the internet, the request does not even touch my server.
    As for the other reply: I've forwarded the same ports and made my server's IP static like in the thread. The only difference is that DD-WRT firmware. Was that the final solution?
    P.S. My server is temporarily down (due to some nasty irrepairable permissions issues) as I reinstall Mac OS X, so I can't really test anything on the server until it's up.
    Message was edited by: Mac OS 9000

  • New to Mac - Issues with imported Excel Docs

    Imported my Excel docs from my PC and they made the trip but when I open them, some don't work properly. I have some billing statements that I made with Excel templates. Whenever I open and try to save them, I get an error message:
    Users/JaneDoe/Documents/Private Practice/Billing Statements/Jones 2 16 05 MAC.numbers
    I'm having some issues with Word documents that have tables in them also.
    I love my new MAC but have many business forms that I need to use. Any help would be appreciated.

    Thanks for your answer, I suspected as much. I've been thinking about this and have decided that since those are historical files and not working files, I'll just leave them alone and create new billing statements using Mac. It's certainly easy enough to do.
    The Word documents, though, are a different story. I've scanned pages out of some manuals and many of the pages are questionnaires with tables to indicate answers. Some documents are multiple pages and every other page I view is blank. It's difficult and sometimes impossible to delete the blank page or move the table up. If I can't salvage these, I'll have to go back into the manuals and scan the pages all over again.
    And I don't want to partition my hard drive, run Windows parallel or invest in Office for Mac because that all defeats the purpose of my transition to a Mac in the first place - ease of use.
    Thanks again.

  • SSL VPN Login failure issue

    Hello,
    I am having an issue with some users trying to login to our SSL VPN (Anyconnect) via ASA5505 8.2(1).  Authentication is done via AD.  From the same computer, the client finds the DNS name and unlocks the login username and password.  When I enter a username and password and click connect, it is instantly rejected with login failure with the following event log:
    Function: ConnectMgr::setPromptAttributes
    File: .\ConnectMgr.cpp
    Line: 2657
    Invoked Function: setPromptAttributes
    Return Code: -33554423 (0xFE000009)
    Description: GLOBAL_ERROR_UNEXPECTED
    Error text:
    Login failed.
    If I change the user account to another user (from the same PC), login works perfectly fine - this is only happening with 3 or 4 users - I have compared the user accounts of a failing account and a successful account and they are identical in AD. 
    This has been driving me crazy - as a work around for the failing users, I just created a temporary account which works perfectly fine.  The request doesn't even seem to hit the ASA (there is nothing in the logs that show a failed attempt).  Still troubleshooting and looking at certificate's at this point.  Any help/suggestions would be greatly appreciated!!  Thanks.
    Regards.
    After a little more testing, seems somehow related to users being in to many groups in AD.      
    Message was edited by: Rich Viola

    Hello,
    If the website is unavailable or in this case, the website is missing several characters(charts, canvas, etc or some other objects), usually could be an issue with the rewrite engine.
    Solution (workaround):
    You may use smart tunnel for this website, so the rewrite engine will not override any content, and it will display the website as it should.
    You can implement it as follow:
    Add a Bookmark
    Bookmark for the service and clicking the Enable Smart Tunnel option in the Add or Edit Bookmark dialog box.
    For further information you can find it here:
    http://www.cisco.com/c/en/us/td/docs/security/asa/asa83/configuration/guide/config/webvpn.html#wp1272236
    Let me know how tit works out!
    Please don't forget to rate and mark as correct the helpful Post!
    David Castro,
    Regards,

  • Cisco ASA 5505 site to site IPSec VPN with RV220W issue

    I have a ASA5505 connected to RV220W through IPSec VPN. When  using SMB to transfer large file, the ASA5505 will show error message:
    CTM ERROR: Invalid input parameters, ctm_get_scb_prot_stats:1561
    The error message from the debug crypto engine. When  the message show, the speed of the transfer will slow down quickly, and  even no data can be go through between ASA and the RV220W. But the IPSec  SA and the IKE SA is active, and can ping the inside network in both  site.
    Both ASA5505 and the RV220W has been updated the latest firmware. I have surf the Google but no such related issue found.
    Any suggestions on where to look would be much appreciated.
    Thanks in advance
    Terry

    Hi Ted thanks for your reply and information.
    The strange things happened in RV220W shows the IPSec sa is expired, but the ASA5505 IPSec and IKEv1 sa is active. Inside both site internal network can ping to other side, but cant transfer file through Windows SMB. It seems when I transfer over 4GBytes of file, it will start happening and required clear IPSec and IKEv1 sa so that the VPN tunnel will start up again.
    I am already surrander for this issue......

Maybe you are looking for

  • Qustion in abap objects

    hallow i wont to now what is the difference betwen  public & private please give me example of benefit of both.and when its  recommended to use any of them Regards

  • Problem with MSSQL 2005 maintenence plan

    Hi, I am facing a problem with MSSQL 2005 maintenance plan. I created a plan which takes full backup of all the db's and in the same plan I added a clean up task which is suppose to clean all the files older that 1 day. To gain compression I converte

  • HT1212 how do I get past the apple icon...my iphone prompts need passcode phone is locked.

    Please offer suggestions...this is a new phone . I have been on the phone with an AT&T rep for 3 hours...

  • TS1424 what to do if songs stop short

    Two of the songs I just purchased stopped after 40-50 seconds.  I "reported the problem" over a week ago but have not heard any response from ITunes.  If I download it again from my purchased history, will I get that bad cut again?  I've never had th

  • Approver changes in PPOM transaction

    Hi All, Please provide inputs on this. We are facing problem in which PPOM approver details are modified in produciton. Please let me know, how can I trace history of these approver changes. Is there any log maintained?