Services over VPN
Services over VPN
Hello everybody, i'm facing some issues with IPSEC vpn with omada. I've a working point to point vpn between central office and local stores. This vpn is working fine :
- i can ping devices both ways
- go to webpages of local devices like printers
- vnc devices
- view local shares (smb)
- connect to sql server
BUT when i try to use some software that needs to connect to the central office or to open/download files over a network share (I can see the shared folder but I cannot download files from it) it doesn’t work.
What is very strange is that when i use forticlient VPN everything works fine.
On the other side (in the central office I’ve a fortinet) the firewall seems well configured and works without any problems on other vpn (made on other fw like palo alto)
What is wrong on the omada side ?
Thank you very much to everyone who could help.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
I myself have two ER707-M2 with site to site vpn, there have never been such problems, do you have any screenshots of the vpn configuration?
Do you have other VPN services on the router such as openvpn or SSL vpn? I have had similar problems as you describe on ER8411 but then SSL vpn has been configured, I had to delete all SSL vpn configuration before site to site worked properly. I haven't tested SSL on the ER707-M2, so I don't know if it's the same problem there
- Copy Link
- Report Inappropriate Content
@MR.S
Thank you very much, here the configuration. On the other side i don't have any SSL vpn configured on the omada side.
- Copy Link
- Report Inappropriate Content
you should not use this encryption, it is outdated and insecure, try this one instead.
Do you have SSL on any of the routers?
Is there ER707-M2 on both sides of the tunnel?
- Copy Link
- Report Inappropriate Content
You have Fortinet I see, sorry I didn't see that.
try with slightly stronger encryption, I have vpn against cisco, unifi, sonicwall and microtik, it works without problems, but I have not tested with the same encryption as you have
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Hi @slamjam
Thanks for posting in our business forum.
slamjam wrote
I've set up the vpn in your exact way but nothing changed... vnc works, ping works but I still can only see smb of windows server files without being able to download (explorer crashes after some minutes stuck in trying)
The above description shows that the VPN works and it is intact.
You might wanna take a look at the server firewall or permission. It does not look like a problem with the router/VPN at all.
- Copy Link
- Report Inappropriate Content
I am quite sure that the problem is not on the ER707-M2 if you have not configured other types of VPN on it, I asked you if you have configured SSL VPN on the ER707-M2, you have not answered this yet.
to test comunication.
can you telnet to the server that has the file share.
in windows you can type that command in the command prompt,
telnet 192.168.56.1 445
ip is an example, replace with ip to server where file share is
if you do not get a response, you must check that nothing is blocked in the Fortinet firewall
if you dont have windows telnet add windows function in add remove program.
- Copy Link
- Report Inappropriate Content
I have done some more tests on my ER707-M2 routers, SSL works fine with this router combined with site to site, only way I can provoke what you have is by blocking TCP port 445. then file explorer hangs and finally it doesn't respond.
- Copy Link
- Report Inappropriate Content
@MR.S
thank you veru much for the support that you're giving.
i've tried and the port 445 is open.
What is very strange is that on the fortinet side the configuration is exactly the same for all the vpns (other sites and ssl)
PS i've done another check, i've a nas with an smb share and it works! So it's some strange configuration regarding something regarding windows shares (but remember that this shares works with the ssl fortinet vpn)
- Copy Link
- Report Inappropriate Content
have you remembered to open the widows firewall for the network that is on the ER707-M2, the windows firewall blocks deafult remote networks
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 970
Replies: 14
Voters 0
No one has voted for it yet.