2010/4/29 M. Ihsan <
ich...@gmail.com>:
>
> Info : seperti sdh kami sampaikan sebelumnya memang configurasi
> firewall adalah local to net allow all, pada saat itu koneksi vpn bca
> bisa normal,
> namun karena security, maka firewall kami tutup dan hanya allow
> port2 yang kami diperlukan saja dibuka, spt, 80, 443, 25, 100 dst
> termasuk port 8002, dan ipsecnat tcp udp 500 4500
>
> Juga di jaringan kami ada beberapa vpn yg koneksi, namun tidak
> masalah dengan setting yang sekarang, kecuali vpn bca
>
VPN BCA emang rada antik, beda sama VPN lainnya.
Saya googling, Cisco VPN, sistem yang digunakan BCA.
Berikut beberapa hasil google, mungkin membantu :
http://articles.techrepublic.com.com/5100-10878_11-5913811.html
http://www.helpdesk.ilstu.edu/kb/index.phtml?kbid=1156
http://support.microsoft.com/kb/812076
Dan ini sumber resminya :
http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_qanda_item09186a0080094cf4.shtml
Bagian yang menarik adalah pertanyaan ini :
If I place my VPN 3000 Concentrator behind a firewall or router
running access control lists, which ports and protocols do I need to
allow through?
Dan jawabannya :
This chart lists ports and protocols.
Service Protocol Number Source Port Destination Port
PPTP Control Connection 6 (TCP) 1023 1723
PPTP Tunnel Encapsulation 47 (GRE) N/A N/A
ISAKMP/IPSec Key Management 17 (UDP) 500 500
IPSec Tunnel Encapsulation 50 (ESP) N/A N/A
IPSec NAT Transparency 17 (UDP) 10000 (default) 10000 (default)
Note: The Network Address Translation (NAT) Transparency port is
configurable to any value in the 4001 through 49151 range. In versions
3.5 or later, you can configure IPsec over TCP by going to
Configuration > System > Tunneling Protocols > IPSec > IPSec over TCP.
You can enter up to 10 comma-separated TCP ports (1 - 65535). If this
option is configured, make sure that these ports are allowed in your
firewall or router running access-control lists.
Sebagai tambahan informasi, barusan saya coba di laptop saya sendiri,
running Ubuntu pakai Speedy.
Berikut kondisi sebelum VPN connect :
root@breadwinner:~# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
192.168.1.0 0.0.0.0 255.255.255.0 U 2 0 0 wlan0
169.254.0.0 0.0.0.0 255.255.0.0 U 1000 0 0 wlan0
0.0.0.0 192.168.1.1 0.0.0.0 UG 0 0 0 wlan0
root@breadwinner:~# cat /etc/resolv.conf
# Generated by NetworkManager
nameserver 8.8.8.8
nameserver 8.8.4.4
root@breadwinner:~# ifconfig
wlan0 Link encap:Ethernet HWaddr 00:26:60:73:50:aa
inet addr:192.168.1.100 Bcast:192.168.1.255 Mask:255.255.255.0
Dan ini setelah terhubung VPN
root@breadwinner:~# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
202.6.211.33 192.168.1.1 255.255.255.255 UGH 0 0 0 wlan0
192.168.1.0 0.0.0.0 255.255.255.0 U 2 0 0 wlan0
172.29.0.0 0.0.0.0 255.255.192.0 U 0 0 0 tun0
169.254.0.0 0.0.0.0 255.255.0.0 U 1000 0 0 wlan0
0.0.0.0 0.0.0.0 0.0.0.0 U 0 0 0 tun0
root@breadwinner:~# cat /etc/resolv.conf
# Generated by NetworkManager
nameserver 10.0.12.32
nameserver 8.8.8.8
nameserver 8.8.4.4
root@breadwinner:~# ifconfig
tun0 Link encap:UNSPEC HWaddr
00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:172.29.36.122 P-t-P:172.29.36.122 Mask:255.255.192.0
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1412 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:4 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:500
RX bytes:0 (0.0 B) TX bytes:5648 (5.6 KB)
wlan0 Link encap:Ethernet HWaddr 00:26:60:73:50:aa
inet addr:192.168.1.100 Bcast:192.168.1.255 Mask:255.255.255.0
Silahkan dicoba dulu.
Kalo masih gak bisa, hubungi pihak berwajib :
Hotline KlikBCA Bisnis di (021) 52 999 777.