You can install the Shrew Soft VPN client on any computer that uses Windows 7, 8, or 8.1. The installation process includes two parts: install the client software on the remote computer and import the end-user profile into the client.
After you import the end-user profile, if you use certificates for authentication, you must import your certificates to the Shrew Soft VPN Client. However, if you used Policy Manager to generate the end-user profile client configuration file (.vpn file), the certificate is embedded in the .vpn file, so you do not have to manually import it. But, if you used Fireware Web UI or the CLI to generate the .vpn file, you must manually import the certificates to the Shrew Soft VPN client after you import the end-user profile.
This software package uses strong cryptography, so even if it is created,maintained and distributed from liberal countries in Europe (where it is legalto do this), it falls under certain export/import and/or use restrictions insome other parts of the world.
This software package should install on any reasonable machine running a 32 or 64bit version of Windows 2000, XP, Vista or Windows 7/8. Testing has only been performedon machines running with the latest service packs installed. For this reason, you areencouraged to keep your operating system up to date when using this software. An accountwith administrative privileges will be required to run the install application but notfor normal operation.
The Shrew Soft VPN Client for Windows is available in two different editions, Standard andProfessional. The Standard version provides a robust feature set that allows the user toconnect to a wide range of open source and commercial gateways. It contains no trial periodlimits, nag screens or unrelated software bundles. It is simply free for both personal andcommercial use. The Professional edition offers additional features that may be helpful forusers connecting to a corporate LAN. It is installed by default with a 14 day evaluationperiod limit. To use the Professional edition after the evaluation period has expired, aclient license may be purchased from the Shrew Soft Shop.
The Shrew Soft VPN Client for Windows is an IPsec Remote Access VPN Client for Windows 2000,XP, Vista and Windows 7/8 operating systems ( 32 and 64 bit versions ). It was originallydeveloped to provide secure communications between mobile Windows hosts and open source VPNgateways that utilize standards compliant software such asipsec-tools, OpenSWAN, StrongSWAN,Libreswan, isakmpd.It now offers many of the advanced features only found in expensive commercial softwareand provides compatibility for VPN appliances produced by vendors such as Cisco, Juniper,Checkpoint, Fortinet, Netgear, Linksys, Zywall and many others.
The Shrew Soft VPN Client for Windows is available in two different editions, Standard andProfessional. The Standard version provides a robust feature set that allows the user toconnect to a wide range of open source and commercial gateways. It contains no trial periodlimits, nag screens or unrelated software bundles. It is simply free for both personal andcommercial use. The Professional edition offers additional features that may be helpful forusers connecting to a corporate LAN. It is installed by default with a 14 day evaluationperiod limit. To use the Professional edition after the evaluation period has expired, aclient license may be purchased from the Shrew Soft Shop.
Recently, I have upgraded my OS to Windows 8. I tried to install SonicWall vpn client but that crashes my Windows 8 during installation. So after several installation failures, I decided to go with Shrew Soft VPN client which works great with our Client's Cisco vpn server.
The problem is that my VPN connection breaks periodically - sometimes every couple of hours and sometimes as often as every few minutes. This is just how my gateway is - it is not VPN client's fault. I just re-connect and keep working.
Why doesn't Shrew Soft VPN client have an option to automatically re-connect disconnected sessions ? I understand that I can do it manually, but that is quite disruptive. If there's no way to achieve auto-reconnection in the current version, then consider it a feature request.
I have some clients running firmware R10-9-5-E that have VPN client disconnect issues that I can't figure out. The VPN client is Shrew Soft version 2.2.2 and 2.1.7 running on both Windows 7 and Windows 8.1 computers. The VPN tunnel will come up as expected and the connection is established. I can RDP into a file sharing PC with no issues and perform updates, use the browser to download files, uninstall software from the Control Panel, etc. The issue is when I copy over a file to the remote PC. In this case as a test I wanted to copy/paste the router firmware file which is 10 to 15MB in size. Once the paste reaches between 60 and 80% the VPN disconnects and my RDP session is obviously terminated. If I enter the VPN password in the Shrew client, it will reconnect and the RDP session reconnects right away, but the file transfer is obviously halted. I can reproduce this effect every time. My clients are getting disconnected in similar fashion.
The Shrew VPN client software will connect to the Netvanta 3120 with no issues and seems to work normally. The user can open mapped folders, ping or access the router as if local, remote desktop to the file sharing PC and work on it remotely. The problem occurs when any larger IPSec traffic occurs. In my test case I was trying to copy a 10MB file to and from the remote desktop PC. In both cases the VPN client would get disconnected at various points during the upload/download of the file copy.
When the VPN client and router are transferring data in a constant fashion there is an issue with the Shrew VPN client software and router Dead Peer Detection (DPD) being sent and read back and forth between the two. When the software, or router does not respond to DPD the router thinks the peer is dead and terminates the connection. The issue is resolved by changing the Shrew VPN client software VPN configuration. Modify the VPN Site Configuration you have created, select the second tab called "Client", at the bottom of this section is "Other Options", uncheck "Enable Dead Peer Detection", click "Save".
So I haven't touched our VPN client software in a long, long while. We installed the Cisco client SW on our remote 32 bit tablets, sent them out, and sacrificed a goat to ensure that there would be no issues. It's been good-ish, but trying to get going on Win7 64 bit has been... fun. Somewhere on the forums, I got tipped off to Shrew Soft VPN client, a beautiful piece of OSS goodness. Installs in about 30 seconds, can import .PCF files, and the installer works on every windows OS in our environment. Give it a try if you're VPNing through an ASA and facing the same headaches we have - www.shrew.net
Init script
To make use of the Shrew VPN client the IKE deamon must be started by root. You can do this manually or you can make an INIT script to start if for you on the next boot:
To run at manually run the following command as root
I have most things working the way I want, except for remote access vpn. I was finally able to make a connection and I can access LAN resources fine, but I have no Internet while doing so. I seem unable to access my regular DNS server. If I do an nslookup from the command line specifying the utm as a resolver, it works fine. But I don't see how to assign that to vpn client sessions. I do have the ipsec vpn pool allowed to use the utm as a resolver, so it's not that. I don't see anything being dropped in the firewall log and the ipsec log looks pretty clean as well.
Thank you for the reply. I installed the Shrew Soft client at work this morning ( I was testing last night using a hosted Windows sever VPS at OHV), and I only specified the remote LAN in the Shrew Soft client. It worked...for about ten minutes. Then it disconnected and will not connect again.
It seems that either the utm at home crashed, or my service provider is suffering a local outage. My wife texted me that the internet is down at home. At least I know it was my just my vpn client :) On the other hand, if it is just the utm that crashed, that will suck. The wife will not be happy...might have to put the ASA back in place.
Well, it turns out that it is something to do with the vpn traffic that is crashing my internet. I can't see what is happening remotely, but the internet came back up after my wife rebooted the cable mode. I connected with the Shrew Soft client again and then (exactly like earlier) as soon as I try to rdp a machine in my remote lan, the internet went down again. Very weird.
But....I now have this weird internet crashes whenever I try to rdp a specific machine in my remote lan from my office. I connected from my Windows vps using the shrewsoft client and was able to rdp everything that I wanted to with no issues. I then connected from my desk, using the same Shrew soft client and settings and everything was great until I tried to rdp that specific machine, and boom the internet crashes. This is the third time that I can repeat this on demand by trying to rdp my laptop at home from my pc at work.
df19127ead