<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to Site IPSEC VPN through 2wire BT router in Archive</title>
    <link>https://business.forums.bt.com/t5/Archive/Site-to-Site-IPSEC-VPN-through-2wire-BT-router/m-p/29061#M4339</link>
    <description>&lt;P&gt;Don't believe I'm even on .48:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Model:&lt;/TD&gt;&lt;TD&gt;2701HGV-C&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Hardware Version:&lt;/TD&gt;&lt;TD&gt;2701-100630-008&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Firmware Version:&lt;/TD&gt;&lt;TD&gt;6.3.9.41-plus.tm&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;P&gt;If I'm reeading&amp;nbsp; the above correctly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 08 Aug 2011 14:58:54 GMT</pubDate>
    <dc:creator>watcher60</dc:creator>
    <dc:date>2011-08-08T14:58:54Z</dc:date>
    <item>
      <title>Site to Site IPSEC VPN through 2wire BT router</title>
      <link>https://business.forums.bt.com/t5/Archive/Site-to-Site-IPSEC-VPN-through-2wire-BT-router/m-p/29055#M4337</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp; not sure if anyone can help. My set up is a 2wire ADSL router (bt issue) with a netscreen firewall behind it. I have the netscreen set to pick up its IP from the 2wire adsl router via DHCP. and it gets assigned the WAN IP the router picks up. I have the Netscreen set as the DMZplus host with all applications etc allowed to it. I'm trying to set up a IPsec vpn from the netscreen to one of our other office sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While I can get this to work for short periods (i.e hour or so) it does fail. Looking in the system log what appears to be happening is the 2wire router is VPN capable and is taking over the IKE port which then causes the VPN from the netscreen to fail. In the log entries below I've changed the IP address so that 1.1.1.1 is the external IP I'm getting on the BT router and being used by the netscreen and 2.2.2.2 is the remote site:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When it is working I see this in the&amp;nbsp; system log on the BT 2wire adsl router:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;INF 2011-08-08T15:03:36+01:00 stream: sock_osr_bind: T_ERROR_ACK, TLI_error 23 UNIX_error 0&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;ERR 2011-08-08T15:03:37+01:00 iked: [INTERNAL_ERR]: isakmp.c:547:&amp;lt;unknown&amp;gt;(): bind(1.1.1.1[500]): Address already in use&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;INF 2011-08-08T15:03:37+01:00 iked: [INFO]: main.c:652:&amp;lt;unknown&amp;gt;(): starting iked for racoon2 repository&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;INF 2011-08-08T15:03:37+01:00 stream: sock_rput_pcproto: T_ERROR_ACK for type 1, TLI error 23, UNIX error 0&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;INF 2011-08-08T15:03:37+01:00 stream: sock_osr_bind: T_ERROR_ACK, TLI_error 23 UNIX_error 0&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;ERR 2011-08-08T15:03:37+01:00 iked: [INTERNAL_ERR]: isakmp.c:547:&amp;lt;unknown&amp;gt;(): bind(1.1.1.1 [500]): Address already in use﻿&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I think you can see its complaining it can't use the external IP for IKE (as I presume its being used for mapping to the netscreen)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when the VPN fails I see the following msg in the 2wire system log that seems to indiciate its taken over the IKE on the external IP and is dropping the connections as its not configured to setup a VPN to the remote host:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERR 2011-08-08T13:42:46+01:00 iked: [PROTO_ERR]: ikev1.c:1031:&amp;lt;unknown&amp;gt;(): couldn't find configuration for remote 2.2.2.2[500] (local 1.1.1.1[500])&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;ERR 2011-08-08T13:42:50+01:00 iked: [INTERNAL_ERR]: cfsetup.c:3824: macro extension failed: IPSEC_DATA%peers_ip&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;﻿&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Ideally it sounds as if I need to turn off the IKE deamon on the 2wore router but I cannot see anyway to achieve this. Does anyone have any tips etc on how to overcome this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2011 14:44:54 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Site-to-Site-IPSEC-VPN-through-2wire-BT-router/m-p/29055#M4337</guid>
      <dc:creator>watcher60</dc:creator>
      <dc:date>2011-08-08T14:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site IPSEC VPN through 2wire BT router</title>
      <link>https://business.forums.bt.com/t5/Archive/Site-to-Site-IPSEC-VPN-through-2wire-BT-router/m-p/29059#M4338</link>
      <description>&lt;P&gt;Hi watcher60,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What firmware if your business hub running? If it is running the .48 firmware as this might need to be updated to the .49 firmware youou will need to contact the helpdesk to get this done. Hare are the &lt;A href="http://btbusiness.custhelp.com/app/contact#s=ImNhdD18Zm9ybV9zdGF0ZT0wIg.." target="_self"&gt;helpdesk contact options&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Markp&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2011 14:54:24 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Site-to-Site-IPSEC-VPN-through-2wire-BT-router/m-p/29059#M4338</guid>
      <dc:creator>markp</dc:creator>
      <dc:date>2011-08-08T14:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site IPSEC VPN through 2wire BT router</title>
      <link>https://business.forums.bt.com/t5/Archive/Site-to-Site-IPSEC-VPN-through-2wire-BT-router/m-p/29061#M4339</link>
      <description>&lt;P&gt;Don't believe I'm even on .48:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Model:&lt;/TD&gt;&lt;TD&gt;2701HGV-C&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Hardware Version:&lt;/TD&gt;&lt;TD&gt;2701-100630-008&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Firmware Version:&lt;/TD&gt;&lt;TD&gt;6.3.9.41-plus.tm&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;P&gt;If I'm reeading&amp;nbsp; the above correctly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2011 14:58:54 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Site-to-Site-IPSEC-VPN-through-2wire-BT-router/m-p/29061#M4339</guid>
      <dc:creator>watcher60</dc:creator>
      <dc:date>2011-08-08T14:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site IPSEC VPN through 2wire BT router</title>
      <link>https://business.forums.bt.com/t5/Archive/Site-to-Site-IPSEC-VPN-through-2wire-BT-router/m-p/29063#M4340</link>
      <description>&lt;P&gt;Hi watcher60,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firmware verion .48 and .49 relates to the 2700HGV not the&amp;nbsp;2701HGV-C﻿ router. The 2701HGV-C﻿ will not need a firmware update. I would recommend contacting the helpdesk on the following &lt;A href="http://btbusiness.custhelp.com/app/contact#s=ImNhdD18Zm9ybV9zdGF0ZT0wIg.." target="_self"&gt;contact options&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Markp&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2011 15:07:27 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/Site-to-Site-IPSEC-VPN-through-2wire-BT-router/m-p/29063#M4340</guid>
      <dc:creator>markp</dc:creator>
      <dc:date>2011-08-08T15:07:27Z</dc:date>
    </item>
  </channel>
</rss>

