Hi All, I am trying to configure an IPSec site-to-site VPN connection between our Essential Business Server 2008 Security Server, running TMG Medium Business Edition (MBE) and a Cyberoam CR35wi located at a remote site. While the process should be very simple,
I am simply not having any luck getting it to play nice.
- Microsoft Forefront Threat Management Gateway is version: 6.0.6417.100 MBE
- Cyberoam CR35wi is at firmware level 10.01.0 build 739
Both TMG and CR35wi have identical configuration for IPSec connection; Phase 1, EA = 3DES, AA = SHA1, DH Group = 2 (1024), Key Life 28800 - Phase 2, EA = 3DES, AA = SHA1, PFS Group (DH Group) = 2 (1024), Key Life = 3600. Both utilise the same Preshared Key.
The CR35wi reports connection issues, e.g.: "EST-P1: Peer did not accept any proposal sent.", "EST-P2: Max number of retransmission 2 reached. No response to first quick mode message. Perhaps peer likes no proposal."
While TMG shows successful connection in log:
- 2011/08/04 02:04:15 PM10.0.0.610.0.0.5500IKE ClientInitiated Connection[System] Allow VPN site-to-site traffic to Forefront TMG0x0 ERROR_SUCCESS
And in TMG Sessions:
- 2011/08/04 02:08:23 PM SVREBSSEC [no Client IP] VPN Remote Site [site name] [no Client Host Name] VPN (IPSec Tunnel)
Any attempts at pinging or accessing resources in remote networks are met with failure, so the connection doesn't appear to be valid.
While troubleshooting the problem using "Troubleshooting VPN over IPSec" (http://technet.microsoft.com/en-us/library/bb794765.aspx) I found that policyagent service had
been disabled on the TMG server. Now I installed the EBS2008 deployment myself and know that I didn't disable that service, so I'm now in doubt as to whether IPSec is functioning properly on the EBS Security Server/TMG. As EBS2008 has been discontinued, documentation
specific to this platform is difficult to come by.
I'd appreciate it if anyone could assist with verifying that IPSec VPN support is indeed fully functional in TMG MBE as deployed with EBS2008. Is there a simple way to test this?
Regards,
Byron.