Cisco VPN Config HOWTO - Galaxy S I9000 General

I have posted this at DARKYROM, i thought it might be useful here too.
Heres a quick "how to" get Cisco IOS VPN working with DARKYROM native vpn client
because of the limitations in android we cannot use group authentication, it does not work.however this how to will show how you to create an L2TP/IPSec tunnel from your Cisco @ work or home to your droid (Preferably darky rom) native client. I.E. settings > wireless & networking> vpn
there is only one prerequisite and that is that you have advandced ip services ios ( required for ipsec)
heres the cisco config additions, please change the stuff in the <CHANGE ME>.
aaa new-model
!
aaa authentication login default local
aaa authentication ppp default local
aaa authorization exec default local
!
user <USERNAME> password <PASSWORD>
!
vpdn enable
!
vpdn-group L2TP
! Default L2TP VPDN group
accept-dialin
protocol l2tp
virtual-template 1
no l2tp tunnel authentication
!
!
!
crypto isakmp policy 10
encr 3des
authentication pre-share
group 2
lifetime 3600
crypto isakmp key <KEY> address 0.0.0.0 0.0.0.0 no-xauth
crypto isakmp keepalive 3600
!
crypto ipsec transform-set ipnetconfig esp-3des esp-sha-hmac
mode transport
!
crypto dynamic-map ipnetconfig-map 10
set nat demux
set transform-set ipnetconfig
!
!
crypto map cisco 10 ipsec-isakmp dynamic ipnetconfig-map
!
interface FastEthernet 4 (This is the OUTSIDE interface, this may be different on your router)
ip address dhcp
duplex auto
speed auto
crypto map cisco (This is the line required to your outside interface)
!
interface Virtual-Template1
ip unnumbered FastEthernet 4 (This is the OUTSIDE interface, this may be different on your router)
peer default ip address pool poolipnetconfig
ppp encrypt mppe 40
ppp authentication ms-chap-v2
!
!
ip local pool poolipnetconfig 172.16.0.9 (change this to whatever range your lan is as this is the address that will be assigned to your droid)
!
end
DO NOT Just copy and paste this onto your router. you must edit it first and remove the comments and the brackets.
Please change the ip, username, passwords and keys to make this work.
then basically on your droid goto the vpn settings and create a L2TP/IPSec vpn. input a name a shared key and the ip address or dns name of your router (internet address).
save the config and try to connect, this will ask for the aaa username and password. enter this and then it should connect. wayhey!!!!!!!!!!!!!!!!!

Any chance SSL VPN can work?

hmmmm dunno i have not tried... maybe ill have a go

hvc123 said:
hmmmm dunno i have not tried... maybe ill have a go
Click to expand...
Click to collapse
I found a Cisco Anyconnect client on the market.
https://market.android.com/details?id=com.cisco.anyconnect.vpn.android&feature=search_result
Just need to acquire mobile licenses for the ASA...

Related

WIFI with a "Conceptronic C54APM" Access Point

Is it possible to connect the Trinity to a "Conceptronic C54APM" access point with WEP activated?
I am able to connect it, give the correct password but I can get no communication!!!
Thanks in advance.
edba2000 said:
Is it possible to connect the Trinity to a "Conceptronic C54APM" access point with WEP activated?
I am able to connect it, give the correct password but I can get no communication!!!
Thanks in advance.
Click to expand...
Click to collapse
Try taking off the wep protection on your access point, then get the Trinity connnected. If all is well, then add the wep again. Make sure that you check that the "shared" option is the same on both.
Just in case, access can also be restricted/enabled at the MAC level.
Thanks for the answer.
Even without WEP, I still can't connect
Here is my "Access Point" config:
System
Up time 0day:0h:21m:25s
Hardware Version Rev. A
Firmware Version 1.25
Wireless Configuration
Mode AP
ESSID xxxxxx
Channel Number 5
Security WEP
BSSID 00:xx:xx:xx:xx:xx
Associated Clients 2
LAN Configuration
IP Address 192.168.0.2
Subnet Mask 255.255.255.0
Default Gateway 192.168.0.1
MAC Address 00:xx:xx:xx:xx:xx
Authentication Type : Open System Shared Key [X]Auto
Fragment Threshold : 2346 (256-2346)
RTS Threshold : 2347 (0-2347)
Beacon Interval : 100 (20-1024 ms)
Data Rate : 54M
Transmit Rate :
Preamble Type : [X] Long Preamble Short Preamble
Broadcast ESSID : [X] Enabled Disabled
IAPP : [X] Enabled Disabled
802.11g Protection : Enabled [X] Disabled
Encryption : WEP
Key Length : 128 bit
Key Format : ASCII (13 char)
Default Tx Key : key1
Encryption Key 1 : *************
Encryption Key 2 : *************
Encryption Key 3 : *************
Encryption Key 4 : *************
[ ] Enable 802.1x Authentication
* Management IP
IP Address : 192.168.0.2
Subnet Mask : 255.255.255.0
Gateway Address : 192.168.0.1
DHCP Server : enabled
* DHCP Server
Default Gateway IP : 192.168.0.1
Domain Name Server IP : 192.168.0.1
Start IP : 192.168.0.5
End IP : 192.168.0.10
Domain Name :
Lease Time : forever
When I connect my HTC to the AccessPoint, the IP 192.158.0.5 is assigned to it but I can't ping to 192.168.0.2 (the AP IP)
Some other help would be great!
Thanks
edba2000 said:
Is it possible to connect the Trinity to a "Conceptronic C54APM" access point with WEP activated?
I am able to connect it, give the correct password but I can get no communication!!!
Thanks in advance.
Click to expand...
Click to collapse
You should try and connect your Trinity to another hot spot just to make sure that the Wifi is working properly. If so, you might try resetting your access point by the pin hole on the back, or however your AP resets. Personally, if I'm ever having trouble connecting a device to my network, I turn off all encryption and filtering until I get a connection. The info you gave shows WEP encryption is still on.
Hi Matterhorn,
Thanks for the answer. The info I gave shows WEP activated, but I did the test without WEP too. The result is the same.
The HTC is working properly and I can connect to other APs. I can't understand what's happening!!!
JUST FOUND THE PROBLEM!!!
The power mode must be: "Best Performance"
Thanks to all.

Default Gateway

I am able to connect via Wifi and getting IP address but the default gateway is sometime set and sometime not. When it is not set i can not surf the internet. Is there a way to set the default gateway in HEMRES ?
Someone , please help
All I need to know is how to set the deafult gateway to 192.168.0.1 same as DHCP Server.
DHCP should give it all the settings
might be worth looking to why your DHCP server isnt giving out the correct settings, but any way
Settings > Connections > Network cards > Network Adapters
you will have a list of the Adapters
at a guess it would be the IEE 802.11b/g Compatable wifi
tap on that
and it should give you some options tick Use Specific IP Address, put in the details
please note this will set the details for all wireless connections, so if only use wireless at home, then it will be no problem, but say you use it at home, at work and out and about at Hotspots, you may need to go in and change it back to using DHCP for it to work
DHCP server settings
might be worth looking to why your DHCP server isnt giving out the correct settings,
Click to expand...
Click to collapse
can you give some hints how to do that ?
I did what you said , in VxIPConfig it said DHCP Disabled, and got the deafult gateway as 192.168.0.1 . I couldn't surf the internet.
Please that from time to time I am able to surf the internet when everything is set to auto. When it happens I get the deafult gateway set (and not blank) and the DHCP is enbale
dotan_shai said:
I did what you said , in VxIPConfig it said DHCP Disabled, and got the deafult gateway as 192.168.0.1 . I couldn't surf the internet.
the DHCP is enbale
Click to expand...
Click to collapse
did you give it an ip addresss and subnet mask ?
eg for ip
192.168.0.10
subnet
255.255.255.0
is your DHCP server on a router or is it like a PC with WiFi running Internet connection sharing
I did what you say , this is what VxIPConfig said:
adapter address : 00-09-2d-b4-91-43
IP address : 169.254.210.158 (which is what i set)
Subnet mask : 255.255.255.0
Deafult gateway : 192.168.0.1 (which is what i set)
DHCP server : 192.168.0.1
Primary WINS : empty
Secondary WINS : empty
Lease obtained : DHCP Disabled
Lease expaired : DHCP Disabled
still can not surf the internet , what is wrong.
dotan_shai said:
I did what you say , this is what VxIPConfig said:
adapter address : 00-09-2d-b4-91-43
IP address : 169.254.210.158 (which is what i set)
Subnet mask : 255.255.255.0
Deafult gateway : 192.168.0.1 (which is what i set)
DHCP server : 192.168.0.1
Primary WINS : empty
Secondary WINS : empty
Lease obtained : DHCP Disabled
Lease expaired : DHCP Disabled
still can not surf the internet , what is wrong.
Click to expand...
Click to collapse
where did you get 169.254.210.158 from?
try 192.168.0.100
as i dont think you will have anything on that ip
with a 192.168.0.1 gateway and subnet mask of 255.255.255.0
your ip needs to be within 192.168.0.* range ( * = 1 to 255)
yeah a class c ip range is what one should use in ones internal lan
192.168.0.0 – 192.168.255.255
http://en.wikipedia.org/wiki/Private_network
Dear frinds,
Thanks a lot for your help , but still no change. This is what i got from VxIPConfig :
adapter address : 00-09-2d-b4-91-43
IP address : 192.168.0.100 (which is what i set)
Subnet mask : 255.255.255.0
Deafult gateway : 192.168.0.1 (which is what i set)
DHCP server : 192.168.0.1
Primary WINS : empty
Secondary WINS : empty
Lease obtained : DHCP Disabled
Lease expaired : DHCP Disabled
The previous IP adress was the one that was set automatically before i changed it manulaly.
Still no surfing the internet. you said before :
might be worth looking to why your DHCP server
Click to expand...
Click to collapse
I'm not using a router it is
PC with WiFi running Internet connection sharing
Click to expand...
Click to collapse
the USB to Wifi adapter is configured as Ad-Hock.
dotan_shai said:
Dear frinds,
Thanks a lot for your help , but still no change. This is what i got from VxIPConfig :
adapter address : 00-09-2d-b4-91-43
IP address : 192.168.0.100 (which is what i set)
Subnet mask : 255.255.255.0
Deafult gateway : 192.168.0.1 (which is what i set)
DHCP server : 192.168.0.1
Primary WINS : empty
Secondary WINS : empty
Lease obtained : DHCP Disabled
Lease expaired : DHCP Disabled
The previous IP adress was the one that was set automatically before i changed it manulaly.
Still no surfing the internet. you said before :
I'm not using a router it isthe USB to Wifi adapter is configured as Ad-Hock.
Click to expand...
Click to collapse
I see now, the ip 169.254.210.158 would be when the ppc couldn't get an IP from the DHCP Server
just a thought
Have you input in some dns servers, should be on the next tab
these dns servers will do
dns 1: 4.2.2.1
dns 2: 4.2.2.2
how did you setup internet connection sharing on you pc ?
via network setup wizard ?
Network connections > Pick your internet connection > right click then properties > then click on the Advanced tab > then make sure the Allow other computers on the network to use this connection, tick box is checked
I added the DNS adresses settings in the PPC , still can not surf the internet.
how did you setup internet connection sharing on you pc ?
via network setup wizard ?
Click to expand...
Click to collapse
That's the way i set my internet connection sharing.
Network connections > Pick your internet connection > right click then properties > then click on the Advanced tab > then make sure the Allow other computers on the network to use this connection, tick box is checked
Click to expand...
Click to collapse
It is checked !! I remove the check in Allow other users to control or disable the shared Internet connection.
I've noticed that in success connection that allowing me to surf, the beacon icon in PPC is changing for 2 seconds to beacon without the circles and than return to its previous picture beacon with two circles. In a failed connection I always see the beacon with the two circles icon that never change.
Still no surfing is available. Any more ideas ?
SOLVED !!!
Thanks for the helpers. My problem is now solved. I've just read in D-Link site regarding configuring Static IP in here
After performing the recommended settings, everything is working always.
THIS THREAD CAN BE CLOSED
Glad its working
so did you need to setup a static ip for your pc, or did you use the guide and put the details in to your ppc ?
The static IP was set in the PC according to D-Link instructions . Hope this tread helped someone .
Here is the link to D-link , static IP settings :
http://support.dlink.com/faq/view.asp?prod_id=2594&question=DWL-G122

Help Required (defining gateway address)

Hi,
Can any body help me in defining gateway address on my imate jasjam. I want to browse internet on my device and without defining gateway address, i am unable to do so.
I've used "wifi profiles" software and defined manual ip, gateway and dns but it is not retreiving gateway settings. At my workplace, there is a dhcp server which is automatically assigning an ip address to my device.
Regards,
Kashif Mehmood

EAP TTLS PAP authentication

I have written a WiFi client that supports OPEN and Preshared key networks, and am trying to add EAP TTLS PAP authentication. The Android WifiConfiguration class has settings for supporting preshared keys, but I don't see how to set the various fields for EAP TTLS PAP, such as inner and outer identity, password.
Has anyone tried to do this?
pliaw said:
I have written a WiFi client that supports OPEN and Preshared key networks, and am trying to add EAP TTLS PAP authentication. The Android WifiConfiguration class has settings for supporting preshared keys, but I don't see how to set the various fields for EAP TTLS PAP, such as inner and outer identity, password.
Has anyone tried to do this?
Click to expand...
Click to collapse
I have the same problem, my friend has an Eris that has all the additonal config parameters you mentioned (inner/outer tunnel, etc...)

own hosting and ip address

I'm installed termux 118 and installed nginx server on my android 9,
I made a domain name ddns service - duckdns site,
connected my ip address, started the server,
and my site is up and running, but after a while,
I can't connect to the my site,
and see this error in windows network diagnostic:
"resource (myDomainName) is online but isn't responding to connection attempts."
Me interested, what is mean? Problem in my phone, server?
or something is blocking my requests to the host IP address of my home internet provider.
Or is it because the free domain name on duckdns is unstable?
I found only approximate answer to this error on the Internet:
-Reset TCP/IP and DNS Cache
-Turn Off Proxy Settings
-Reset Network Settings
-Disable Extensions/Add-ons On The Browser

Categories

Resources