Home Forums Archive VaporSec Why does turning on VaporSec prevent ssh connection?

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #356895
    Anonymous
    Participant

    Hello,

    I’m trying to get two 10.2 Macs to share a VPN connection. I usually connect to the other Mac using ssh and then tunnel VNC through the ssh connection. My local Mac is behind a firewall and my remote Mac is on the internet.

    I set up VaporSec on my local machine using the remote IP # as the main configuration entry (everything else I just left alone except the shared secret).
    When I clicked the “Vaporize” button, the ssh connection went down and my VNC connection froze.

    I tried connecting again to no avail. I realized however that I had set up the remote VaporSec with my local Internet IP, not my LAN IP. So I put my local Mac on the internet and configured my local IP # accordingly. This enabled me to make the IPSec connection! I was then able to ssh to my remote box as well as fire up a VNC session through the tunnel.

    With this capability, I then of course wanted to have all my other computers on my LAN to also see the internet at the same time so I added a new entry to the remote VaporSec configuration. I then added 192.168.0.211 to my list of remote devices. When I clicked the Vaporize button, my connection again died. However, I am not able to get the VPN connection up and running again when going through my router. (I’m using Linksys BEFSR11 with IPsec Passthru enabled). So I thought I would re-connect with my local computer right on the internet and re-connect the VPN and then turn it off so I could at least ssh to the remote machine from behind the firewall. No go! Argh.

    Any ideas as to why this is happening, and if this is normal behavior? I figured this would work, but when I tail… troubleshoot the process it looks like its just timing out after the initiation of the phase 2 negotiation. Maybe this is a wrong password.

    I wish I could just ssh connect to the remote machine and fix the password! Hehehe. Oh well. Maybe next time.

    – Al

    #356916
    Anonymous
    Participant

    A little further down the road – I’ve learned that setkey is a little bit like iptables, it sets the behavior of your network connectivity. When I used VaporSec to configure two machines the rules specified that the network connection be created using specific protocols. That was preventing the ssh cconnections between the two machines. Once I flushed the rules, the two machines were able to connect flawlessly.

Viewing 2 posts - 1 through 2 (of 2 total)
  • You must be logged in to reply to this topic.

Comments are closed