wap.howardforums.com | FAQs | Reviews | About | Rules | Advertise | Contact  
HowardForums: Your Mobile Phone Community & Resource

Go Back   HowardForums: Your Mobile Phone Community & Resource > US Carrier Discussion > ATT.HowardForums.com
User Name
Password
Marketplace Register FAQ Premium Mark Forums Read



Reply
Welcome to the HowardForums: Your Mobile Phone Community & Resource.
HowardForums is discussion board dedicated to mobile phones with over 1,000,000 members and growing!

For your convenience HowardForums is divided into 7 main sections; marketplace, phone manufacturers, carriers, smartphones/PDAs, general phone discussion, buy sell trade and general discussions. Just scroll down to see them!

Only registered members may post questions, contact other members or search our database of over 8 million posts. Why don't you join us today!

CLICK HERE TO REGISTER

If you have time check out our sister sites:
HowardChui.com - Where you can find the latest mobile phone news and reviews.
HowardChui.com phone gallery - See interesting pictures of phones that we've taken.
HowardForums Wiki - Our Mobile Phone Encylopedia.
Niknon.com - Our sister site about Digital Photography.
SlowFo.com - General Discussion.
 
Thread Tools Display Modes
  #1  
big_redfox big_redfox is offline

Phone fan
Phone(s):
1:
2:
3:
Provider(s):

Joined: Dec 2003
Posts: 18
Talking Got Cisco VPN working via wap with Bluefire on Tilt

Just want to share the experience I had on getting Cisco VPN working via wap.cingular using Bluefire.

Bluefire can be found here: http://www.bluefiresecurity.com

I also tried athanvpn http://www.anthavpn.com . Both have different GUI but identical features.

When I first started, the biggest issue is encrypted group password. Most corporations uses encrypted group password, which neither of these software supports. After 2 days of looking around on Google, I found a group password decoder that works:

http://www.unix-ag.uni-kl.de/~massar/bin/cisco-decode

You can also verify that this decoder works by copying your original .pcf file and edit the group password section (take out the encrypted one and put in the non encrypted one), and then import the edited .pcf file. Cisco's VPN client on PC should re-encrypt the password and it should be the same string as in your original .pcf file.

The next thing is to connect your VPN using VPN client on PC and look at the statistics section. It should show you the encryption and authentication methods. This is for IPsec part of the VPN. Before connection can be made (pop up screen for user name and password), an IKE session has to complete. IKE session can use totally different encryption and authentication method as IPsec. However, most companies keep them the same.

There is also a term of "Group" or "DHGroup" in VPN. For most companies, use Group 2 or DHGroup 2.

For Bluefire, most of these terms are hidden in a .xml file. You should configure the connection as much as you can, then export the connection. Edit the exported file to the encryption/authenticaiton you want, and import the connection again. MAKE SURE YOU DELETE EXISTING CONNECTIONS BEFORE IMPORT! Sometimes Bluefire just make a second connection with the same name and you end up have no idea which one is which.

Last but not least, neither software supports load balancing! If you connect to a big corporation with multiple VPN servers, there is more likely load balancing. On your PC, turn on logging on IKE and do a connection. If you have load balancing, you should see messages on load balancing and also shows the IP address of the VPN server you are actually connecting to. This is the IP address you should use for your Mobile VPN SW.

I got VPN connection working on two client site, one is a huge networking company and the other one is a high tech startup.

The next issue is how to keep VPN connection alive. Simply keeping your data connection alive on your phone does not keep the VPN alive. I am testing "GPRS Keep Alive 1.01" to ping a machine inside the firewall every 30 sec, to see if VPN can be kept alive for the whole day.

All my connection is made via wap.cingular. I have the $39.99 PDAPersonal plan and isp.cingular is not working. I do get assigned an IP address by the VPN server and I actually got SSH (putty) working.

Yes, doing this would costs a lot of juice in the battery. I am also testing how many hours the batter would last.

Reply With Quote
  #2  
big_redfox big_redfox is offline

Phone fan
Phone(s):
1:
2:
3:
Provider(s):

Joined: Dec 2003
Posts: 18
OK, it seems that ATT terminates data session after an hour or so. I am going to call ATT tomorrow to see if it is the case and if they can take out this limit. The problem is that my Cisco VPN password is not static, but based on Softoken II (generated by a PC app). I can pregenerate the keys, but if I have to do it 8-9 times a day, that's a lot of trouble.
Reply With Quote
  #3  
Elfreshcuh's Avatar
Elfreshcuh Elfreshcuh is offline

Banned
Phone(s):
1: i880, i580, i530 (nextel)
2: nokia N91 & Nokia 6030 Cingular Prepaid
3: iPHONE 4gb & HTC tytn (UNBRANDED)
Provider(s):
Nextel Cingular
Joined: Aug 2006
From: SANFORD, FL
Posts: 1,662
Send a message via AIM to Elfreshcuh Send a message via MSN to Elfreshcuh
Quote:
Originally Posted by big_redfox
OK, it seems that ATT terminates data session after an hour or so. I am going to call ATT tomorrow to see if it is the case and if they can take out this limit. The problem is that my Cisco VPN password is not static, but based on Softoken II (generated by a PC app). I can pregenerate the keys, but if I have to do it 8-9 times a day, that's a lot of trouble.


why so often?
Reply With Quote
  #4  
big_redfox big_redfox is offline

Phone fan
Phone(s):
1:
2:
3:
Provider(s):

Joined: Dec 2003
Posts: 18
It looks like just pinging a machine behind the firewall does not keep the VPN connection alive. So I downloaded "pocketputty" and opened a shell on my Tilt. I wrote a shell script to ping another machine every 30 sec, and display the time. This is to simulate network activity. I kept the connection alive for 7.5 hrs last night.

Yep, the battery bar goes down real quickly. I am going to see next Monday if it would last from 9am to 5pm.
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump



Current time is 14:20 GMT.


Niknon.com | HowardChui.com | wap.HowardForums.com | wiki.HowardForums.com | SlowFo.com