Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Users might experience few discrepancies in Search results. We are working on this on our side. We apologize for the inconvenience it may have caused.
New Member

How to VPN out from inside a 'corporate firewall'?

Hi! How does one VPN out from a 'behind the corporate firewall' scenario to a remote network?

I found out that IPSec VPN uses ESP 50 and UDP 500 protocols and that if using transparent tunneling mode it can either encapsulate ESP 50 in UDP 500 (UDP) or both ESP 50 and UDP 500 inside TCP 10000 (TCP)--the later being ideal for overcoming stateful firewalls.

Unfortunately, my company has a firewall that does not allow direct connections to any outside internet address. For example, if I want to ssh to an outside host I need to request that they map an internal address to the external address I need to get to and then open the firewall for that specific SSH connection.

If I were to choose the TCP tunneling option and request an internal mapping of say port 22 to map to port 10000 (the standard VPN TCP port) and then configure the client as if the remote host was the internal address ( port 22) whoud that work?

Your help is much appreciated!!!



New Member

Re: How to VPN out from inside a 'corporate firewall'?

The short answer is that you need to request that they allow you to get to the IP address for the VPN and that they allow that VPN traffic back to you. In the senario you gave above it does not sound like the company you work for would be willing to do that. It is a simple process, but not one that you (the end user) control. It is controlled by the company, and more specifically the person(s) controlling the firewall.

New Member

Re: How to VPN out from inside a 'corporate firewall'?

Hi there,

thanks for replying! Effectively that mapping would give us access to the external concentrator and vice-versa. What I am not sure is whether that relay would cause the VPN to fail (or not) even if we use the TCP based tunneling... That mapping acts kinna like a temporary gateway to that external resource and to open that gate one needs to first authenticate to the firewall, and then use that internal address as if it were the destination (the firewall mapping takes care of the rest).

Any idea if that will work?



New Member

Re: How to VPN out from inside a 'corporate firewall'?

Here is the basic how it works... Your PC internal IP gets a static map to an external IP address from the firewall. Your PC requests to go to the External IP address for VPN. Firewall allows you to. You get to the external IP address for VPN, and try to authenticate. The External IP address passes back information ESP and UDP. Your firewall has to allow that information through to your PC. If ESP and UDP are not specifically allowed from that specific IP address to your specific IP address, then you don't get to VPN to a remote host from inside your network.

Thats as basic of an answer as I can think of. There are other things involved, but I think that should give you a pretty good idea as to how the process works. As long as we are talking about a Cisco PIX box you don't make the connection without both of these things happening. If you are the one configuring the firewall and I misunderstood your entire question, then I could show you an example of the configuration you would need to connect to the remote VPN. I have done it a few times, and it works well.

CreatePlease to create content