cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
536
Views
5
Helpful
2
Replies

EZ_VPN and using port 150000 (TCP) Question

David Trad
VIP Alumni
VIP Alumni

Hi All,

I must be getting a little hazy with so much going on at the moment, but I am unable to see where in CCA I can setup the EZ_VPN to use port 15000 and TCP?

Basically I cannot do it as standard as they have their own VPN operational on the 800 series, and not much support to have it any other way but I have managed to get the networking solutions company to allow me to use 15000 and port forward it to the UC540, but need confirmation as to how I can get the UC540 to accept this incoming connection?

Cheers,

David.

Cheers, David Trad. **When you rate a persons post, you are indicating a thank you or that it helped, but at the same time you are also helping to maintain the community spirit - You don't have to rate posts and you wont be looked down upon :) *
1 Accepted Solution

Accepted Solutions

Brandon Turpin
Cisco Employee
Cisco Employee

Hi David,

There's not a way in CCA to configure EZVPN to use TCP.  Is the UC540 sitting behind the 800 router, which requires the port-forwarding?  Do you have an extra public ip address (or can you get one) to setup 1-to-1 NAT on the 800 router for this?  That would be a cleaner solution than configuring EZVPN over TCP via CLI.

Thanks,

Brandon

View solution in original post

2 Replies 2

Brandon Turpin
Cisco Employee
Cisco Employee

Hi David,

There's not a way in CCA to configure EZVPN to use TCP.  Is the UC540 sitting behind the 800 router, which requires the port-forwarding?  Do you have an extra public ip address (or can you get one) to setup 1-to-1 NAT on the 800 router for this?  That would be a cleaner solution than configuring EZVPN over TCP via CLI.

Thanks,

Brandon

Hi Brandon,

I'll Try and answer your questions...

Is the UC540 sitting behind the 800 router, which requires the port-forwarding?

Yes it is sitting behind a Cisco 857 router, and is currently doing all the port forwards on all incoming traffic

 Do you have an extra public ip address (or can you get one) to setup 1-to-1 NAT on the 800 router for this?

No the client will not pay for this as it is a significant cost here in Australia to purchase an extra IP address on a monthly basis from the carrier, and especially just to do VPN only, there would need to be a greater justification for this and right now there is not.

That would be a cleaner solution than configuring EZVPN over TCP via CLI.

Yes and no, in the past this was simple to do and achieve on CLI, the issue now is the restrictions of staying within CCA operational modes and it is clearly frustrating but something I am willing to deal with.

I am trying to convince their I.T house who manage that side of the network to create the EZ_VPN on the 857 instead and just make all the subnets routable, but they are not happy to do so given the issues they have had in the past with setting this up, and since we do not manage this router I am unable to make configuration changes to it which would only take me 15 or so minutes to do.... A rock between a hard place I think the saying goes????

Love Cisco systems, hate it when you have to integrate it into existing network and you have terratorial issues that you know just wont get resolved

I get laughed at daily here by the LG-Erricson stooges, always constantly telling me, program the LG phone system, give it an IP address and never hear back from the customer again until they need something... MEH! I think we both know this is just not possible with Cisco's

Cheers,

David.

Cheers, David Trad. **When you rate a persons post, you are indicating a thank you or that it helped, but at the same time you are also helping to maintain the community spirit - You don't have to rate posts and you wont be looked down upon :) *
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: