I recommended a DFL-210 for an office that needed to put the hammer down on employee use of the internet during business hours. Overall, the experience is a good one, but a nagging VPN problem exists. It is a Cisco VPN client issue - the user needs to VPN into a vendor server as part of their normal business activity.
The original network setup was a DSL Modem --> LinkSys WRT54G2 --> Local Network. This router has all its VPN pass-thru options enabled. The Cisco Systems VPN Client is version 4.0.2(D). The VPN client connects properly and establishes a link. Then another application (MediTech Magic Workstation 3.26c) is used to telnet to a server over the VPN link. The LinkSys setup works perfectly.
I have yet to get the D-Link DFL-210 to work with this application. Firmware Version: 2.20.02.12-7178
Jun 25 2008
First off, the Cisco VPN Client was originally configured to use transparent tunnelling via IPSEC over TCP using Port 9500. I never did get this to work. The router kept dropping packets due to:
16:52:06 Debug TCP_FLAG 3300016 TCPSequenceNumbers TCP lan wan 192.168.1.20112.34.243.37 19471 9500 tcp_seqno_too_low
drop seqno=16820901 accstart=16820902 accend=16886437 origsent=120 termsent=40 ipdatalen=20 syn=1
I was able to get past this error by modifying the TCP parameters to ignore this error, but then it started dropping packets due to corrupted TCP flags. I didn't get past that one - didn't try that hard, but felt it was not a good thing to have to go in and modify TCP settings anyway, so I undid the change above and went down another road.
The Cisco VPN client was reconfigured to avoid use of transparent tunneling. With this configuration, a DFL-210 IP Rule was set up using the pre-defined ipsec-esp service. Now the VPN Client successfully establishes a connection with the remote server and sets up link, but, the telnet client is unable to contact the remote IP. There are no drops listed in the DFL-210 log that appear relevant to the issue. The client is configured to telnet to an ip address (not a name).
I am not experienced with VPN issues and the vendor support person was not able to give any ideas why one could establish the link but not use the connection.
I have not much of an idea how to troubleshoot this issue or resolve it. Just to be sure something did not get messed up in the client software, I put the WRT54G2 back into the network in place of the DFL-210 and everything works fine. I put the DFL-210 back in, and the VPN is not usable. I have the Microsoft Network Monitor on the workstation, but do not really know what to look for.
Any ideas?