<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: WatchGuard Firebox VPN and Active Directory Integration</title>
	<atom:link href="http://blog.scottlowe.org/2005/12/06/watchguard-firebox-vpn-and-active-directory-integration/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.scottlowe.org/2005/12/06/watchguard-firebox-vpn-and-active-directory-integration/</link>
	<description>The weblog of an IT pro specializing in virtualization, storage, and servers</description>
	<pubDate>Fri, 05 Dec 2008 08:33:58 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: kryptonet</title>
		<link>http://blog.scottlowe.org/2005/12/06/watchguard-firebox-vpn-and-active-directory-integration/#comment-42306</link>
		<dc:creator>kryptonet</dc:creator>
		<pubDate>Fri, 07 Nov 2008 21:59:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=136#comment-42306</guid>
		<description>I just got a new client who has a Firebox Edge X Watch Guard . I was trying to configure it for remote management or administration. I guess if you just setup the VPN it will allow you you to manage it from the inside because you have a I.P assigned throught the VPN. Does that sound right?
Thanks</description>
		<content:encoded><![CDATA[<p>I just got a new client who has a Firebox Edge X Watch Guard . I was trying to configure it for remote management or administration. I guess if you just setup the VPN it will allow you you to manage it from the inside because you have a I.P assigned throught the VPN. Does that sound right?<br />
Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://blog.scottlowe.org/2005/12/06/watchguard-firebox-vpn-and-active-directory-integration/#comment-42273</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Wed, 05 Nov 2008 15:56:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=136#comment-42273</guid>
		<description>Do you have specific steps that you can post on setting up the inbound and outbound rule for the vpn traffic? thanks, chris.</description>
		<content:encoded><![CDATA[<p>Do you have specific steps that you can post on setting up the inbound and outbound rule for the vpn traffic? thanks, chris.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Damian</title>
		<link>http://blog.scottlowe.org/2005/12/06/watchguard-firebox-vpn-and-active-directory-integration/#comment-42265</link>
		<dc:creator>Damian</dc:creator>
		<pubDate>Tue, 04 Nov 2008 17:28:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=136#comment-42265</guid>
		<description>We have a customer with a Firebox running version 10.  They have vpn's setup and it works, the issue is that the remote user cannot access their local network when they have the VPN up.  I know most VPN solutions allow you to regulate this.  The user cannot even use her USB printer.  Everything else seems to work okay.  Any suggestions?</description>
		<content:encoded><![CDATA[<p>We have a customer with a Firebox running version 10.  They have vpn&#8217;s setup and it works, the issue is that the remote user cannot access their local network when they have the VPN up.  I know most VPN solutions allow you to regulate this.  The user cannot even use her USB printer.  Everything else seems to work okay.  Any suggestions?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://blog.scottlowe.org/2005/12/06/watchguard-firebox-vpn-and-active-directory-integration/#comment-42148</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Sun, 26 Oct 2008 17:42:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=136#comment-42148</guid>
		<description>from the traffic monitor I receive firewalld deny in pptp0 and deny out pptp0. I've created a rule but still missing something.</description>
		<content:encoded><![CDATA[<p>from the traffic monitor I receive firewalld deny in pptp0 and deny out pptp0. I&#8217;ve created a rule but still missing something.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://blog.scottlowe.org/2005/12/06/watchguard-firebox-vpn-and-active-directory-integration/#comment-42147</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Sun, 26 Oct 2008 17:37:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=136#comment-42147</guid>
		<description>I can connect using the above but I cannot talk to the network, cant pint the servers and the servers cant ping me. using a v500 with 7.5. Any ideas?</description>
		<content:encoded><![CDATA[<p>I can connect using the above but I cannot talk to the network, cant pint the servers and the servers cant ping me. using a v500 with 7.5. Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: elim</title>
		<link>http://blog.scottlowe.org/2005/12/06/watchguard-firebox-vpn-and-active-directory-integration/#comment-39959</link>
		<dc:creator>elim</dc:creator>
		<pubDate>Wed, 09 Jul 2008 06:19:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=136#comment-39959</guid>
		<description>Sorry, I believe the exact phrase was "It was not possible to verify the identity of the server."</description>
		<content:encoded><![CDATA[<p>Sorry, I believe the exact phrase was &#8220;It was not possible to verify the identity of the server.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: elim</title>
		<link>http://blog.scottlowe.org/2005/12/06/watchguard-firebox-vpn-and-active-directory-integration/#comment-39957</link>
		<dc:creator>elim</dc:creator>
		<pubDate>Wed, 09 Jul 2008 05:56:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=136#comment-39957</guid>
		<description>For some reason i am getting error 778 "can not verify the identity of the server" when connecting via VPN. Any ideas?</description>
		<content:encoded><![CDATA[<p>For some reason i am getting error 778 &#8220;can not verify the identity of the server&#8221; when connecting via VPN. Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Talrude</title>
		<link>http://blog.scottlowe.org/2005/12/06/watchguard-firebox-vpn-and-active-directory-integration/#comment-39630</link>
		<dc:creator>Talrude</dc:creator>
		<pubDate>Fri, 27 Jun 2008 14:52:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=136#comment-39630</guid>
		<description>Wanted to add.

I wanted to Add more.(I Have an 1000)
You must have the Management Software istalled.

Connect directly to the Trusted port using a cross over cable with a static IP or 192.168.253.xxx Not .1 

1 Unplug power from firebox.
2 Push and Hold reset button.
3 Plugin power to firebox.
4 Wait for red light and flashing triangle.
5.Use the Quick Setup Wizard to re-Configure the unit. Default IP 192.168.253.1
6.Default password will be shown during setup and you will get to change it.
7. Change your IP Rang accordingly if you change Trusted network Ip Settings. (DHCP is not enabled be default)
8.Use Policy Manager to configure firewall.
9.Expect reboots and 4 min down time for reboots. (I counted it on my 1000)

There is a Student manual floating around out there. Get it! it helps.

************************************************
DaveLChgo said: 
*** CAUTION ***
This will wipe out all of your settings on the firebox and set them to factory defaults.

1 Unplug power from firebox.
2 Push and Hold reset button.
3 Plugin power to firebox.
4 Wait for red light to come on and go off.
5 Release reset button.
6 Unplug power.
7 Plugin power.

Now Iâ€™m doing this from memory so steps 4 and 5 might beâ€¦.
4 Wait for red light to come on.
5 Release reset button and wait for red light to go off.

Hope this helps.</description>
		<content:encoded><![CDATA[<p>Wanted to add.</p>
<p>I wanted to Add more.(I Have an 1000)<br />
You must have the Management Software istalled.</p>
<p>Connect directly to the Trusted port using a cross over cable with a static IP or 192.168.253.xxx Not .1 </p>
<p>1 Unplug power from firebox.<br />
2 Push and Hold reset button.<br />
3 Plugin power to firebox.<br />
4 Wait for red light and flashing triangle.<br />
5.Use the Quick Setup Wizard to re-Configure the unit. Default IP 192.168.253.1<br />
6.Default password will be shown during setup and you will get to change it.<br />
7. Change your IP Rang accordingly if you change Trusted network Ip Settings. (DHCP is not enabled be default)<br />
8.Use Policy Manager to configure firewall.<br />
9.Expect reboots and 4 min down time for reboots. (I counted it on my 1000)</p>
<p>There is a Student manual floating around out there. Get it! it helps.</p>
<p>************************************************<br />
DaveLChgo said:<br />
*** CAUTION ***<br />
This will wipe out all of your settings on the firebox and set them to factory defaults.</p>
<p>1 Unplug power from firebox.<br />
2 Push and Hold reset button.<br />
3 Plugin power to firebox.<br />
4 Wait for red light to come on and go off.<br />
5 Release reset button.<br />
6 Unplug power.<br />
7 Plugin power.</p>
<p>Now Iâ€™m doing this from memory so steps 4 and 5 might beâ€¦.<br />
4 Wait for red light to come on.<br />
5 Release reset button and wait for red light to go off.</p>
<p>Hope this helps.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harry</title>
		<link>http://blog.scottlowe.org/2005/12/06/watchguard-firebox-vpn-and-active-directory-integration/#comment-39456</link>
		<dc:creator>Harry</dc:creator>
		<pubDate>Wed, 18 Jun 2008 13:53:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=136#comment-39456</guid>
		<description>Hi Scott

I was able to resolve the problem by taking out the NAS-IP-Address codition to the policy.

Authentication works well but I am having trouble acessing or even pinging anything including the DC that logged me on!  I think this may be down to m being a complete novice to this as opposed to anything else!

Thanks</description>
		<content:encoded><![CDATA[<p>Hi Scott</p>
<p>I was able to resolve the problem by taking out the NAS-IP-Address codition to the policy.</p>
<p>Authentication works well but I am having trouble acessing or even pinging anything including the DC that logged me on!  I think this may be down to m being a complete novice to this as opposed to anything else!</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: slowe</title>
		<link>http://blog.scottlowe.org/2005/12/06/watchguard-firebox-vpn-and-active-directory-integration/#comment-39455</link>
		<dc:creator>slowe</dc:creator>
		<pubDate>Wed, 18 Jun 2008 11:44:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.scottlowe.org/?p=136#comment-39455</guid>
		<description>Harry,

Looks like your Remote Access policy isn't configured for the right authentication method. With PPTP, you'll want to be sure that MS-CHAP and MS-CHAP v2 are enabled in the profile for the policy, and uncheck any other authentication types. I'm not sure what authentication type the Mobile VPN client uses.

Hope this helps!</description>
		<content:encoded><![CDATA[<p>Harry,</p>
<p>Looks like your Remote Access policy isn&#8217;t configured for the right authentication method. With PPTP, you&#8217;ll want to be sure that MS-CHAP and MS-CHAP v2 are enabled in the profile for the policy, and uncheck any other authentication types. I&#8217;m not sure what authentication type the Mobile VPN client uses.</p>
<p>Hope this helps!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
