Cisco VPN - Atrix 4G Q&A, Help & Troubleshooting

I have gone through the steps in the development post for [Module] tun.ko for stock 2.6.32.9 (for openvpn/vpnc/etc), http://forum.xda-developers.com/showthread.php?t=1013513. I am still unable to connect to my companies Cisco VPN router. I have rooted my Atrix and confirmed that tun.ko is running. Every time I try VPN Connections, it will not connect with no response after an attempt. I have also tried VPNC Widget which tells me "0:unexpected operatorError: root access missing! Waringin:'Advanced Routing' feature missing - VPN Conectivity might be lost after a while"
VPN access is all I am missing to get RDP working, at least I hope as I can use it on my home domain with my Windows server.
I am somewhat new to Android devices, other than tinkering with my old AT&T Tilt with Android 2.2 on NAND. Any help to resolve is much appreciated.

I am still unable to connect through my company's VPN. I have found out that we use a Cisco 3000 Concentrator. If anyone else has had luck with this model, I would like to hear about it.

I had a lot of issues getting mine to work too..
After hours of hunting and lots of logcats later I figured out VPNConnections is very picky about your busybox version. Something to do with the output of the ps command.
Check this thread (Mostly my last two posts on page 5): http://forum.xda-developers.com/showthread.php?p=13859822
Cliff Notes version:
I got it working with VPN Connections .6, Busybox 1.17.1, and the tun.ko posted by rozzco in that thread.
BB 1.17.1 is available from Stericsons BB installer under alternate versions.
If you need the APK for it or the VPN app lemme know and I'll post it.
FWIW, I never got VPNC widget to work. I had your same error,

I tried your suggestions, using the specific versions. Still no luck. Look at logcat, it appears to attempt to connect but ultimately finishes with "process stderr: no response from target".
scoob8000 do you know what VPN device through which you are connecting? I don't know if it is a issue with the Cisco VPN 3000 Concentrator we are using. There was a mention of retiring the device, but they do not know when or with what it will be replaced.

Did you try this one?
http://code.google.com/p/get-a-robot-vpnc/

That is the VPN Connections app scoob8000 has mentioned.

rgbaxter said:
I tried your suggestions, using the specific versions. Still no luck. Look at logcat, it appears to attempt to connect but ultimately finishes with "process stderr: no response from target".
scoob8000 do you know what VPN device through which you are connecting? I don't know if it is a issue with the Cisco VPN 3000 Concentrator we are using. There was a mention of retiring the device, but they do not know when or with what it will be replaced.
Click to expand...
Click to collapse
From memory I think it's juist a old 26xx series router.. (Don't quote me on this lol)
It almost sounds like your at least hitting the network. Can anyone try to see your attempted connections on the concentrator?

Working IPSEC VPN Client for Cisco VPN Concentrator
I know this is an old thread, but thought I would post an update anyway.
I recently started looking for a VPN client I could use with our Cisco VPM Concentrator, and ran across the one mentioned in this topic, VPN Connections. I installed it from the same link also posted by lhurtado earlier.
I think this may be a newer version than what was available at that time, though. Either way, I've got it working without any issues, and I'm able to VPN into my network, and use RDP without any issues.
I did try this on a non-rooted Asus Transformer TF-101, and it did not work. I only got a "Failed to Connect" message in VPN Connections. I'll have to see if I can find the logcat mentioned previously for any information on why it is failing, but I'm guessing the stock Kernel/ROM does not have tun.ko.
Here's the specs on what I've got:
Acer Iconia A500 (rooted), custom ROM (Taboonay 2.2) and Kernel (HoneyVillain 3.4)
BusyBox 1.19.2
VPN Connections 0.99
2X Client
Cisco VPN Concentrator 3005
Hope this helps someone else who is looking for a VPN client that works with the Cisco VPN Concentrators.

As long as your kernel support tap/tun configs, you can use the VPN Widget. I use it with our cisco equipment at the hospital I work for. It works like a champ! You will need to get your information to get it to work properly but its the only one I have found so far to work out of the box (with the proper kernel).
As for the OP, being this is an old thread I sure he gave up- however if he was trying to RDP using the hostname, that is not possible (without hackery). Always use your IP until we have CIFS support. NetBIOS name are not resolved on a linux platform without it. I use RDP/VNC with my VPN over 4G almost daily.

Beating a dead horse
OK...First off, thank you to everyone for looking into this.
I'm a Network Engineer that has the pleasure of supporting a Cisco 3030 VPN Concentrator from the stone age. For those with Iphones we just give the Facutly/Staff the IPSEC/PSK and use the native VPN client and all is well.
The Androids (which I'm a die hard fan of) don't work....UNTIL version 4.0.x arrived.
There is an app called VPNCILLA (or for those rooted VPN WIDGET) that works with the old style concentrators. VPNCILLA has a 10 day trial, but afterward is a $4.95 one time fee.
They both work flawlessly and are easily setup.
Just wanted to pass the word in case the one person in the world out there is still trying to get it to work (like me).
Thanks
Shayne

Related

[Q] Anyone get VPN Connections to work?

Hey guys,
I have been keeping my eyes out for the tun.ko module to come out in one of the kernels, and it finally did in the 1.76 GHz kernel. I had to reinstall VPN connections after flashing the kernel, and then VPN connections would tell me that my VPN was connected properly. However, I can't get data to pass through the VPN. No pings to the remote end, no RDP, nothing.
Anybody else get this working?
Thanks,
Seth
I thought I set up my VPN wrong >_> Well that explains it! Thanks! Same issue. I have however been able to see my phone in my router, though I can't do anything with it there in or out.
This sounds like the same issue I was having with openvpn (I assume that's what you're referring to since you're talking about the tun module). I'm running Das BAMF 1.3.2, and tun is already built into the kernel. I'm having the same problem. The VPN connects, no errors at all, even ran it in the terminal so I could see all of OpenVPN's connection output. But data is not routed through the tunnel. WhatIsMyIP still reports my Verizon IP address.
Now, on two occasions I have had success. I was able to connect and disconnect my VPN all I wanted and everything worked. However this only lasted for the current phone 'life cycle', ie it failed again after the next reboot. I can't find a pattern or anything, it seems that it will randomly work after a reboot, but not that often... 1 out of 10 maybe? I didn't waste my time trying to nail down a ghost.
I think I solved the OpenVPN problem. There's an option in OpenVPN settings called 'Fix HTC Routes'. If you check it, you can get the link to view the issue tracker. Essentially it deletes a few routing tables after OpenVPN starts up. For some reason, it doesn't seem to work on the Thunderbolt. Perhaps that option is using a deprecated script command (ip ru del route)? Whatever the reason, the fix is simple. After connecting to OpenVPN, open a terminal and issue the following commands:
Code:
ip ru del table gprs
ip ru del table wifi
Ignore any errors you might get if the routing table doesn't exist. I don't think you need SU, and you can use GScript Lite to make the process easier on you.
I'll give this a shot with VPN Connections when I get a chance and report back. If anybody else has any success, please post here.
I have had better success, but it's not right yet for me. I am able to get some data to flow using RDP, Telnet, etc., but nothing actually works completely right.
When telnetting into routers, I am not able to actually authenticate. however, I CAN finally see the prompts.
When using RDP, it doesn't time out any more, but I don't get any video data back to my phone's screen. No login page, etc.
Those two commands also seem to time out eventually. I need to reenter them to get the data flowing again, it seems.
Anybody else have better results?
Seth
Well, without knowing which VPN you're using, I can't say. But it does seem to work with openvpn and the OpenVPN Settings market app (I have my own install of openvpn, so I don't use the related OpenVPN Installer app).
The routing tables gprs/wifi are automatically recreated when those connections are re-established. Meaning, if you are on VPN via wifi, and wifi disconnects/reconnects, then the wifi routing table is recreated. The same goes for gprs if you lose connection and it is reestablished. I don't know what the system might try to do using the built in VPN connections.
Sorry about that, the lack of info wasn't very helpful.
I'm trying to connect to my Cisco VPN. We are using group authentication as well as user authentication. The outside device is a 2811 router, and if there are any other specifics that might help, I'd be happy to provide it.
Thanks,
Seth

Barnacle Wifi Tether - PPTP

I'm currently using the new 2.3.4 leaked moto rom from Kenneth Penn's post. I also use Barnacle quite regularly for tethering. When attempting to connect directly from the phone to our PPTP VPN, I successfully connect, but a bunch of protocols are rejected and the connection is pretty much useless.
However, when I tether and connect to the VPN via wifi, I'm not even able to connect. Is this a known issue with Barnacle/Android or the Atrix specifically? Are there other apps that people have found that circumvent these issues?
I've seen some posts that explain you can modify the ppp0 routing tables and some people are using the Android Tether app. But before I dig too deep into those ventures, I'm curious if someone else has already found a decent solution.
Thanks!!
I'm having the same issue with the wired tether app. It worked just fine on froyo but now it doesn't on GB. My computer recognizes the connection to the device but my phone doesn't seem to recognize my computer. Therefore I get no connection between my phone and the computer for the usb tethering to occur.
The issue I posted originally is specific to a PPTP VPN connection. Are you connecting to a VPN? If not, you may be better off creating a new topic as your issue may be replied to more quickly.
shaunole said:
The issue I posted originally is specific to a PPTP VPN connection. Are you connecting to a VPN? If not, you may be better off creating a new topic as your issue may be replied to more quickly.
Click to expand...
Click to collapse
Oh I see. Thanks

[Q] Cisco VPN in new touchwiz

Hi
I have updated the Tab to Touchwiz today.
I read that Cisco VPN was meant to be available - and yet I can't see it.
Am I missing something?
Do I need to download from somewhere?
I tried AnyConnect ...is that the one?
It does not seem to work with our VPN Setup
M
I'm with you. I don't see a Cisco VPN app, and the native VPN seems unchanged.
I downloaded the one from the market and it worked. It is listed as Anyconnect. Tab 10.1 is not listed but it works.
Does it only work with certificate mode? Our VPN is set up with group password
Our network at work uses Group Secret IPSEC Cisco VPN with RSA Secure ID cards. I'm currently lead tech on the IPAD2 project to get all our executives using IPAD2's. We got them working without the anyconnect software using the built in Cisco VPN on the IPAD2. It connects faster than anything I've used before. Flick VPN on at the switch and it's there as soon as you put in the password. Very slick.
I was hoping for something similar on the Galaxy Tab just so I know it works. I'll download the update over the weekend and give it a shot early next week.
Once we get that working, I'll just have to get Citrix connectivity going and I'll be laughing
Did you look under Setting>Wireless and networks>VPN
cisco
Hi
yes I checked under the VPN settings - but they do not seemed changed since the update. Nothing seem to match the credential I need to input like a group password authentication
i can confirm also that its not there :/
Dang. I was really hoping TW had this as advertised. I can't connect to a lot of university services from home without AnyConnect. Part of the reason I picked up the SGT10.1 was to read PDFs I downloaded from EBSCO for my research.
Cisco AnyConnect for Samsung devices is the VPN that was referenced as being supported after the update. It's an SSL VPN client. If you are using IPSEC then I think you can use the native Android VPN.
From my understanding, SSL needed deeper access to the OS in order to function and that's why the TouchWiz update is fixing it... because somehow TouchWiz has access to those areas of the OS that were locked. It already worked if you had root... same deal I guess. Deeper access.
Please keep in mind the following:
To use the Cisco AnyConnect, you will need to download the app from the market. Once you do this, you must make sure your ASA has the AnyConnect Mobile license on it. If it does not, you will not be able to use AnyConnect on your Tablet.
I have it working on mine, pre-TW and will test it after I install TW.
~Scott~ said:
Cisco AnyConnect for Samsung devices is the VPN that was referenced as being supported after the update. It's an SSL VPN client. If you are using IPSEC then I think you can use the native Android VPN.
From my understanding, SSL needed deeper access to the OS in order to function and that's why the TouchWiz update is fixing it... because somehow TouchWiz has access to those areas of the OS that were locked. It already worked if you had root... same deal I guess. Deeper access.
Click to expand...
Click to collapse
And I had it from the market from before and can tell you that after the TW update
it's able to ping our VPN server properly and properly prompt for login details. Now to get IT to enable the license for access....
Please use the Q&A Forum for questions Thanks
Moving to Q&A

[Q] VPN Connection

does anyone know how to make a working vpn connection with the touchpad?
i couldnt get one.
i have win 7
tried vnc too,
did anyone get an working vpn connection?
works for me. my proxy server uses pptp so i download pptp plugin from market and all's good.
I think if you have an ASA you can try the built in anayconnect client provided you have a mobile license activated on the Cisco otherwise use IPSEC on your gateway device. I never played with pptp on the touchpad before.
I saw this but what can I do by joining a VPN?
is there someone who can write up an a quick tutorial for the ones that dont know how to do it.
that would be apriated.
i want to control windows 7 remotly with it
jlove said:
is there someone who can write up an a quick tutorial for the ones that dont know how to do it.
that would be apriated.
i want to control windows 7 remotely with it
Click to expand...
Click to collapse
Bump... Same question. Out of all the people who have recently bought the touchpad, there has to be someone out there that can give a short explanation on how to use the native VPN capability to connect to a Windows system. I have searched all over the net for the answer and have come across many unanswered forum threads.
Below are instructions I used on Win 7 to create an incoming VPN connection to make it available to be connected to.
pcworld. com/article/210562/how_to_set_up_vpn_in_windows_7. html (take the two spaces out of the link, cant post links yet since Im a NOOB!!)
Step by Step: Building a VPN (Incoming)
Step 1 Click the Start button, and, in the search bar, type Network and Sharing.
Step 2 Click Change Adapter Settings in the left-hand menu.
Step 3 Click File, and then New Incoming Connection.
Step 4 Select the users you'd like to give access to and click Next.
Step 5 Click Through the Internet and select Next.
Step 6 Select the Internet Protocol you'd like to use. (The default TCP/IPv4--the line highlighted in the screenshot below--will work fine.)
Click to expand...
Click to collapse
On the touchpad when using the Cisco AnyConnect VPN connection type and enter the host name, I get this error "Connection attempt has failed due to configuration issue with server"
When using the VPNC connection type, and enter the host name and password, I am prompted to fill in several fields that I dont know what to enter.
I use my laptop to log into my Win7 desktop all the time easily via the Remote Desktop Connection app. Hopefully there is something similar coming to the touchpad.
I have an openvpn subscription with strongvpn - this works well for the technically deficient peeps like myself to have an added layer of security when using windows machines in a public wifi area (i.e. hotels)
I asked strongvpn about any support for webos, and they were not sure of any workarounds to date. Any new ideas on this? I am using an open vpn (as opposed to their ptpp). They said that on rooted android devices open vpn will work following one of their tutorials.
If you are technically sound only then you will be able to set up a VPN and solve these kind of issues yourself..Average PC users like me will avoid indulging in these configurations as they are too complicated for us
Why not try an already established, reliable VPN service provider for touchpad??
you can definitely Google them and can choose amongst the choices you get..That would be far easier believe me
[Q] VPN support
I was wondering if anyone has tried vpn support on the touchpad? I am looking at using it overseas as a way to watch amazon VOD while I travel.
Edit: Found out I needed to download a free app from app catalog for PTP support. Works now when I connect to my school network. Also I found out that playon services work too on touchpad so I might try that for netflix.

[Q] stock vpn connection bug?

Has anyone successfully made a VPN connection with their rezound? I am trying to connect to a VPN connection known to be working and it says its connected, but I am unable to get internet traffic to go through. (I.e. when I am connected to the VPN, Any app that uses data is unable to find a connection to the internet.) I know it's not on the VPN server side because I am able to connect and get data with another phone.
Any ideas? Thanks in advance!!!
BUMP. no one has tried or can try out VPN for me?
Bump. Not to sound whiney, and but I find it sad that my post can be up for so long without even a single reply. There is a ton of good info in these forums and I'm patiently waiting for s-off just like the average member, but the issue of the vpn hasn't even been looked into by anyone else? I guess my question to any mods would be "what do I have to do to get some attention to an issue I'm having? "
nlitend1 said:
Bump. Not to sound whiney, and but I find it sad that my post can be up for so long without even a single reply. There is a ton of good info in these forums and I'm patiently waiting for s-off just like the average member, but the issue of the vpn hasn't even been looked into by anyone else? I guess my question to any mods would be "what do I have to do to get some attention to an issue I'm having? "
Click to expand...
Click to collapse
you are so active on the forums, I can't believe your question hasn't been answered yet...
sorry, don't have anything to hide, so don't use vpn.
Why would you need to use a VPN on a phone lol? If you're using free wireless tethering I really doubt that it'll mask it for you. Verizon would be like zomg in Russia wireless tethering steals you!
zetsumeikuro said:
Why would you need to use a VPN on a phone lol? If you're using free wireless tethering I really doubt that it'll mask it for you. Verizon would be like zomg in Russia wireless tethering steals you!
Click to expand...
Click to collapse
First of all, thank you both so much for the replies.
I'm not sure that I follow that last sentence, but but to answer the first question.... I want to use the vpn to encrypt my data. I don't use tethering that often, so I don't want to pay for the hotspot fee..... And I don't want to risk Verizon messing with or possibly closing my account or charging me a fee.... So I'd like to run my tethering data though my personal vpn.
I am able to use the stock VPN to connect to my networks. I have about 25 different VPN connections and my VPN connections are the L2TP/IPSEC PSK type. I can mount shares, as well as using remote control programs.
I would look at the logs of the device that you are trying to connect to, maybe that might give you some hints as to the issue. One thing I did find it that my device does not see the DNS server for some reason (even though it is specified), so therefore I have to use IP addresses to connect to anything.
This probably doesn't help you too much, but I did want to reply to let you know that I have the stock VPN working.
Good luck!
Flipdog said:
I am able to use the stock VPN to connect to my networks. I have about 25 different VPN connections and my VPN connections are the L2TP/IPSEC PSK type. I can mount shares, as well as using remote control programs.
I would look at the logs of the device that you are trying to connect to, maybe that might give you some hints as to the issue. One thing I did find it that my device does not see the DNS server for some reason (even though it is specified), so therefore I have to use IP addresses to connect to anything.
This probably doesn't help you too much, but I did want to reply to let you know that I have the stock VPN working.
Good luck!
Click to expand...
Click to collapse
Wow! Thank you! It's so good to know that someone has a version of the stock vpn working. Mine are the PPTP type. I wonder if this phone has issues with that setup. Could you possibly test a PPTP connection?
Sorry, I'd love to be able to help you test but all of the device's that I connect to use only the L2TP/IPSEC PSK VPN. Good luck solving your problem and have a happy holiday!
Well I just wanted to update this thread. It looks like PPTP VPN is broken in stock android and therefore it's not specific to the rezound. It looks like it can be fixed by developers (and from what I've read) it's pretty common for it to be fixed in non-stock roms. The lack of internet/browsing is caused by a bug in the MPPE (Microsoft Point-to-Point Encryption) implementation. The following article explains it pretty well:
http://www.securitykiss.com/resources/articles/android_vpn_bug/index.php
This thread discusses some workarounds that were a bit over my head:
http://code.google.com/p/android/issues/detail?id=4706
IPsec connections are not affected....and it looks like MPPE connections have been fixed in ICS. If any developers could take a look at the above thread and explain in more basic english how to "fix" the connections that would be greatly appreciated. If not, i guess i'll have to wait and hope ICS fixes it.
nlitend1 said:
First of all, thank you both so much for the replies.
I'm not sure that I follow that last sentence, but but to answer the first question.... I want to use the vpn to encrypt my data. I don't use tethering that often, so I don't want to pay for the hotspot fee..... And I don't want to risk Verizon messing with or possibly closing my account or charging me a fee.... So I'd like to run my tethering data though my personal vpn.
Click to expand...
Click to collapse
I was just joking around w/ the last sentence. Hope you figured it out!
I have been able to use Raptor VPN on my Rezound. Just Google it, it's free
Sent using my HTC Rezound
fjl307 said:
I have been able to use Raptor VPN on my Rezound. Just Google it, it's free
Sent using my HTC Rezound
Click to expand...
Click to collapse
Very interesting! Thank you! Have you used the PPTP or L2TP version? Was this just to setup the vpn server and then you connect to it with the stock vpn client?
I'm using the L2TP version
Sent using my HTC Rezound
I'm having the same issues as you are. I know I'm replying a month late, but I didn't get my phone setup until almost Dec 30th and have been fighting my corp VPN ever since.
Once in a while I can get ping to work from Better Android Terminal, but that is always short lived and I can never get anything to work from other apps.
I'm glad you found the issue. I took a look at logcat and it is definitely a kernel issue. When the connection starts, I get the message "couldn't set tty to ppp discipline".

Categories

Resources