Dec 21

Virtual Private Network Consortium, better known as VPNC, tests interoperability of various VPN technologies from different vendors. During year 2011 Stonesoft Firewall/VPN has received two new IPsec interoperability logos. These are logos for IKEv2 and IPv6.

VPNC IKEv2 Basic Interop LogoVPNC IPv6 Interop Logo

Testing conducted by VPNC proves that vendor has implemented standards defined protocols in a way that can be used in real life where interoperability between different vendor’s implementation is frequently needed.

written by juhalu - 361 views \\ tags:

Jul 06

Have a shiny new iPad/iPhone/iOS device and wonder how to access all your precious corporate data? Are you a sysadmin who needs to manage the corporate LAN from everywhere? Do you need some intranet-only web pages you don’t want to publish for security reasons?

This simple tutorial will explain how to create a VPN between your StoneGate and your iDevices.

Thanks to Marco Rottigni who gave me precious hints to make all things work!

This is my very first post to the Stoneblog, if you want feel free to give me feedbacks and suggestions! Roberto

written by roberto.toniolo - 2,168 views \\ tags: , , , ,

Jul 01

StoneGate 5.3 – Other Enhancements

Feature Previews, Firewall Engine, SMC, VPN -
1 Star2 Stars3 Stars4 Stars5 Stars (4 votes, average: 5.00 out of 5)
Loading ... Loading ...
2 Comments »
SMC 5.3.1 is now publicly available and FW/VPN 5.3.0 is also published as controlled shipment. I wanted to conclude the StoneGate 5.3 feature previews by listing the other significant enhancements that are introduced in version 5.3. More details can be found from SMC and FW Release Notes and product manuals. StoneGate logo

Continue reading »

written by Tero Jantunen - 1,146 views \\ tags: , , , , , , , , ,

Jun 27

StoneGate 5.3 – VPN enhancements

Feature Previews, SMC, VPN -
1 Star2 Stars3 Stars4 Stars5 Stars (3 votes, average: 5.00 out of 5)
Loading ... Loading ...
No Comments »
Internet Key Exchange (IKE or IKEv2) is the protocol used to set up a security association (SA) in the IPsec protocol suite. StoneGate FW/VPN 5.3 introduces the support for IKEv2 (in addition to IKEv1) in VPN configuration. IKEv2 includes the support for IKEv2 Mobility and Multihoming Protocol (MOBIKE). MOBIKE enables transparent recovery for VPN clients if the IP address of the VPN client or the IP address of the gateway to which the VPN client is connected changes in the middle of an open VPN connection. IKEv2 support

Continue reading »

written by Tero Jantunen - 974 views \\ tags: , , , , , ,

Jun 23

StoneGate FW/VPN and SMC 5.3 provide a couple of nice enhancements related to StoneGate’s unique Multi-Link feature.

Continue reading »

written by Tero Jantunen - 1,048 views \\ tags: , , , , , , , ,

Jun 01

StoneGate 5.3 – VPN SA Monitoring

Feature Previews, SMC, VPN -
1 Star2 Stars3 Stars4 Stars5 Stars (6 votes, average: 5.00 out of 5)
Loading ... Loading ...
No Comments »
This other brand new session monitoring view lists all VPN Security Associations that have been currently negotiated in the firewall. The view lets the administrator e.g. to filter VPN SAs, create statistics, aggregate the table by any field and save VPN SA monitoring snapshots for further analysis. VPN SA monitoring icon

Continue reading »

written by Tero Jantunen - 826 views \\ tags: , , , , , , , ,

Oct 29

StoneGate FW/VPN IPsec Certificate Interoperability

Firewall Engine, VPN -
1 Star2 Stars3 Stars4 Stars5 Stars (4 votes, average: 4.25 out of 5)
Loading ... Loading ...
No Comments »

VPN Consortium (VPNC) recently started to test IPsec VPN product interoperability against a new criteria. The test is about VPN interoperability when tunnel setup is authenticated using certificates from a common trusted certificate authority.

In October 2010 VPNC update first results were announced. StoneGate Firewall/VPN was among the first five vendors to pass this test and receive right to use this new logo.

VPNC Certificate Interop Certified

As a VPN technology this is nothing new for StoneGate FW’s IPsec VPN. It has supported certificate based VPN authentication starting from the very first version.

written by juhalu - 1,037 views \\ tags:

Jun 21

In StoneGate Management Center 5.2 the VPN troubleshooting tools have improved significantly. There are a lot of new drill-in actions available in System Status view. You can for example right-click any VPN tunnel in the VPN diagrams and drill-in to logs that flow through the selected tunnel. You can also right-click individual Gateways or Endpoints (from the Info panel) and drill-in to the related logs.

Drill in to VPN log data

written by Tero Jantunen - 1,507 views \\ tags: , , , , , , , , ,

Mar 02

StoneGate 5.0: VPN diagrams

Feature Previews, SMC, VPN -
1 Star2 Stars3 Stars4 Stars5 Stars (3 votes, average: 4.33 out of 5)
Loading ... Loading ...
No Comments »

StoneGate Management Center 5.0 introduces a new network diagram type: VPN diagrams. That gives you two interesting opportunities:

  • Visualize the VPN topologies
  • Monitor the status of VPN tunnels

VPN Diagram

VPN diagrams are autogenerated in the System Status view. You’ll see the VPN topology and the status of the VPN tunnels with a single click. You can also select individual Gateways from the Status tree. Then system draws you a diagram that includes all the tunnels of all your VPNs in which the selected gateway is used. And if these features don’t still satisfy your needs, you can of course create your custom VPN network diagrams that show you exactly the information you need. Network diagrams are btw a convenient tool also for documenting your environment.

written by Tero Jantunen - 3,698 views \\ tags: , , , ,

Jan 23

VPN: where is my fragmentation needed ICMP message?

Hints and Tips, VPN -
1 Star2 Stars3 Stars4 Stars5 Stars (3 votes, average: 3.67 out of 5)
Loading ... Loading ...
1 Comment »

If there is a link with a smaller MTU somewhere between the VPN gateways, the router connected to the link will send ICMP fragmentation needed message (type 3, code 4) as a response to ESP packets that have DF bit set and that are bigger than the MTU.

However, only the MTU information is stored on the firewall at that time but no ICMP error message is sent to the endpoint of the original connection.

When the host in the internal network sends the following packet, that’s when the firewall handling the connection will reply with the ICMP error message.

written by RoarinPenguin - 3,846 views \\ tags: , , ,