- LANCOM Advanced VPN Client as of version 3.x (download latest version)
- LCOS as of version 9 (download latest version)
- LANtools as of version 9 (download latest version)
Step 2:
Check the order or the network adapters as found by your operating system.
Windows Vista, Windows 7 & Windows 8:
2.1) Open the Network and Sharing Center via Control Panel → Network and Sharing Center.
2.2) Click on the option Change adapter settings.
2.3) Open you the menu Advanced → Advanced settings.
2.4) Re-order your network adapters as follows:
- First position: Physical network adapter
- Middle position: WLAN network adapters, Firewire, UMTS, etc.
- Final position: Virtual network adapter LANCOM Advanced VPN Client
These changes come into effect after the computer's operating system is restarted.
Step 3:
Add the remote local IP network to the VPN configuration of the LANCOM Advanced VPN Client.
3.1) In the LANCOM Advanced VPN Client, open the menu Configuration → Profiles.
3.2) Select the profile which you wish to edit and click on the Edit button.
3.3) Navigate to the menu Split tunneling.
3.4) Enter the local IP network(s) which are to be accessed via the VPN tunnel.
If you do not specify an IP network here, your Internet traffic will also be directed via the VPN tunnel!
Step 4:
Check if you require an IPSec pass-through, or whether this has been set up already.
By default an IPSec connection uses the port 500 UDP, the IP protocol ESP (50), or port 4500 UDP. The VPN tunnel may occasionally be directed via routers which do not support IPSec pass-through. In these cases, the IPSec packets may be handled incorrectly, or they may even be dropped.
A result of this is that, even though the tunnel has been established, it cannot be used for communications. This problem can be avoided by activating port forwarding for the UDP ports 500 and 4500 on the client-side of the router.
For a description on how to set up port forwarding on a LANCOM router, see this Knowledge Base article.
Step 5:
If you cannot use IPSec pass-through, you have the option of setting up a VPN connection based on IPSec over HTTPS. All you have to do in this case is to open the HTTPS port 443.
With IPSec over HTTPS, an attempt is first made to transfer data using standard IPSec. If the connection cannot be established (e.g. because IKE port 500 is blocked), then an attempt is then automatically made to establish a connection that encapsulates the IPSec VPN in an additional SSL header (port 443, like HTTPS).
For a guide on setting up a VPN with IPSec over HTTPS, see this Knowledge Base document.
Step 6:
If you are using a computer or a notebook from HP (Hewlett Packard), where the HP Velocity software is installed, deinstalling HP Velocity fixes the issue.
Step 9 – other possible error sources:
In most cases security software is installed on the system with the LANCOM Advanced VPN Client to protect it from unauthorized access.
The system may be running a virus scanner, a firewall, and/or a Spy Doctor. These programs often integrate deeply into the system, and thus can cause software conflicts with the Advanced VPN Client. A potential effect of this is that the LANCOM Advanced VPN Client may not be able to communicate over an active VPN tunnel.
In most cases the connection problems cannot be solved simply by deactivating the security program. To find out whether the programs being used are affecting communications, they must first be uninstalled and the operating system then restarted. LANCOM Systems has experienced problems of this nature with the programs listed below. The only way of assisting our customers was for them to uninstall this anti-virus or firewall software:
- Norton Internet Security
- Panda Antivirus
- Trendmicro
- Kaspersky
Generally the security software can be reinstalled after the Advanced VPN Client is installled correctly without negative effects to the Advanced VPN Client.