Sitemap

Amicuk Programming Answers

Minimal open ports for groupwise to use by vpn

-0001-11-30   Views:0

Advertisement

Hi, What are the minimal ports that need to be open to use groupwise online remotely (by use of vpn) ? We use the novell client 4.91sp4 and groupwise 7.0.3hp on windows xp sp2. - dns resolving for both udp and tcp are authorized and an user authentic

Hi,
What are the minimal ports that need to be open to use groupwise online
remotely (by use of vpn) ?
We use the novell client 4.91sp4 and groupwise 7.0.3hp on windows xp sp2.
- dns resolving for both udp and tcp are authorized and an user
authenticates to the FQDN like mail.domain.com
- port 1677 is open, but then it takes 10 minutes, before you can do
anything.
- after monitoring with an account with full rights to every protocol and
port, we see NCP being used, so after having this authorized, it is already
much better.
Still have to wait 1 minute.
Could it have something to do with the primary or dns suffix entries?
We do not use primary or dns suffix entries, so these are empty. The
connection suffix is being set by the dhcpserver. So this name differs for
each person at home.
What we see in the capture is that the groupwise server name is being
accessed by its hostname, like <servername>.<connection suffix>
An enduser can not resolve these server names remotely, unless the FQDN is
being used.
We do not wish to change primary of dns suffix entries, and prefer changes
on the serverside instead of clientside, but is this possible in this
situation?
Anyone has experience with this ?
Also some icmp request are being made. Is it required to allow icmp to the
groupwise server?
regards,
Marcel
by the way : if we remove the novell client, then only port 53, 1677 are ok
and performance is ok (within 10 seconds groupwise client opens)

The replay answer
Advertisement
Hi Craig,
Thanks for your answer, but how do you explain that adding ncp (524) over
tcp is decreasing the timeout?
In the Groupwise client options the archive and views are all located on a
netware server using the UNC syntax.
I do not see the public ip in the traces. In fact when tracing with a client
with restricted rights, I do not see anything at all. I need to trace with
all rights, to see what possibly could be used as protocol. Then I noticed
ncp (524) being accessed. So after that I authorized that and it was like a
dream came true.
However.... like I said. only with the novell client (4.91sp4) being used.
without novell client it just works fine. In vista with both novell client
and vpn client the slow gwclient also does not appear.
regards,
Marcel
"Craig Johnson" <[email protected]> wrote in message
news:[email protected]..
> GroupWise client only needs port 1677. TCP for GW Client, UDP for GW
> Notify.
>
> I often open filter exceptions to the POA for tcp port 1677 for people
> to connect remotely to the client without VPN. That's all they need.
>
> If you are trying to connect on that port, and the traffic is taking a
> long time, you might be seeing some sort of redirection attempt trying
> to take you to a public address instead of using the private IP of the
> POA.
>
> Craig Johnson
> Novell Support Connection SysOp
> *** For a current patch list, tips, handy files and books on
> BorderManager, go to http://www.craigjconsulting.com ***
>
>

Go to See the other 4 answers

Minimal open ports for groupwise to use by vpn

Category:DefaultRelease time:-0001-11-30Views:130

Hi, What are the minimal ports that need to be open to use groupwise online remotely (by use of vpn) ? We use the novell client 4.91sp4 and groupwise 7.0.3hp on windows xp sp2. - dns resolving for both udp and tcp are authorized and an user authentic[More]

Port Forwarding for Cisco ASA 5505 VPN

Category:DefaultRelease time:2015-10-11Views:130

This is the Network Linksys E2500 ---> Cisco ASA 5505 ---> Server I beleive I need to forward some ports to the asa to use the IPsec VPN I just setup. I had the SSL VPN working but only needed to forward 443 for that....I assume that IPsec tunnel is[More]

SA520: problem when trying to access HTTPS over custom port in a site-to-site vpn

Category:DefaultRelease time:-0001-11-30Views:130

We've set up a site-to-site VPN between our SA520 and our SmoothWall running at our data center. The tunnel is always connected, so that part runs fine What works fine: - Client 192.168.11.1 is able to start an RDP session (on it's default port 3389)[More]

How to manage port 80 hosts via gateway - gateway vpn (rv220w)

Category:DefaultRelease time:-0001-11-30Views:130

I replace our aging rv082 routers with wireless rv220w routers. The gateway to gateway vpn works great, however I am no longer able to manage our print servers port 80 management page. I can ping any host with success, and I can manage hosts that hav[More]

Port Forwarding for OS X Server VPN on BT Home Hub...

Category:DefaultRelease time:-0001-11-30Views:130

We have BT Infinity using a BT Home Hub 5 and I have recently installed OS X Server to create my own VPN. However, I cannot seem to get the hub to open the ports I desire using the port forwarding tool - I have tried everything I can think of includi[More]

What TCP/UDP ports need to be open for VPN Client version 4.8?

Category:DefaultRelease time:-0001-11-30Views:130

What TCP/UDP ports need to be open for Cisco VPN Client version 4.8 to work? Thanks,Normally, you need the following ports and protocol : UDP 500 UDP 4500 ESP In case, you are using IPSec over TCP you have to open, TCP port 10000 or any other port yo[More]

Lion Server: VPN external ports to open on firewall

Category:DefaultRelease time:2015-10-11Views:130

With Leopard/SnowLeopard Server, opening ports back to my server @ 500, 1701 and 4500 were sufficient for L2TP VPN.  I had no issues trying to connect to my VPN until I upgraded to Lion (which I'm quickly learning was a big mistake). Now it appears t[More]

Port Forwarding for L2TP/IPSec VPN Behind Verizon Actiontec MI424WR-GEN2 Rev. E v20.21.0.2

Category:DefaultRelease time:2015-10-11Views:130

I've got a NAS setup with various services running on custom ports to help minimize exposure (especially to script kiddies). I've tested everything both internally and externally to confirm they all work, and even had someone at a remote location con[More]

Unable to configure voice ports on cisco2811

Category:DefaultRelease time:-0001-11-30Views:130

I have configured the Voice Gateway and calls are working internally.   I recently installed a WIC-1B-S/T-V3 card to prepare to getting outside line access. To try a set of Dial-Peer and put the port command , but I have been rejected.  I've confirme[More]

Ports are being block (not responding)

Category:DefaultRelease time:-0001-11-30Views:130

Ports are being block (not responding), port forwarding is configured on the router and firewall is turned off on the server (osx 10.8).  Am I missing anything? Server has a static IP which I forwarded to ports to I'm setting up VPN server and need p[More]

Leopard VPN open ports

Category:DefaultRelease time:-0001-11-30Views:130

Hello, I use standard Leopard VPN for connecting laptop to my office network. Web and Exchange mail work fine but I cannot get connection to Perforce server (port 1666). Changing firewall settings didn't help. My Windows environment uses same VPN and[More]

Hot
I have just setup my Apple ID using the iCloud. iCloud requested that I setup my Apple ID with my email address. My email address is not one of .me.com or mac.com. How do I use my Apple ID to work with iChat? Thanks George.Humm, That looks like a gen [More]
Dear all, Sorry for my post which is very long but i will try to give you all information. I am currently developing a full stack ADF application (with BC4J to access the database) using Jdev 11g last release (5407) When working in JDev, my applicati [More]
My iPad air will not automatically connect to wi fi unless I turn off and then back on again, any suggestions as to why?Hello Juanita289 Check out the article below to troubleshoot issues with connecting to WI-Fi. You may want to reset the Network Se [More]
Why can't I actually put widgets on the desktop and have stay on the desktop; not float on top of all my programs so I can't see what I am doing? I know there are a few widgets that claim to do this, but they don't! (Dashit) Here is the main problem [More]
My phone do not hold a charge unless I turn off the radio on the phone or remove the sim card. Prior to this it while charging a black plug used to replace the lightening bolt on the battery symbol. However, while the radio is off the plug do not app [More]
"There is not enough free space on your Aperture Library Volume to import the selected items. It is estimated that you need at least an additional 326895 MB of space." To import a 19gb iPhoto library? And this is on a drive with 307GB free! So.. [More]
We have attempted to download AFP enumerable times on a Dell Inspiron with Win Vista 32 bit. We have followed so many suggested methods to download and trouble shoot that I cannot remember... 15, 20 or more.... And yes, security/antivirus were always [More]
Can anyone tell me where I can find a list of all "illegal" non-alphanumerci characters that I am not to use in any of file names. It was brought to my attention that bullets can really mess my system up. Some of my font folders have TM's (trade [More]
Hi, I am using Oracle 10.2.0.3 enterprise edition Since we put in two materialised views and 2 jobs to refresh the materialised views every 5 minutes the database has been creating a lot of redo. Around about 2GIG every hour. We have tried to recreat [More]
hi everyone i am working with Interaction centre in my project i am stucked in Employee Interaction centre concept. Really i dont have any idea about this. it will be great help if anybody provide such information . regards samHi Sampath, Surf throug [More]