<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
	<title>Comments for StoneBlog.stonesoft.com</title>
	
	<link>http://stoneblog.stonesoft.com</link>
	<description>Share knowledge about StoneGate</description>
	<lastBuildDate>Wed, 08 Feb 2012 09:11:13 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/CommentsForStoneblog" /><feedburner:info uri="commentsforstoneblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Comment on A Very Quick Guide for Configuring StoneGate for iOS VPN by rence.suarez</title>
		<link>http://feedproxy.google.com/~r/CommentsForStoneblog/~3/PWO9L2jAIAs/</link>
		<dc:creator>rence.suarez</dc:creator>
		<pubDate>Wed, 08 Feb 2012 09:11:13 +0000</pubDate>
		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3410#comment-498</guid>
		<description>another question.. is this support on 5.0.5?</description>
		<content:encoded><![CDATA[<p>another question.. is this support on 5.0.5?</p>
]]></content:encoded>
	<feedburner:origLink>http://stoneblog.stonesoft.com/2011/07/a-very-quick-guide-for-configuring-stonegate-for-ios-vpn/comment-page-1/#comment-498</feedburner:origLink></item>
	<item>
		<title>Comment on A Very Quick Guide for Configuring StoneGate for iOS VPN by rence.suarez</title>
		<link>http://feedproxy.google.com/~r/CommentsForStoneblog/~3/S_Bau1WmCFk/</link>
		<dc:creator>rence.suarez</dc:creator>
		<pubDate>Tue, 07 Feb 2012 10:09:15 +0000</pubDate>
		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3410#comment-497</guid>
		<description>@RoarinPenguin thanks for the prompt reply.. i downloaded the application.. but im really lost.. can you send me a guide or a documentation on how to use this app? thanks a lot!</description>
		<content:encoded><![CDATA[<p>@RoarinPenguin thanks for the prompt reply.. i downloaded the application.. but im really lost.. can you send me a guide or a documentation on how to use this app? thanks a lot!</p>
]]></content:encoded>
	<feedburner:origLink>http://stoneblog.stonesoft.com/2011/07/a-very-quick-guide-for-configuring-stonegate-for-ios-vpn/comment-page-1/#comment-497</feedburner:origLink></item>
	<item>
		<title>Comment on A Very Quick Guide for Configuring StoneGate for iOS VPN by RoarinPenguin</title>
		<link>http://feedproxy.google.com/~r/CommentsForStoneblog/~3/VDi3S_g7eJk/</link>
		<dc:creator>RoarinPenguin</dc:creator>
		<pubDate>Tue, 07 Feb 2012 09:33:08 +0000</pubDate>
		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3410#comment-496</guid>
		<description>@rence.suarez: if it has 0kb size it means that export or generation obviously failed.
To generate good working certificates for these tests, I recommend to user the nice easy application XCA which is available for free @ http://xca.sourceforge.net.
Also, consider that on the iPhone you need to import both the user certificate and the CA public certificate that is used to validate the server certificate that SG will present.
Hope this helps.</description>
		<content:encoded><![CDATA[<p>@rence.suarez: if it has 0kb size it means that export or generation obviously failed.<br />
To generate good working certificates for these tests, I recommend to user the nice easy application XCA which is available for free @ <a href="http://xca.sourceforge.net" rel="nofollow">http://xca.sourceforge.net</a>.<br />
Also, consider that on the iPhone you need to import both the user certificate and the CA public certificate that is used to validate the server certificate that SG will present.<br />
Hope this helps.</p>
]]></content:encoded>
	<feedburner:origLink>http://stoneblog.stonesoft.com/2011/07/a-very-quick-guide-for-configuring-stonegate-for-ios-vpn/comment-page-1/#comment-496</feedburner:origLink></item>
	<item>
		<title>Comment on A Very Quick Guide for Configuring StoneGate for iOS VPN by rence.suarez</title>
		<link>http://feedproxy.google.com/~r/CommentsForStoneblog/~3/NRa69Zey08I/</link>
		<dc:creator>rence.suarez</dc:creator>
		<pubDate>Tue, 07 Feb 2012 09:22:54 +0000</pubDate>
		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3410#comment-495</guid>
		<description>Hi,

i tried making certificates but im having a problem with .p12.. i cant upload it because of its size, 0kb. i also tried Jose's way but still cant see the certificate on the iphone. the Use certificate tab is grayed out. what does that mean? sorry for my poor english..</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>i tried making certificates but im having a problem with .p12.. i cant upload it because of its size, 0kb. i also tried Jose&#8217;s way but still cant see the certificate on the iphone. the Use certificate tab is grayed out. what does that mean? sorry for my poor english..</p>
]]></content:encoded>
	<feedburner:origLink>http://stoneblog.stonesoft.com/2011/07/a-very-quick-guide-for-configuring-stonegate-for-ios-vpn/comment-page-1/#comment-495</feedburner:origLink></item>
	<item>
		<title>Comment on Forum by luchino7773</title>
		<link>http://feedproxy.google.com/~r/CommentsForStoneblog/~3/BSoOEv-WRbA/</link>
		<dc:creator>luchino7773</dc:creator>
		<pubDate>Fri, 03 Feb 2012 15:07:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-492</guid>
		<description>Hello.
I'm trying to install policy on a single firewall connected via pppoe (unfortunately with a dynamic ip address).
Smc and Log are statically natted by another cluster, contact was successful but everytime I try to install a simple policy i get a message like
Failed to connect to Reverse DCP dynamic for {StoneGate firewall node ID:343 SN:1014}	...	Error	4987	
Did anyone have this kind of problem?

Best regards!</description>
		<content:encoded><![CDATA[<p>Hello.<br />
I&#8217;m trying to install policy on a single firewall connected via pppoe (unfortunately with a dynamic ip address).<br />
Smc and Log are statically natted by another cluster, contact was successful but everytime I try to install a simple policy i get a message like<br />
Failed to connect to Reverse DCP dynamic for {StoneGate firewall node ID:343 SN:1014}	&#8230;	Error	4987<br />
Did anyone have this kind of problem?</p>
<p>Best regards!</p>
]]></content:encoded>
	<feedburner:origLink>http://stoneblog.stonesoft.com/stoneblog-community/forum/comment-page-2/#comment-492</feedburner:origLink></item>
	<item>
		<title>Comment on Forum by Marcello di Pasquale</title>
		<link>http://feedproxy.google.com/~r/CommentsForStoneblog/~3/oh6ArzAOuiw/</link>
		<dc:creator>Marcello di Pasquale</dc:creator>
		<pubDate>Mon, 30 Jan 2012 12:16:33 +0000</pubDate>
		<guid isPermaLink="false">#comment-487</guid>
		<description>Good morning. I have seemingly some troubles with certificates. When i try to install policy i receive the follwing error message: Received fatal alert: certificate_expired. i receive the same message when i try to get sginfo from firewall nodes. however, if i go to cnofiguration --&gt; configuration --&gt; administration --&gt; other elements --&gt; internal certificates (even in internal certificate authority), all my certificates are active. I tried to make an initial contact with one of my nodes, but nothing changes. did anyone have the same problem?
Thanks to all.
Regards.</description>
		<content:encoded><![CDATA[<p>Good morning. I have seemingly some troubles with certificates. When i try to install policy i receive the follwing error message: Received fatal alert: certificate_expired. i receive the same message when i try to get sginfo from firewall nodes. however, if i go to cnofiguration &#8211;&gt; configuration &#8211;&gt; administration &#8211;&gt; other elements &#8211;&gt; internal certificates (even in internal certificate authority), all my certificates are active. I tried to make an initial contact with one of my nodes, but nothing changes. did anyone have the same problem?<br />
Thanks to all.<br />
Regards.</p>
]]></content:encoded>
	<feedburner:origLink>http://stoneblog.stonesoft.com/stoneblog-community/forum/comment-page-2/#comment-487</feedburner:origLink></item>
	<item>
		<title>Comment on A Very Quick Guide for Configuring StoneGate for iOS VPN by djarvlejon</title>
		<link>http://feedproxy.google.com/~r/CommentsForStoneblog/~3/03-omr8KcAc/</link>
		<dc:creator>djarvlejon</dc:creator>
		<pubDate>Fri, 20 Jan 2012 08:09:20 +0000</pubDate>
		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3410#comment-480</guid>
		<description>Hi alien2108,
Did you test the way Jose Villafaña sugested? I keep geting the "Negotiation with VPN server failed"</description>
		<content:encoded><![CDATA[<p>Hi alien2108,<br />
Did you test the way Jose Villafaña sugested? I keep geting the &#8220;Negotiation with VPN server failed&#8221;</p>
]]></content:encoded>
	<feedburner:origLink>http://stoneblog.stonesoft.com/2011/07/a-very-quick-guide-for-configuring-stonegate-for-ios-vpn/comment-page-1/#comment-480</feedburner:origLink></item>
	<item>
		<title>Comment on A Very Quick Guide for Configuring StoneGate for iOS VPN by alien2108</title>
		<link>http://feedproxy.google.com/~r/CommentsForStoneblog/~3/7FX_9Lo-ZG4/</link>
		<dc:creator>alien2108</dc:creator>
		<pubDate>Thu, 19 Jan 2012 20:55:21 +0000</pubDate>
		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3410#comment-479</guid>
		<description>Doing some OS X clients again on another SG FW a couple more notes....

Be sure that at least ONE USER has IPSEC as authentication method in your policy (it doesn't matter if this user actually has ipsec method enabled). If no user has it, IPSEC authentication method will not be enabled on engines at all and your iosuser certificate will thus fail!

Creating vpn config package with "Iphone Configuration Utility" is fine for iOS devices but when I used it on OS X device, VPN didn't work no matter what. Reason was that StoneGate CA certificate was added to "Login" keychain and even moving it to system keychain didn't help. BUT if I deleted the CA certificate from the keychain and manually added this same SG CA certificate to System keychain (when you import it, be sure to select destination keychain-&gt;system) everything worked OK (sometimes you have to kill racoon process -&gt; "sudo killall -9 racoon").

Another thing is that Jailbroken iPhones will NOT establish VPN no matter what (IOS 5.0.1). This is a known issue (not sg related), just to let you all know -&gt; do not test with JB iPhones.</description>
		<content:encoded><![CDATA[<p>Doing some OS X clients again on another SG FW a couple more notes&#8230;.</p>
<p>Be sure that at least ONE USER has IPSEC as authentication method in your policy (it doesn&#8217;t matter if this user actually has ipsec method enabled). If no user has it, IPSEC authentication method will not be enabled on engines at all and your iosuser certificate will thus fail!</p>
<p>Creating vpn config package with &#8220;Iphone Configuration Utility&#8221; is fine for iOS devices but when I used it on OS X device, VPN didn&#8217;t work no matter what. Reason was that StoneGate CA certificate was added to &#8220;Login&#8221; keychain and even moving it to system keychain didn&#8217;t help. BUT if I deleted the CA certificate from the keychain and manually added this same SG CA certificate to System keychain (when you import it, be sure to select destination keychain-&gt;system) everything worked OK (sometimes you have to kill racoon process -&gt; &#8220;sudo killall -9 racoon&#8221;).</p>
<p>Another thing is that Jailbroken iPhones will NOT establish VPN no matter what (IOS 5.0.1). This is a known issue (not sg related), just to let you all know -&gt; do not test with JB iPhones.</p>
]]></content:encoded>
	<feedburner:origLink>http://stoneblog.stonesoft.com/2011/07/a-very-quick-guide-for-configuring-stonegate-for-ios-vpn/comment-page-1/#comment-479</feedburner:origLink></item>
	<item>
		<title>Comment on A Very Quick Guide for Configuring StoneGate for iOS VPN by alicante</title>
		<link>http://feedproxy.google.com/~r/CommentsForStoneblog/~3/tDC8wxVYizc/</link>
		<dc:creator>alicante</dc:creator>
		<pubDate>Fri, 13 Jan 2012 09:55:17 +0000</pubDate>
		<guid isPermaLink="false">http://stoneblog.stonesoft.com/?p=3410#comment-476</guid>
		<description>Hi all.

I have tried all the choices and followed all the advices unsuccessfully. I would like to know if someone has tested this kind of vpn with iOS5 and/or os x 10.7 lion.

Thanks in advance.</description>
		<content:encoded><![CDATA[<p>Hi all.</p>
<p>I have tried all the choices and followed all the advices unsuccessfully. I would like to know if someone has tested this kind of vpn with iOS5 and/or os x 10.7 lion.</p>
<p>Thanks in advance.</p>
]]></content:encoded>
	<feedburner:origLink>http://stoneblog.stonesoft.com/2011/07/a-very-quick-guide-for-configuring-stonegate-for-ios-vpn/comment-page-1/#comment-476</feedburner:origLink></item>
	<item>
		<title>Comment on TCPDUMP is your friend! by jmogez</title>
		<link>http://feedproxy.google.com/~r/CommentsForStoneblog/~3/S-DN1ZyWwsc/</link>
		<dc:creator>jmogez</dc:creator>
		<pubDate>Wed, 11 Jan 2012 09:15:27 +0000</pubDate>
		<guid isPermaLink="false">http://stoneblog.stonesoft.com/2009/01/tcpdump-is-your-friend/#comment-473</guid>
		<description>One question about inbound traffic : is tcpdump take place before filtering ?</description>
		<content:encoded><![CDATA[<p>One question about inbound traffic : is tcpdump take place before filtering ?</p>
]]></content:encoded>
	<feedburner:origLink>http://stoneblog.stonesoft.com/2009/01/tcpdump-is-your-friend/comment-page-1/#comment-473</feedburner:origLink></item>
</channel>
</rss>

