Go Back   NETGEAR Forums > Enterprise/Business Products > Firewall / VPN Devices > VPN Routers

Reply
 
Thread Tools Display Modes
  #1  
Old March 23rd, 2008, 11:23 AM
hansn hansn is offline
Senior Member
NETGEAR Expert
 
Join Date: Mar 2008
Location: Germany - Pfaffenhofen/Ilm
Posts: 417
hansn is on a distinguished road
Default FVS338 VPN Policy Enable Failed or mode conf errors

After modifying some IKE-policy-parameters I cannot enable the according vpn-policy any more; it shows "VPN Policy Enable Failed"; sometimes I get "mode conf"-error too. It is a FVS338 with actual v3.0.2-21. I think about going back to the latest v1-firmware. Any idea?
Reply With Quote
  #2  
Old March 23rd, 2008, 11:31 AM
jmizoguchi's Avatar
jmizoguchi jmizoguchi is offline
Senior Member
NETGEAR Fanatic
 
Join Date: Feb 2007
Location: Kentucky, USA
Posts: 88,745
jmizoguchi is on a distinguished road
Default Re: FVS338 VPN Policy Enable Failed or mode conf errors

you may want to create new policy instead. I would not go back to 1.x.x firmware. if you have just upgraded. you may want to hard reset
__________________
VPN Case Study (www.vpncasestudy.com)
Our Second To None VPN Related Setup Case Study
"One Stop Solution To Your Netgear VPN Connectivity"
*Visit the site for Non-VPN related Doc & Links* [Windows & Mac user/support]

Most Other Useful Docs -"General Technical Documentation", "Router Reset", "Router Setup", "Print Server Tips", "Remote Admin"
"Wireless Tips"


Forum Policy

June Mizoguchi-i....@vpncasestudy.com
Reply With Quote
  #3  
Old March 23rd, 2008, 11:53 AM
hansn hansn is offline
Senior Member
NETGEAR Expert
 
Join Date: Mar 2008
Location: Germany - Pfaffenhofen/Ilm
Posts: 417
hansn is on a distinguished road
Default Re: FVS338 VPN Policy Enable Failed or mode conf errors

I tried creating new policies; creating the ike-policy works, but by saving/applying a new vpn-policy I get a "Loading Conf Failed"-error. Have you experience, that this is durable solved after a hard-reset? Is the v3-firmware really reliable in your opinion?
Reply With Quote
  #4  
Old March 23rd, 2008, 12:00 PM
jmizoguchi's Avatar
jmizoguchi jmizoguchi is offline
Senior Member
NETGEAR Fanatic
 
Join Date: Feb 2007
Location: Kentucky, USA
Posts: 88,745
jmizoguchi is on a distinguished road
Default Re: FVS338 VPN Policy Enable Failed or mode conf errors

338 has pre-share key issue on reboot (on/off) with key will show "****" so you may need to use prior version from the newest one.

hard reset can clear the some issues I would try that.. you can back up restore and try. if still have issue hard reset again and manually setup all up on router setting.. some back up and restore bad configuration
__________________
VPN Case Study (www.vpncasestudy.com)
Our Second To None VPN Related Setup Case Study
"One Stop Solution To Your Netgear VPN Connectivity"
*Visit the site for Non-VPN related Doc & Links* [Windows & Mac user/support]

Most Other Useful Docs -"General Technical Documentation", "Router Reset", "Router Setup", "Print Server Tips", "Remote Admin"
"Wireless Tips"


Forum Policy

June Mizoguchi-i....@vpncasestudy.com
Reply With Quote
  #5  
Old March 23rd, 2008, 12:26 PM
hansn hansn is offline
Senior Member
NETGEAR Expert
 
Join Date: Mar 2008
Location: Germany - Pfaffenhofen/Ilm
Posts: 417
hansn is on a distinguished road
Default Re: FVS338 VPN Policy Enable Failed or mode conf errors

I found a solution!!! I reduced the PSK-stringlength to nine characters, rebooted the rooter and all works well! Without hardreset. Maybe the "****"-problem is also related to long psk's. I can remember, there was a psk-length-problem with the fvs338 in the year 2006 too; the problem in 2006 was, you never can establish a vpn-connection. To me it seems, Netgear has a psk-length-problem since years... if so, it is a shame...
Reply With Quote
  #6  
Old March 23rd, 2008, 12:30 PM
beisser's Avatar
beisser beisser is offline
Moderator
NETGEAR Prophet
 
Join Date: Nov 2006
Location: Near Munich, Germany
Posts: 3,620
beisser is on a distinguished road
Default Re: FVS338 VPN Policy Enable Failed or mode conf errors

Quote:
Originally Posted by hansn View Post
Maybe the "****"-problem is also related to long psk's.
its not related to psk length.
__________________
Forum Rules
How to contact Techsupport using various methods!
How to contact Techsupport by phone!
How to contact Techsupport online!
IPSEC-VPN, Tips and Tricks and Howto's
How to get proper access to the Enterprise-Forum!

"Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the universe trying to produce bigger and better idiots. So far, the universe is winning." -- Rich Cook

EVA1: EVA9000 -> 32" Samsung LCD
EVA2: EVAx000 -> 32" Samsung LCD
NAS: ReadyNAS Pro RNDP6610
Reply With Quote
  #7  
Old March 23rd, 2008, 12:41 PM
hansn hansn is offline
Senior Member
NETGEAR Expert
 
Join Date: Mar 2008
Location: Germany - Pfaffenhofen/Ilm
Posts: 417
hansn is on a distinguished road
Default Re: FVS338 VPN Policy Enable Failed or mode conf errors

I can not say, the '****'-problem is related to the psk-length, because I never had this problem seen on my FVS338s; but the "Policy Enable Failed" or "load conf" - errors are solved with short psks in my case; OK, I have to watch this the next days, but before shortening the PSKs I rebooted the router lots of times and tried lots of configurations without success. After shortening, all works well!? I've no reason to lie.
Reply With Quote
  #8  
Old March 23rd, 2008, 12:43 PM
beisser's Avatar
beisser beisser is offline
Moderator
NETGEAR Prophet
 
Join Date: Nov 2006
Location: Near Munich, Germany
Posts: 3,620
beisser is on a distinguished road
Default Re: FVS338 VPN Policy Enable Failed or mode conf errors

there should be a new firmware out soon™. it will contain various fixes on PSK's and other vpn-related stuff.
__________________
Forum Rules
How to contact Techsupport using various methods!
How to contact Techsupport by phone!
How to contact Techsupport online!
IPSEC-VPN, Tips and Tricks and Howto's
How to get proper access to the Enterprise-Forum!

"Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the universe trying to produce bigger and better idiots. So far, the universe is winning." -- Rich Cook

EVA1: EVA9000 -> 32" Samsung LCD
EVA2: EVAx000 -> 32" Samsung LCD
NAS: ReadyNAS Pro RNDP6610
Reply With Quote
  #9  
Old March 23rd, 2008, 12:45 PM
beisser's Avatar
beisser beisser is offline
Moderator
NETGEAR Prophet
 
Join Date: Nov 2006
Location: Near Munich, Germany
Posts: 3,620
beisser is on a distinguished road
Default Re: FVS338 VPN Policy Enable Failed or mode conf errors

Quote:
Originally Posted by hansn View Post
I've no reason to lie.
i dont say you lie.. but i tell you it (the ****-issue) has nothing to do with psk-length. there is no need for discussion there.
__________________
Forum Rules
How to contact Techsupport using various methods!
How to contact Techsupport by phone!
How to contact Techsupport online!
IPSEC-VPN, Tips and Tricks and Howto's
How to get proper access to the Enterprise-Forum!

"Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the universe trying to produce bigger and better idiots. So far, the universe is winning." -- Rich Cook

EVA1: EVA9000 -> 32" Samsung LCD
EVA2: EVAx000 -> 32" Samsung LCD
NAS: ReadyNAS Pro RNDP6610
Reply With Quote
  #10  
Old March 23rd, 2008, 12:50 PM
hansn hansn is offline
Senior Member
NETGEAR Expert
 
Join Date: Mar 2008
Location: Germany - Pfaffenhofen/Ilm
Posts: 417
hansn is on a distinguished road
Default Re: FVS338 VPN Policy Enable Failed or mode conf errors

New FW inside april?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -8. The time now is 01:27 AM.