ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Cradlepoint (Pertino) VPN and Watchguard Firewall

    IT Discussion
    9
    22
    2.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JoelJ
      Joel
      last edited by

      Team, I have a network running behind a Watchguard Firewall.

      I'm have installed Pertino (a cloud based software VPN) on our FileServer with the aim for external client laptops to access files from outside to the office. However, I believe the Watchguard is blocking Pertino's connection and it cant authenticate to the pertino server.

      My Q is: does anyone know how I can allow the application through our Watchguard?

      1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller
        last edited by

        That should not be a problem, unless the Watchguard is blocking outbound connections, which is very possible, but quite non-standard.

        1 Reply Last reply Reply Quote 1
        • stacksofplatesS
          stacksofplates
          last edited by

          I’ll be the annoying one. Why Pertino and not another mesh VPN like ZeroTier or Tinc?

          JaredBuschJ 1 Reply Last reply Reply Quote 4
          • JaredBuschJ
            JaredBusch
            last edited by

            Pertino works completely over port 443 with standard TLS. Unless you are screwing with outbound TLS, you should have no issues.

            1 Reply Last reply Reply Quote 2
            • JaredBuschJ
              JaredBusch @stacksofplates
              last edited by

              @stacksofplates said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

              I’ll be the annoying one. Why Pertino and not another mesh VPN like ZeroTier or Tinc?

              Also, I would use ZeroTier over Pertino.

              scottalanmillerS 1 Reply Last reply Reply Quote 3
              • scottalanmillerS
                scottalanmiller @JaredBusch
                last edited by

                @jaredbusch said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                @stacksofplates said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                I’ll be the annoying one. Why Pertino and not another mesh VPN like ZeroTier or Tinc?

                Also, I would use ZeroTier over Pertino.

                Same here.

                1 Reply Last reply Reply Quote 1
                • dbeatoD
                  dbeato
                  last edited by

                  @joel said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                  ave installed Pertino (a cloud based software VPN) on our FileServer with the aim for external client laptops to access files from outside to the office. H

                  What are the errors or logs you see on the Pertino software? What does your package analyzer show on the firewall or client?

                  1 Reply Last reply Reply Quote 0
                  • R3dPand4R
                    R3dPand4
                    last edited by

                    Just out of curiosity....why are you going with a separate VPN product? The SSL Client VPN from WatchGuard is free and works fine.

                    scottalanmillerS 1 Reply Last reply Reply Quote 1
                    • scottalanmillerS
                      scottalanmiller @R3dPand4
                      last edited by

                      @r3dpand4 said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                      Just out of curiosity....why are you going with a separate VPN product? The SSL Client VPN from WatchGuard is free and works fine.

                      Totally different type of product.

                      1 Reply Last reply Reply Quote 0
                      • JoelJ
                        Joel
                        last edited by Joel

                        I dont know ZeroTier - I pressume it's similar? I'll take a look at it - why would you pick that over Pertino? I do believe our Watchguard is blocking the outbound connections. What ports do Pertino use (anyone know off the top?) I can see our firewall is denying 56436 AND 56511

                        JaredBuschJ 1 Reply Last reply Reply Quote 0
                        • JaredBuschJ
                          JaredBusch @Joel
                          last edited by

                          @joel said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                          I dont know ZeroTier - I pressume it's similar? I'll take a look at it - why would you pick that over Pertino? I do believe our Watchguard is blocking the outbound connections. What ports do Pertino use (anyone know off the top?)

                          They use 443.

                          stacksofplatesS 1 Reply Last reply Reply Quote 1
                          • stacksofplatesS
                            stacksofplates @JaredBusch
                            last edited by stacksofplates

                            @jaredbusch said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                            @joel said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                            I dont know ZeroTier - I pressume it's similar? I'll take a look at it - why would you pick that over Pertino? I do believe our Watchguard is blocking the outbound connections. What ports do Pertino use (anyone know off the top?)

                            They use 443.

                            The only other port ZeroTier uses is 9993/udp, but that's to help with local LAN detection. But it's not necessary.

                            1 Reply Last reply Reply Quote 0
                            • JoelJ
                              Joel
                              last edited by

                              I just took a look at ZT and I like that it works on QNAP and Synology too - very useful. I may have to look at this 🙂

                              JaredBuschJ scottalanmillerS 2 Replies Last reply Reply Quote 0
                              • JaredBuschJ
                                JaredBusch @Joel
                                last edited by

                                @joel said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                                I just took a look at ZT and I like that it works on QNAP and Synology too - very useful. I may have to look at this 🙂

                                One of my clients has the paid subscription to get notifications of ZT going down on selected devices. It is quite useful.

                                1 Reply Last reply Reply Quote 1
                                • scottalanmillerS
                                  scottalanmiller @Joel
                                  last edited by

                                  @joel said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                                  I just took a look at ZT and I like that it works on QNAP and Synology too - very useful. I may have to look at this 🙂

                                  It's very broad support.

                                  1 Reply Last reply Reply Quote 0
                                  • K
                                    krisleslie
                                    last edited by

                                    @scottalanmiller said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                                    just took a look at ZT and I like th

                                    Scott is there a use case for Pertino anymore ? I still have them.

                                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @krisleslie
                                      last edited by

                                      @krisleslie said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                                      @scottalanmiller said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                                      just took a look at ZT and I like th

                                      Scott is there a use case for Pertino anymore ? I still have them.

                                      If you have them already, they are fine. And they do some decent AD management stuff that is unique (I designed that 😉 but overall, what they offer isn't really unique and they are way more expensive than their more advanced competition. So my feeling is that their place is pretty niche today.

                                      JaredBuschJ 1 Reply Last reply Reply Quote 1
                                      • JaredBuschJ
                                        JaredBusch @scottalanmiller
                                        last edited by

                                        @scottalanmiller said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                                        @krisleslie said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                                        @scottalanmiller said in Cradlepoint (Pertino) VPN and Watchguard Firewall:

                                        just took a look at ZT and I like th

                                        Scott is there a use case for Pertino anymore ? I still have them.

                                        If you have them already, they are fine. And they do some decent AD management stuff that is unique (I designed that 😉 but overall, what they offer isn't really unique and they are way more expensive than their more advanced competition. So my feeling is that their place is pretty niche today.

                                        It is important to note that today that @scottalanmiller ended with. When Pertino started in 2012, there was not anything good on the market to compare.

                                        1 Reply Last reply Reply Quote 3
                                        • scottalanmillerS
                                          scottalanmiller
                                          last edited by

                                          Exactly, times change. They have new and more modern competition and I've not seen Pertino do anything to keep up.

                                          1 Reply Last reply Reply Quote 2
                                          • J
                                            Jimmy9008
                                            last edited by

                                            Connect to your Watchguard with WSM. Go to Policy and check the rules.
                                            Do you have a policy for TCP(0)/UDP(0), From 'Any', to 'Any-External'.?
                                            If so, then 443 request out from the device will be allowed.

                                            If you do not have that rule, or a similar rule but with the IP of the device withing the 'From' column, TCP/UDP will not be allowed out.

                                            I believe Watchguard standard configuration is to stop all out, then allow only particular things out that are allowed. Rather than allow all out.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post