VPN / Tunneling Woes - Networking

Hey, I was hoping I could get some help with this. I must be doing something wrong because I've spent a ridiculous amount of time on this project and have nothing to show for it.
I want to run a mobile hotspot on my phone, but not nearly enough to justify paying Verizon an extra $30/month for tethering. I'd only use it a few times a month and wouldn't push a lot of data thru, plus I'm paying them for an "unlimited" data plan - I won't get into that, you know where I'm coming from. I know they probably won't do anything about it since I'm using it so little, but I want to add an extra layer of security via an SSH tunnel or a VPN. I'm sure they just have to run a very basic report on their system to catch somebody who's tethering, and who knows when some manager will tell them to run it on every user vs just the high bandwidth ones? They could force me onto a more expensive plan, disable my account, throttle my connection, or just block any port an Android phone doesn't normally use, and they could do all that automatically pretty easily. If all my tethering data is encrypted they'd have to do some actual work to prove I'm tethering and probably won't think it's worth their time.
I installed OpenSSH on my home PC, forwarded some ports, and put the SSHTunnel app on my phone and it works great. It seamlessly moves all traffic over my SSH tunnel, except for the mobile hotspot. Which was kind of the point of the whole exercise! I looked all over the place but could not find a way to resolve this.
Next I looked at setting up a VPN so I loaded TomatoVPN on my router. The default VPN (OpenVPN) option for that firmware is IPSec with a CA certificate, so I went about setting that up. Apparently the default Android VPN client doesn't work well with IPSec because I can't get it to work - it keeps prompting me for a username and password, but it won't accept my router's admin credentials. None of the tutorials mention that prompt and I can't get around it. I messed around with an IPSec PSK VPN but couldn't get Android to connect to that either.
I looked into PPTP a bit but they say it's not supported by Linksys or OpenWRT, and from my experience Tomato doesn't appear to work with it either. I was going to put a PPTP server on my PC but saw somewhere that many routers can't forward PPTP requests from a WAN into the LAN.
So I went back to the IPSec approach, figuring the problem is with the Android client. I tried putting OpenVPN on my phone, but got stuck where I have to register a tun.ko file using the terminal. I don't even know if I found the right tun.ko. Then I realized I was trying to install an app to configure an app that installs another app and maybe I wasn't going about this the right way.
Does anybody have any advice? How should I approach this?
Here's what I'm using
Phone: Rooted HTC Thunderbolt
Carrier: Verizon

Ugh, looks like Verizon is 1 step ahead of me:
jbenisek.wordpress.com/2010/10/05/android-2-1-and-2-2-vpn-pptp-over-verizon/
Well, that sucks.

Related

ATT Tilt vpn not connecting over EDGE

Anyone else having trouble with att tilt vpn over edge? I've had several smartphones in the past, the last being tmobile wing, and have never had any problems creating a vpn connection with url exceptions. With this new tilt it seems like I can connect the vpn only over wifi, it does not attempt to connect to the vpn when just using edge. I've reset the device several times both with and without the att customization.
Any ideas for this problem would be appreciated.
Thanks,
-J
TILT VPN Connection problems
I have been trying to make VPN connections over EDGE and 3G also. I find that the connection does get made if I connect manually, but as soon as I try to access something through IE, RD or Opera, it drops the connection. I have seen the connection maintained for up to a minute, but I cannot access anything.
I called ATT yesterday early afternoon. At that point the CSR was a proxy for the tech dept and told me to call HTC. I contacted HTC tech support and they were convinced it was an att softwae problem since the url exceptions worked correctly over wifi.
I called back ATT last night, got a csr who xfer me to a tech rep. He walked through the steps and provisioned isp.cingular apn to see if that would work. It did not. He then sent me to advanced network services where I got someone who definately was either not having a good night or had no intention of actually working that night. After his xfer to a bad extension, I called back to a csr, who then semi-understood the situation ( she was actually excellent help at the time for not being a tech person ) She put me with another advanced network services tech ( the first time she called advanced tech services she was hungup on by the same "Steve" I had encounted a few minutes earlier. Nice work Steve) who walked through the settings a few times, and then suggested I try another tilt at an att store.
Unfortunately it seems as though noone I've talked to yet has a grasp on url exceptions or what a vpn is? Noone from ATT or HTC seems to understand that its the software that's not trying to even attempt to connect to the vpn. I would be fine if it was my problem, vpn wise. I'm sure they're just doing their jobs but it's a little frustrating to pay $550 for a phone to have it no do something your other htc phone was doing last week. Anyways thats where I'm at now. I will try to go to an att store tonight and see if it works on another phone. I'm curious to know if anyone with the regular kaiser ( with the front camera ) is having a similar problem.
-J
Round 1
I called ATT yesterday early afternoon. At that point the CSR was a proxy for the tech dept and told me to call HTC. I contacted HTC tech support and they were convinced it was an att softwae problem since the url exceptions worked correctly over wifi.
I called back ATT last night, got a csr who xfer me to a tech rep. He walked through the steps and provisioned isp.cingular apn to see if that would work. It did not. He then sent me to advanced network services where I got someone who definately was either not having a good night or had no intention of actually working that night. After his xfer to a bad extension, I called back to a csr, who then semi-understood the situation ( she was actually excellent help at the time for not being a tech person ) She put me with another advanced network services tech ( the first time she called advanced tech services she was hungup on by the same "Steve" I had encounted a few minutes earlier. Nice work Steve) who walked through the settings a few times, and then suggested I try another tilt at an att store.
Unfortunately it seems as though noone I've talked to yet has a grasp on url exceptions or what a vpn is? Noone from ATT or HTC seems to understand that its the software that's not trying to even attempt to connect to the vpn. I would be fine if it was my problem, vpn wise. I'm sure they're just doing their jobs but it's a little frustrating to pay $550 for a phone to have it no do something your other htc phone was doing last week. Anyways thats where I'm at now. I will try to go to an att store tonight and see if it works on another phone. I'm curious to know if anyone with the regular kaiser ( with the front camera ) is having a similar problem.
-J
Sorry for that last double post. I did go back to the att kiosk again today and tried another tilt, which had the same results. I decided to return the one I had purchased and think i may try the regular htc kaiser with the front camera.
If anyone can verify that that version of phone works with pptp, that would be great.
From your last message I tried a few other things and I too was able to manually connect ( even get a prompt for login credentials to the vpn ) however the IE still will not try to connet with the url exception or keep the vpn connection open after IE is opened.
It's sad to think the att tilt is not working in thie regard. It takes away quite a bit of functionality for those who do use the vpn feature.
-J
PIE will "ignore" exceptions for work connection using EDGE
I see similar problem with 8525 at&t WM 5.0 device (HTC Hermes) exact version Microsoft ® Windows Mobile™ Version 5.0 with the Messaging and Security Feature Pack. 5.0 OS 5.1.478 (Build 15706.3.5.2)
PIE will "ignore" exceptions for work connection using EDGE. However other applications like “ActiveSync” and “Terminal Service Client” work properly.
If Wi-Fi connection used for Internet, PIE as well works properly.
FYI on previous device 8525 Cingular
Microsoft ® Windows Mobile™ Version 5.0 OS 5.1.195 (Build 14955.2.3.0)
work exceptions works with PIE
it continues...
I ordered htc kaiser, had it shipped opened it, configured, and the results were.....
it would use work exceptions as it should, dialing the vpn when using PIE and calling trying to access a host in the exceptions list.
It did not however want to connect to the host even after establishing a connection with the vpn server.
I dont know why, but I thought of checking the ip address with PocketLan on the gprs interface. The ip address was a 10.x.x.x but the kicker was the subnet mask using 255.0.0.0. That may cause a problem with routing as my vpn tunnel is not a full 10/8 but still a 10/16. Anyway I decided to try the online tech chat and spoke with "Marcus"
I asked if there had been any changes in the last month or so on as far as ip address scopes using wap.cingular He said yes. I'm still not sure if that was actually the case or not . I went ahead and upgraded to the pda connect unlimited to use the isp.cingular, as the "pda personal max" just uses wap.cingular.
I had to connect several times with the isp.cingular to have the connection get a public ip address rather than a nat'd 10.x.x.x. It DOES now work properly with url exceptions, connecting the vpn, the whole ball of wax with isp.cingular
Unfortunately I had already returned the ATT Tilt so I dont have any way to test if it was the att software causing it or not. If anyone would like to let me borrow one for a few days we can do that
I am going to test with another vpn connection using a 192.168 or 172.16 etc. ip scope and see if it works with wap.cingular getting a 10.x.x.x address.
Anyways, thats it for now. I'll post again after the vpn test with the different scope.
Thanks,
-J
Today I setup a vpn server with a 192.168.x.x scope. Using wap.cingular i was able to connect to the vpn and hosts within the vpn.
I tried again to connect to the 10.x.x.x vpn and try to edit the routing table using the PocketLan but each time I try to edit something it returns an error.
I'll have to try to find another utility or see if there a way to edit the routing table.
I'm hoping theres a way to change the default route for the 10.x network.
Here's some of the info when connecting over a wap.cingular connection
ip: 10.67.x.x
gateway: 10.67.x.x ( same as ip address )
subnet mask: 255.0.0.0/8
DNS: 66.209.10.201, 66.102.163.231
WINS: 10.11.12.13, 10.11.12.14 ( kind of hard to imagine any reason for wins entries? 10-11-12-13 seems like they may just be fake address. I dont know how window mobile does it's resolution, but that doesnt seem like it would be in the customers interest to be pointed to non-existant wins, if thats what they are. This may just be place holder entries for the PocketLAN software?)
Here's some of the info when connecting over a isp.cingular connection
ip: 166.128.x.x
gateway: 166.128.x.x ( same as ip address )
subnet mask: 255.255.0.0/16
DNS: 209.183.48.11, 208.183.48.10
WINS: 10.11.12.13, 10.11.12.14 ( same comments as before )
See Arin Whois for this netblock
OrgName: Service Provider Corporation
OrgID: SPC-10
Address: 442 Route 202-206 North
Address: # 485
City: Bedminster
StateProv: NJ
PostalCode: 07921-0523
Country: US
NetRange: 166.128.0.0 - 166.255.255.255
CIDR: 166.128.0.0/9
NetName: NETBLK-CDPD-B
NetHandle: NET-166-128-0-0-1
Parent: NET-166-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.WIRELESSDATASPCO.ORG
NameServer: NS.CDPDSPCO.ORG
Comment:
RegDate: 1993-07-09
Updated: 2005-01-07
RTechHandle: WDSPC-ARIN
RTechName: WDSPCo Helpdesk
RTechPhone: +1-215-489-7599
RTechEmail: [email protected]
OrgTechHandle: WDSPC-ARIN
OrgTechName: WDSPCo Helpdesk
OrgTechPhone: +1-215-489-7599
OrgTechEmail: [email protected]
# ARIN WHOIS database, last updated 2007-11-02 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
I just thought of testing tracreroutes form both isp and wap.cingular. It does then show the problem with the ip information when trying to route.
When using the tilt though at first, none of this seemed possible at the time ( as I thought I was going a little nuts ) since the url exceptions never seem to attempt to connect to the vpn at all. As if the exceptions were ignored when using anything except WIFI.
Thats it for now. Post something new later.
-J
jakedahs,
Very informative. Looks like its' been a few weeks. New insights?
Best,
Things are still working good with the kaiser and the isp.cingular. I haven't come across another ATT Tilt again to test it out again. Any other things you can think to test to put on this forum?
Thanks,
-J
LOL! I'm so far behind, I don't have a clue.
Tilt and VPN PPTP
jakedahs said:
I called ATT yesterday early afternoon. At that point the CSR was a proxy for the tech dept and told me to call HTC. I contacted HTC tech support and they were convinced it was an att softwae problem since the url exceptions worked correctly over wifi.
I called back ATT last night, got a csr who xfer me to a tech rep. He walked through the steps and provisioned isp.cingular apn to see if that would work. It did not. He then sent me to advanced network services where I got someone who definately was either not having a good night or had no intention of actually working that night. After his xfer to a bad extension, I called back to a csr, who then semi-understood the situation ( she was actually excellent help at the time for not being a tech person ) She put me with another advanced network services tech ( the first time she called advanced tech services she was hungup on by the same "Steve" I had encounted a few minutes earlier. Nice work Steve) who walked through the settings a few times, and then suggested I try another tilt at an att store.
Unfortunately it seems as though noone I've talked to yet has a grasp on url exceptions or what a vpn is? Noone from ATT or HTC seems to understand that its the software that's not trying to even attempt to connect to the vpn. I would be fine if it was my problem, vpn wise. I'm sure they're just doing their jobs but it's a little frustrating to pay $550 for a phone to have it no do something your other htc phone was doing last week. Anyways thats where I'm at now. I will try to go to an att store tonight and see if it works on another phone. I'm curious to know if anyone with the regular kaiser ( with the front camera ) is having a similar problem.
-J
Click to expand...
Click to collapse
I too am having issues with my Tilt and VPN. So when I got the Tilt 10 days ago, I had a blackberry 8300 (Curve), when i left the store they had me on the same BlackBerry Data plan. The VPN worked fine - Perfectly in fact. A few days later when I questioned why I was still using a blackberry plan the CSR at AT&T said I should be on a PDA data plan and changed my service. After that the VPN stopped working. I contacted AT&T chat support and also called their complex data device support department and after changing a bunch of settings on the phone they finally gave up and said they could not support the VPN option. Nice Huh?
When I get home I am going to try connecting over WiFi and trying the VPN. This should tell me if the routing / VPN issue is related to traffic over AT&T or if there is something wrong with the phone.
Additionally, when the VPN worked it used to show a " balloon status " telling me VPN was connecting. Now it no longer does that. Even if I do force the VPN to connect and then try to use the connection is disconnects immediately.
I'm guessing you're going to have the same result. If you'd like we can run through some tests using different scopes of vpn's. I'd be interested in trying the tilt again since I know the kaiser I have works ok and I'm not crazy
VPN
jakedahs said:
I'm guessing you're going to have the same result. If you'd like we can run through some tests using different scopes of vpn's. I'd be interested in trying the tilt again since I know the kaiser I have works ok and I'm not crazy
Click to expand...
Click to collapse
What kind of tests were you thinking?
wap.cingular - isp.cingular / netowrk settings
jakedahs said:
I ordered htc kaiser, had it shipped opened it, configured, and the results were.....
it would use work exceptions as it should, dialing the vpn when using PIE and calling trying to access a host in the exceptions list.
It did not however want to connect to the host even after establishing a connection with the vpn server.
I dont know why, but I thought of checking the ip address with PocketLan on the gprs interface. The ip address was a 10.x.x.x but the kicker was the subnet mask using 255.0.0.0. That may cause a problem with routing as my vpn tunnel is not a full 10/8 but still a 10/16. Anyway I decided to try the online tech chat and spoke with "Marcus"
I asked if there had been any changes in the last month or so on as far as ip address scopes using wap.cingular He said yes. I'm still not sure if that was actually the case or not . I went ahead and upgraded to the pda connect unlimited to use the isp.cingular, as the "pda personal max" just uses wap.cingular.
I had to connect several times with the isp.cingular to have the connection get a public ip address rather than a nat'd 10.x.x.x. It DOES now work properly with url exceptions, connecting the vpn, the whole ball of wax with isp.cingular
Unfortunately I had already returned the ATT Tilt so I dont have any way to test if it was the att software causing it or not. If anyone would like to let me borrow one for a few days we can do that
I am going to test with another vpn connection using a 192.168 or 172.16 etc. ip scope and see if it works with wap.cingular getting a 10.x.x.x address.
Anyways, thats it for now. I'll post again after the vpn test with the different scope.
Thanks,
-J
Click to expand...
Click to collapse
Since they had me change my plan and settings around I called and confirmed that I now have the PDA Connect Unlimited plan. However, in the phone's connection settings what should the two network and subsequent individual network setting be? Mine was set to Media Net and Media Net.
I tried setting it to ATT ISP but it still did not work.
I just use isp.cingular all the time. Have you created work url exceptions for your vpn connection? The problem I was having when I had the tilt is even though I had the exceptions it would never attempt to dial the vpn when going to a web site on the vpn network. I'm thinking it may have been ATT that cripled the phone somewhat. The regular HTC Kaiser I have now works fine.
VPN - TILT
So I confirmed that if I use my WiFi connection the VPN works perfectly.
There is some issue with routing over AT&T data network. I tried chatting with their online chat support and they could not give me the settings I needed. It was clearly beyond their scope of knowledge. I will try calling their complex data support department to see if I can get the right settings.
How can a company offer data services and not understand their own network?
Vpn - Tilt - Settings
I found this posting at the cingular.com forum.
Since I need to call tomorrow to confirm my provisioning and my data plan subscription I cannot tell if they will work but I thought I would make the info public.
Here's what I've done to VPN using L2TP successfully... (someone else)
- Have PDA Unlimited Plan
- Call to have your account "provisioned" to use isp.cingular
- Create a new connection using the isp.cingular settings
- Configure device to always use that connection
- Create a new VPN connection
- Import appropriate certificates (if necessary)
- Disable (preferably remove) Proxy settings in Registry
- Create an Exception list for Intranet addresses
- Configure device networks to use isp.cingular for Internet access and vpn for 'Your Work/Intranet' network
One thing I have noticed is that if I let the device connect automagically to VPN, it will disconnect after a short period of inactivity. If I manually/force connect to VPN, it stays that way until I disconnect session.
I can connect either via 3G or Edge with no issues/problems.
VPN Access over anything on the tilt would be nice
I am unable to either one of my 2 vpn's using any connection configuration. I It seems like it wants to connect but then gives me an error msg telling me to check username and password.
Can anyone shed anylite what I'm doing wrong?
Tilt Vpn over Edge
With a little patience i figured it out! if you connect to your VPN first and then go to IE it will disconnect you. But if you go to IE, Opera, whatever first and then go to the address that you have in your exception list the tilt will connect to MediaNet and then connect to your VPN server and work!

tun.ko for 2.1 ROMs..? Need for Cisco VPN

Hey, I have been looking forward to the 2.1 update for our Heros because I thought it was going to finally give us simple VPN access... *to Cisco concentrators*. Unfortunately, it only gives us IPSec/L2TP PSK or CRT... whereas I need a pure IPSec client that supports Group Authentication in order to connect to my corporate VPN.
So, I, and I am sure many others, need to revert back to the Get-A-Robot-VPNC client to connect to our corporate networks, but apparently do not have a correct tun.ko module. Trying to insmod a tun.ko module, I get "invalid format" or "failed executable" - So, can someone provide a tun.ko that we can use, or explain how to get one installed in these new 2.1 ROMs?
I am currently using the ZenHero 2.1 ROM
Thanks! Once I get VPN access again, the Hero will really be something pretty damn awesome again.
Or, does anyone know of any VPN clients coming down the pipe for Android? or any other projects in development?
I heard Shew Soft was coming out with a mobile variant... not sure if it'll be on Android though..
I have no use for it or way to try it, but I did find vpn connections in the market when searching for something else and remembered this thread. It said on the comments though to go to the site for the latest version. http://code.google.com/p/get-a-robot-vpnc/
actually, a search for vpn in the market turned up a few options. Take a look, I don't know exactly what you need.
I have been trying multiple ways. I even tried the tun.ko. I have not been successful but I would like to hear if anyone is successful.
danaff37 said:
actually, a search for vpn in the market turned up a few options. Take a look, I don't know exactly what you need.
Click to expand...
Click to collapse
Unfortunately, none support, what I think to be the most popular VPN type, from a corporate stand-point: pure IPSec that supports Group Authentication. Most in the market are just for VPNC.
Thanks for your post though.
Yes the android app is lacking.
I have a Cisco concentrator working with MY phone. I just dumped all Group based auth. We wanted a device that would work with 99.999% of devices on the market and our little Asa-5505 does the trick.
You should be able to configure policies on the cisco to handle either clients, that is really your or your admins choice.
Otherwise the stock android vpn client MY only complaint is it will NOT let me vpn over mobile network.. only wifi. Kinda pointless if I have wifi I would use my laptop to vpn to work. WTF?
Sprint is the problem
kkruse said:
Yes the android app is lacking.
I have a Cisco concentrator working with MY phone. I just dumped all Group based auth. We wanted a device that would work with 99.999% of devices on the market and our little Asa-5505 does the trick.
You should be able to configure policies on the cisco to handle either clients, that is really your or your admins choice.
Otherwise the stock android vpn client MY only complaint is it will NOT let me vpn over mobile network.. only wifi. Kinda pointless if I have wifi I would use my laptop to vpn to work. WTF?
Click to expand...
Click to collapse
I realize this post has been sitting here for a while, but I thought this might help some others who may run into similar issues. At my work, we have all Cisco equipment and have a Cisco ASA configured with PSK mobile VPN. We are having basically no luck getting in using Sprint-connected devices (Sprint EVO 4G) on anything but Wifi. I CAN, however, connect just fine on my Samsung Captivate over AT&T 3G signal using the same built-in android VPN client. We've gone the rounds with the Sprint Engineers on this and they have nothing they can pinpoint that is causing this outage. I would really like for either Cisco or Sprint to come up with a good explanation as it shouldn't matter if you're on Wifi or 3G, it should work either way. The point is that it works on AT&T for us, but not Sprint, as far as 3G/4G data connection is concerned.

VPN Constant Disconnects

My Xoom usually disconnects the VPN immediately after opening any file from an SMB Share using ES File Explorer. I preferred Astro but the SMB addon doesn't work with Honeycomb yet. A variation of different vpn clients all do the same, as soon as data is done being transferred from a single download, the VPN will disconnect.
Is there a workaround for this? It would be great to only have the VPN connect when resources on the network were accessed or written.
I haven't found a workaround or solution to keep the VPN up and stable.
(btw, this is a typical MS 2008 PPTP on a Windows Domain)
At the moment, I'm having to reconnect after every file transfer- again, the wireless network doesn't seem to make a difference (although the 3g connection is obviously poor)
I've done a little troubleshooting on this in the last few days using the magic of wireshark. MS PPTP Server, makes the connection and then drops after SMB traffic is attempted, as well any website will not load, and no email / communication will work.
I believe this fully involves a Default Gateway setting on the Xoom, being it's a client-side setting and the Xoom doesn't appear allow that option to be changed (silly that it's missing, imo).
When I make a connection, Verizon's firewall policies see a foreign IP return traffic at some point on their network and blocks the transmission completely, eventually causing PPTP to timeout.
Here's a good read on how to get around the restriction:
http://jbenisek.wordpress.com/2010/10/05/android-2-1-and-2-2-vpn-pptp-over-verizon/
I myself have been on the phone this morning regarding this issue, I'm up to about a 3rd level of tech support and he is trying to tell me 'nothing is blocked at all on the Verizon network'...
I'm awaiting a call back now... at which I'll try to show him the above site/resource and maybe he'll move me to an unrestricted IP block. We bought 3 Xooms with the intention of working remotely in the field using PPTP- 4 more coming soon---
At this point, I'm still tempted to go back to Sprint and just wait on their Xoom release.
*btw, you can verify the above by tethering to the Xoom and changing your default gateway on a laptop/pc, the connection will work fine.
edit:
AH-HAH!
And more info;
http://code.google.com/p/android/issues/detail?id=4706
Apparently this is a known issue.
Encrypted PPTP is broken on Android: http://code.google.com/p/android/issues/detail?id=4706
I've posted about this problem in this thread:
http://forum.xda-developers.com/showthread.php?t=992876
I've tried it on every version of Android since 2.1. I tried it with my Xoom on 3.0 and the problem remains. It appears to be a pretty low priority for Google.
sangreal06 said:
Encrypted PPTP is broken on Android: http://code.google.com/p/android/issues/detail?id=4706
Click to expand...
Click to collapse
Turned off encryption on the server and all was well. I can't believe google let that slide... !?
I guess I'll transition to a L2TP VPN...

Tmobile Blocking tethering - im rooted on cm7

Well yesterday I was tethering like i've done every day on my device and I kept getting redirected to a tmobile webpage telling me to pay an extra $15 per month for tethering.
My T989 Sgsii is using CM7 and there is no tmobile tethering software on the device. Is anyone else able to tether? Im on a prepaid contract have have tethered every day for free since last december.
Im guessing tmobile is blocking my tethering on the network end, since all blocking/tethering management software has been removed from my phone.
Any advice? If i cant tether, i cant use up all 5 gigs i pay for, so ill probably get a cheaper plan or switch to straight talk.
Seems like we have the same problem?
I made a post on the Nexus One forum aswell.
zeus_chingon said:
Seems like we have the same problem?
I made a post on the Nexus One forum aswell.
Click to expand...
Click to collapse
Yup. Looks like we both have the same problem.
Tmobile must be somehow able to detect when my computer tries to hop on their network and blocks it.
Can anyone else who uses tmobile comment on this?
They're mainly catching you by looking at the headers of your http traffic, and assuming that http requests with desktop browser strings are coming from tethered PCs. If you change them to spoof Android's browser, T-mo can't tell the difference.
They could probe more deeply if they wanted to, but as a practical matter, they don't. If they blindly dip the net into the stream and just look for http traffic with desktop-browser identities, they can effortlessly catch 99% of the people who tether.
If you really want to hide your tethering from them, just subscribe to a PPTP VPN service like ibvpn.com. It's around $5/month (~$37 if you pay for the whole year up front), it'll TOTALLY hide what you're doing from T-Mobile (because all they'll see is an encrypted bitstream), and also comes in handy for using a wi-fi tablet with public access points (the reason *I* subscribe).
Just be careful to make sure your network connection doesn't drop while you're tethered, because there doesn't seem to be any way to tell Android, "Establish this VPN whenever there's connectivity, and DO NOT send ANY data via ANY means besides the VPN". If your connection drops, the VPN will break, and if the phone reconnects to T-Mo a half second later, it'll just silently send all network traffic going forward straight through T-Mobile until you reconnect to the VPN.
bitbang3r said:
They're mainly catching you by looking at the headers of your http traffic, and assuming that http requests with desktop browser strings are coming from tethered PCs. If you change them to spoof Android's browser, T-mo can't tell the difference.
They could probe more deeply if they wanted to, but as a practical matter, they don't. If they blindly dip the net into the stream and just look for http traffic with desktop-browser identities, they can effortlessly catch 99% of the people who tether.
If you really want to hide your tethering from them, just subscribe to a PPTP VPN service like ibvpn.com. It's around $5/month (~$37 if you pay for the whole year up front), it'll TOTALLY hide what you're doing from T-Mobile (because all they'll see is an encrypted bitstream), and also comes in handy for using a wi-fi tablet with public access points (the reason *I* subscribe).
Just be careful to make sure your network connection doesn't drop while you're tethered, because there doesn't seem to be any way to tell Android, "Establish this VPN whenever there's connectivity, and DO NOT send ANY data via ANY means besides the VPN". If your connection drops, the VPN will break, and if the phone reconnects to T-Mo a half second later, it'll just silently send all network traffic going forward straight through T-Mobile until you reconnect to the VPN.
Click to expand...
Click to collapse
best advice ive received so far - i was wondering how they were able to tell i was tethering. so i guess ill just need a browser that supports changing of the user agent? or is it more complicated to browser spoof?
I got the same message two days ago with a prepaid account on a CM9 exhibit ii
I'm not sure just changing the ua would help though because I'm getting the redirect on my android tablet as well, not just my laptop
The headers also give them an idea if more than one unit is being serviced, ie: hotspot. Encryption hides this as well. Bottom line? They will see tethering if they look for it.
Sent from my SCH-I510 using XDA
I just use Opera. It hasn't failed me yet.
I believe the tether detection works by looking at the TTL for packets. It would be more than it should be if the client is using the device as a gateway. Thing is HTTPS still works once you've been "blocked" as well a bunch of other protocols, so it looks like they are just setting a captive portal for port 80 traffic. That said, I have a Zentyal VPN set up at home on my 50mb/s line, so once tethered I VPN into my home machine which then resets my gateway on my laptop to be the gateway on the VPN machine at home. This redirects ALL traffic through the VPN effectively side stepping t-mobiles blocking altogether. So as long as they still allow any data connections over my data plan while tethering than I can access everything like normal. One positive side effect is that general browsing seems to be MUCH faster given that the traffic is really actually being downloaded from my home connection and being siphoned through the VPN rather than having the phone itself and t-mobiles crappy gateway doing all the work.
---------- Post added at 08:04 AM ---------- Previous post was at 08:00 AM ----------
Not to mention, everything is encrypted so t-mobile cant track any of my surfing habits either. I dont know about you all, but I tend to trust my ISP a little more than my wireless carrier.
So the issue has been solved.
I can tether on tmobiles network with no issues as long as i DONT use google chrome. Safari and Firefox access webpages no problem. Chrome has a user agent string which tmobile is able to see - and block by default on their network.
I'm on Tmobile w/ my Droid 3, stock OS. I tether once in a while, only use Chrome for browsing, and I've never gotten redirected.
--posted from my phone
EDIT: found another thread here with more posts:
http://forum.xda-developers.com/showthread.php?p=26477722
5318008 said:
I'm on Tmobile w/ my Droid 3, stock OS. I tether once in a while, only use Chrome for browsing, and I've never gotten redirected.
--posted from my phone
EDIT: found another thread here with more posts:
http://forum.xda-developers.com/showthread.php?p=26477722
Click to expand...
Click to collapse
I was using chrome all day today. First half of the day it was fine (and every other time before this but I've only had them for less than a month), but then after I started pushing maybe a gig through netflix in addition to using chrome THEN chrome stopped working. Had to use a user agent extension to get chrome working again.
So it might be a trigger set off by data usage to THEN check for the user agent
colonelcack said:
I was using chrome all day today. First half of the day it was fine (and every other time before this but I've only had them for less than a month), but then after I started pushing maybe a gig through netflix in addition to using chrome THEN chrome stopped working. Had to use a user agent extension to get chrome working again.
So it might be a trigger set off by data usage to THEN check for the user agent
Click to expand...
Click to collapse
Makes sense. TMobile doesn't appear to have refarmed Portland yet, so when I do tether, I don't end up using that much data, what with being stuck on 2G and all.
Please look at my post regarding T-mobile tethering
http://forum.xda-developers.com/showthread.php?p=26649587#post26649587
The methods employed by t-mobile to detect tethering are quite frivolous and an asinine move on their part. Their detection does not even work properly.
Sent from my SGH-T989 using Tapatalk 2
fix for Tmobile blocking tethering with usb cable
To fix your issue just change your user agent in IE or Firefox. If you dont know how to do that just google change Useragent for IE or firefox.
Hopes this helps.
jordanishere said:
Well yesterday I was tethering like i've done every day on my device and I kept getting redirected to a tmobile webpage telling me to pay an extra $15 per month for tethering.
My T989 Sgsii is using CM7 and there is no tmobile tethering software on the device. Is anyone else able to tether? Im on a prepaid contract have have tethered every day for free since last december.
Im guessing tmobile is blocking my tethering on the network end, since all blocking/tethering management software has been removed from my phone.
Any advice? If i cant tether, i cant use up all 5 gigs i pay for, so ill probably get a cheaper plan or switch to straight talk.
Click to expand...
Click to collapse
Firefox doesn't work either...
jordanishere said:
So the issue has been solved.
I can tether on tmobiles network with no issues as long as i DONT use google chrome. Safari and Firefox access webpages no problem. Chrome has a user agent string which tmobile is able to see - and block by default on their network.
Click to expand...
Click to collapse
I'm going to try Safari, but they pounced on me when using Firefox.... :crying:

Sprint blocking inbound ports? Want to use VNC Server over 3G/4G

IMHO a data connection I'm paying for is a data connection. I'm peeved at the thought that Sprint is not allowing outside world inbound port connections to my device (S4). I have a technically challenged mother-in-law and it'd be great if I could VNC into her device to help her.
Droid VNC Server supposedly allows this over 3G/4G and even shows my external IP address, but all connections fail.
VMLite Server ( http://goo.gl/Q14Hq ) does work, but ONLY via local WiFi.
Anyone have experience with getting this to work over 3G/4G data connection or a way around this?
Lol dude, do you think your "ip adress" is unique on cellphone? Of course not...
You are paying to have DATA in your cellphone, not a internet service. Use wifi..
armyturtle said:
IMHO a data connection I'm paying for is a data connection. I'm peeved at the thought that Sprint is not allowing outside world inbound port connections to my device (S4). I have a technically challenged mother-in-law and it'd be great if I could VNC into her device to help her.
Droid VNC Server supposedly allows this over 3G/4G and even shows my external IP address, but all connections fail.
VMLite Server ( http://goo.gl/Q14Hq ) does work, but ONLY via local WiFi.
Anyone have experience with getting this to work over 3G/4G data connection or a way around this?
Click to expand...
Click to collapse
You're doing better then I am if you have it working at all. I'm on rooted MF9 and haven't found a working server yet. Only tried the free ones so far though. May have to give in and buy VMLite I reckon.
Have you thought about using a MDM to access her device. At my job we use SOTI Mobile Device Management (recommended by Samsung), with this software I am able to remote access and control any android, ios and Windows xp-Windows 8 on any network. I have tried 3G, LTE and Wifi. Our school currently has 670 Galaxy Note 10.1 and I can control each and every one. I can remote in to the device run programs, watch videos and push out Apps silently without having to have the student login into google services. Most companies will give you at least a 2 week trial to see if you like it and that is when you can remote in to their device.
pmcnano said:
Lol dude, do you think your "ip adress" is unique on cellphone? Of course not...
You are paying to have DATA in your cellphone, not a internet service. Use wifi..
Click to expand...
Click to collapse
"Lol dude", my old Epic 4G had a unique IP, as does my partner's current Epic Touch. (So did my Palm Pre.) But the Epics are/were Wimax, so it must be that Sprint got stingy when they moved to LTE.
Sucks for me. I know there are dynamic DNS updaters... anyone know of a persistent reverse SSH tunnel app?
armyturtle said:
IMHO a data connection I'm paying for is a data connection. I'm peeved at the thought that Sprint is not allowing outside world inbound port connections to my device (S4). I have a technically challenged mother-in-law and it'd be great if I could VNC into her device to help her.
Droid VNC Server supposedly allows this over 3G/4G and even shows my external IP address, but all connections fail.
VMLite Server ( http://goo.gl/Q14Hq ) does work, but ONLY via local WiFi.
Anyone have experience with getting this to work over 3G/4G data connection or a way around this?
Click to expand...
Click to collapse
Have you thought about TeamViewer? I use that from my mobile to log into my parents computer to help them.
Setup a VPN connection and use that to connect to what you want?
Sent via mobile

Categories

Resources