Routing and Remote Access

From: Paul Hadfield (paul_at_anon.com)
Date: 02/01/05


Date: Tue, 1 Feb 2005 09:48:55 -0000

All,

How can I set up a Windows 2000 Server running Routing and Remote Access
service to be both a VPN server and implement NAT between a private network
and a public network?

For example:

We have two networks:

Net A = 172.16.0.0 mask 255.255.248.0
Net B = 192.168.2.128 mask 255.255.255.128

Our RRAS server has
NIC A = 172.16.1.1
NIC B = 192.168.2.181

Net A is considered the public network and Net B is considered the private
network.

We have quite a unique environment as we have clients on the private Net B
that fall in to two categories; 1) Net B clients that must establish a VPN
to Net A so that they have a 172.16.x.x IP address and are therefore
completely visible to network A, and 2) Net B clients that must use NAT to
be able to establish communications to any Net A server/IP, while remaing
behind NAT and as such having no route back (other than the route
established through NAT).

I have first set-up RRAS to provide the VPN functionality from Net B to Net
A and have this working perfectly. However, as soon as I install the NAT
Routing Protocol and add in both the Net A and Net B interfaces, routing
from the VPN to Net A ceases while NATing from Net B to Net A works fine.

It seems to be when I add the Net A (Public) network into NAT that the
problem occurs. As soon as I remove this single interface from NAT (leaving
the Net B interface there), NAT routing to Net A stops (as expected) and
then VPN routing to Net B resumes.

What am I doing wrong here???

Many thanks in advance for any suggestions,
Paul.



Relevant Pages

  • Re: NATting both ways
    ... on my "VPN" network off a PIX 525. ... We are using ip nat inside and ip nat outside on our inside and ... creates a VPN to another router on a remote network. ... crypto map CLIENTMAP client authentication list default ...
    (comp.dcom.sys.cisco)
  • Re: 2 servers and 3 nics = pain of my life
    ... "Since you are using 3rd party VPN, you need not only enable IP ... you may have a name resolution or routing issue. ... WINS server as VPN server DNS and Split Tunneling for VPN? ... How to Setup Windows, Network, VPN & Remote Access on ...
    (microsoft.public.windows.server.networking)
  • Re: RRAS for VPN, use an internal-only 192.168.x.x connection pool?
    ... Posting the routing table here may help. ... Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net ... I can only ping the server's two network ...
    (microsoft.public.win2000.ras_routing)
  • Re: Joining subnets
    ... Find a real news server. ... Kernel IP routing table ... By using nat, I do not have to worry about routing ... to the lan network from the servers. ...
    (comp.os.linux.networking)
  • Re: VPN problem! remote net using same ip range?
    ... Posting on MS newsgroup will benefit all readers and you may get more help. ... Networking, Internet, Routing, VPN, Anti-Virus, Tips & Troubleshooting on ... >>> of wisdom just based on knowing both remote and local network are using ...
    (microsoft.public.win2000.ras_routing)