Re: W2K VPN Setup
From: Bill Grant (not.available_at_online)
Date: 01/25/05
- Next message: Bill Grant: "Re: LAN-to-LAN Routing"
- Previous message: Mark: "Re: W2K VPN Setup"
- In reply to: Mark: "Re: W2K VPN Setup"
- Next in thread: Mark: "Re: W2K VPN Setup"
- Reply: Mark: "Re: W2K VPN Setup"
- Messages sorted by: [ date ] [ thread ]
Date: Wed, 26 Jan 2005 09:21:46 +1100
Just a note concerning ports and protocols.
GRE is as IP protocol, just like TCP or UDP. TCP is protocol 6, UDP is 17
and GRE is 47. So it can be allowed or blocked by a firewall/router. It
cannot be forwarded, because it is not a port.
When you set up a PPTP connection, PPTP controls the setup and
maintainence of the PPTP tunnel. So if you forward TCP port 1723 from your
router to your server, you extend the tunnel endpoint to the server.
The actual packet containing the encrypted data has a GRE header with a
public IP on the front. If your router (or anything else in the path) blocks
GRE, no data is transferred, and the connection fails.
"Mark" <not.available@online> wrote in message
news:%23XS6Q$xAFHA.936@TK2MSFTNGP12.phx.gbl...
> Guys,
>
> OK.. I FINALLY found out what I belive the problem is. Seems my router
> doesn't do a very good job with VPN (after at 45 min discussin with
> Linksys) so I will have to start looking arround.
>
> Thanks for all the help!
>
> Mark
>
>
> "Mark" <not.available@online> wrote in message
> news:eJs%23DpuAFHA.2572@tk2msftngp13.phx.gbl...
>> Bill,
>>
>> Thanks for the help.
>>
>> I am able to access the VPN through the LAN with no problems. I have
>> configured the router to forward port (PPTP 1723 correct??) to the server
>> and I get at 721 error. Everything I have read talk about GRE protocol
>> 47. I would suspect that my firewall is causing the problem (Linksys
>> BEFVP41). I can't seem to find out how to configure this on the router
>> anywhere. I understand that this is not a "port protocol". Is this
>> correct? Then how do you allow it?
>>
>> Thanks again,
>> Mark
>>
>> "Bill Grant" <not.available@online> wrote in message
>> news:eB4DBhBAFHA.2540@TK2MSFTNGP09.phx.gbl...
>>> If you only have one NIC in the server, do not try to use any of the
>>> VPN wizards. Simply configure your server as a remote access server.
>>> This will set up the miniports you need for VPN.
>>>
>>> Test your config by making a VPN connection to the server from one of
>>> your LAN clients. (VPN works fine over Ethernet).
>>>
>>> When this works, try forwarding tcp port 1723 from your router to the
>>> server's IP address. Now try making a VPN connection from a remote
>>> machine to the router's public IP. The port forwarding will extend the
>>> connection to the server through its LAN NIC.
>>>
>>> "Mark" <not.available@online> wrote in message
>>> news:OdTLIb9$EHA.600@TK2MSFTNGP09.phx.gbl...
>>>> Hi,
>>>>
>>>> Sorry to repost this to the group, but I thought I was on the right
>>>> tack and
>>>> home free. Seems I am not.
>>>>
>>>> Hello,
>>>>
>>>> I am trying to setup a VPN on my server.
>>>>
>>>> I start to run "Configure and Enable Routing and Remote Access" I run
>>>> into a
>>>> snag. As I go through the screens I come to a place to "Specify the
>>>> Internet Connection that the Server Uses". Here I show my LAN
>>>> connection
>>>> (this is the NIC in the server.. it has two IP addresses) and another
>>>> line
>>>> showing <No Internet Connection>. When I select the LAN card I get
>>>> "You
>>>> have chosen the last available connection as the internet. A VPN Server
>>>> requires one connection to be used as the private network connection"
>>>> I
>>>> can't seem to go any further. If I select "no internet connection" I
>>>> can't
>>>> seem to get anything to work.
>>>>
>>>> I can browse from the server to the net just fine. I also have a
>>>> router in
>>>> place where the gateway is 192.168.0.1...
>>>>
>>>> Thanks for any help of suggestions!
>>>>
>>>>
>>>>
>>>>
>>>
>>>
>>
>>
>
>
- Next message: Bill Grant: "Re: LAN-to-LAN Routing"
- Previous message: Mark: "Re: W2K VPN Setup"
- In reply to: Mark: "Re: W2K VPN Setup"
- Next in thread: Mark: "Re: W2K VPN Setup"
- Reply: Mark: "Re: W2K VPN Setup"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|