Re: Ghost IP assignmnet

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance




"Bill Grant" <not.available@online> wrote in message news:OtEIY4N3FHA.3600@xxxxxxxxxxxxxxxxxxxxxxx
Why? Lots of people with simple one segment LANs prefer to use the same IP subnet for their remotes and let RRAS get a pool of addresses from DHCP. This has been the default setup since the early days of RAS in NT. The remote users then have access to all machines on the LAN by default (because the server acts as a proxy for the remotes). It is only a problem if the RRAS server is a DC.

If you put the remote users in their own subnet (which I usually do, I admit) you need to enable IP routing on the RRAS server. You may also need to modify your LAN routing to allow the remotes full access to the LAN machines on a routed LAN.

If you read the documentation you will see there is a lot said about the advantages and disadvantages of using on-subnet or off-subnet addresses for remotes.

ah ha,

In fact, I finally started to use VPN because my DSL router, supports the correct VPN pass-through protocoals (other than passing TCP port 1723).

Happy to meet you as an expert on this. Reading all the docs for all services on Windows server does not make sense...

.



Relevant Pages

  • Re: Configuration of VPN solutions behind NAT
    ... The RRAS server just acts as a proxy on the LAN for ... > the remotes. ... > LAN machines by IP? ...
    (microsoft.public.win2000.ras_routing)
  • Re: 2003 SP1 RRAS problem
    ... > and remotes clients and the remote RRAS SP1 server). ... > LAN IP Address 192.168.1.50/24 ... > Out of the local RRAS server Internet NIC - OK ...
    (microsoft.public.win2000.ras_routing)
  • Re: Set up IPsec...
    ... > you have it configured on a rras server, then it could filter just lan and ... > ipsec filter will be processed according to the policy as the non rras ...
    (microsoft.public.win2000.security)
  • Re: Windows 2000 / Windows 2003 VPN setup questions.
    ... same subnet as the LAN machines, the remotes will be able to connect to LAN ... Note that VPN only gives you IP connection. ... You would need to configure port filtering, or run a third party firewall. ...
    (microsoft.public.win2000.ras_routing)
  • Re: Ghost IP assignmnet
    ... IP subnet for their remotes and let RRAS get a pool of addresses from DHCP. ... RRAS server is a DC. ... to modify your LAN routing to allow the remotes full access to the LAN ...
    (microsoft.public.win2000.ras_routing)