Re: Help setting VPN (RRAS) on W2K Advanced Server behind a router



Hi,

Yes the router already provides a VPN tunnel, through a security
policy\certificate on the remote computers , all I want to do is setup a
remote access on the server and be able to login or authenticate after the
bootup and certificate activation so I can see the shared drives and other
resources.

Regards,
Mauro


"globemast" wrote:

Mauro, when you say secure tunnel do you mean VPN...because VPN is a secure
tunnel. And if your router provides VPN server functionality then there is no
reason you should setup you Windows 2003 server as a VPN server.

Robert, is it possible you make a small HowTo for Win2K Adv Server as the
one you mentioned above?

Thank you very much for your help so far.

"Mauro" wrote:

Thanks
Do I choose "LAN Routing" or "VPN access" if my router already provides the
secure tunnel from one network to another?

Regards,
Mauro

"Robert L [MVP - Networking]" wrote:

OK, it is the time to create a how to with screen print. I just published it in How to setup Windows 2003 as VPN server with one NIC - http://www.howtonetworking.com/VPN/2003vpn11.htm

Please post back with the result or any comments on the how to.

Thanks.

Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
"Mauro" <Mauro@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:4734910F-2486-4A0A-9084-3743AE795A62@xxxxxxxxxxxxxxxx
Hi Robert,

Thanks for confirming what I have been seeing.

The question is, HOW do you set it up then if during the configuration of
the RRAS it asks which NIC is the internet side? Is is okay to give the
other nic any IP and not even connecting it?
I have been searching for a step by step on how to set this up using one NIC
but can't find anything that completely describes the setup.

Any help would be appreciated, again Thanks for your time.

Regards,
Mauro

"Robert L [MVP - Networking]" wrote:

> Again, you don't need to have two NICs to setup RRAS/VPN if it is behind a router. If for some reasons, you must have multihomed server and enable NAT, you must configure it carefully, especially the routing and name resolution. Otherwise, you may have a connectivity issue.
>
> Bob Lin, MS-MVP, MCSE & CNE
> Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
> How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
> "Mauro" <Mauro@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:DEE0A3ED-F312-41CC-AC37-F265DC67F559@xxxxxxxxxxxxxxxx
> Hi,
>
> I don't know about that howto. I am also in the same situation one server
> that I want to use VPN with, multiple NIC but all behind a Nat router.
>
> The mistake I made was to use the main server IP as the internet connect,
> once I connected it threw everybody off the network.
>
> Prior to this I tried another test on another server with a made up private
> IP on one nic which wasn't even connected, and the server IP as the network
> connection.
> When I made the remote VPN connect I went straight to lan ip because my
> router can handle the VPN directly and I was able to authenticate directly to
> the server.
>
> Without the remote access and routing setup on the server I can't do
> anything, what setup should I use to get this working?
>
> Regards,
> mauro
>
>
> "Robert L [MVP - Networking]" wrote:
>
> > In this case, the server can be just one NIC. This how to may help,
> >
> > VPN SetupHow to setup VPN on w2k server with one NIC ... To setup a Windows 2000 server for VPN, open Routing and Remote Access console in the Administrative Tools ...
> > www.chicagotech.net/vpnsetup.htm
> >
> >
> > Bob Lin, MS-MVP, MCSE & CNE
> > Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
> > How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
> > "globemast" <globemast@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:13491A73-732A-42A4-84DD-060809CE0FFC@xxxxxxxxxxxxxxxx
> > Hello,
> >
> > I currently want to setup my W2K Adv. Server as a VPN Server using RRAS.
> >
> > From what i have read so far, the server machine has to have 2 ethernet
> > cards, on for the local network and one connected to the Internet.
> >
> > The LAN ethernet must be assigned static IP's within the LAN (i.e
> > 192.168.1.10) and the WAN ethernet must be given the public IP assigned by
> > the ISP. This is all clear to me.
> >
> > But my case is a bit different. My W2K server is behind and ADSL
> > router-modem which is assigned a public IP from the ISP. Both ethernet cards
> > on the server are thus assigned private (LAN) IP's.
> >
> > What should be the configuration of each ethernet card, assuming ETH1 should
> > be for the LAN and ETH2 should be for the WAN.
> >
> > P.S. My network (LAN) has several machines which get their IP's from the
> > ADSL router. IP's are in the range of 192.168.1.xxx
> >
> > Thank you in advanced
.



Relevant Pages

  • Re: How to configure for Two different IP subnets
    ... It can even be done using the DC as the router (otherwise Small Business ... Server wouldn't work) but it is not simple or straightforward. ... doesn't work using the default setup wizard in Server 2003. ... more difficult if you also configure the DC as a VPN server. ...
    (microsoft.public.windows.server.networking)
  • Re: How to configure for Two different IP subnets
    ... Active Directory will go haywire in a setup like that. ... AD integrates with the local DNS, so you cannot use the DNS at your ISP ... With Server 2003 Standard ... for its internal interface (ie the VPN endpoint). ...
    (microsoft.public.windows.server.networking)
  • Re: VPN Advice...do I need a purchased static ip address on the external interface?
    ... >> Server then that server must have a been assigned a purchased static IP ... >> if I was to try and use Windows 2000 SBS as the server for the VPN, ... >> If I used a router instead then the router would have this purchased IP ... > supports dynamic dns, then users connect to the dynamic dns name and ...
    (comp.dcom.vpn)
  • >>>> SETUP VPN <<<<
    ... Vpn End Points Setup Vista ... Setup Vpn Windows Server 2003 ... Setup Vpn With Zyxel Prestige Router ...
    (rec.radio.shortwave)
  • Re: Specified network name is no longer available
    ... ISP says nothing wrong with the connection.. ... Also it works just fine if the guys make a dial up VPN connection to ... On it's own the SBS2003 server worked well, ... So Site B was setup. ...
    (microsoft.public.windows.server.sbs)

Loading