Re: PPTP and NAT

From: Phillip Windell (_at_.)
Date: 07/26/04


Date: Mon, 26 Jul 2004 15:51:22 -0500

In theory yes.

There is no relationship between what happens "outside" the Tunnel vs what
happens "inside" the Tunnel. They are two separate and distinct logical
datastreams. One connection "creates" the Tunnel while the other runs
"inside" the Tunnel after it is created.

The session inside the Tunnel only sees the Client at one end and the PPTP
Server at the other end,...it does not "see" either Firewall or the Internet
because those exist "outside" the Tunnel. Likewise the Firewalls or the
Internet can not "see" what is inside the Tunnel nor act upon it.

-- 
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com
"TwistedPair" <twistedpair@mail.com> wrote in message
news:uUrnSB1cEHA.3616@TK2MSFTNGP10.phx.gbl...
> Hi All,
> Here is the scenario:
>
> PPTP Server -> Firewall -> Internet -> Firewall -> Client
> 192.168.x.x
> 192.168.y.y
>
> I want to be able to NAT PPTP from one internal net to another after it
had
> been NAT'ed to and from the Internet.  Can this protocol cope with this
> scenario?
>
> Thanks,
> Pair
>
>


Relevant Pages

  • IPSec tunneling problem
    ... We have a central office which is separated from the Internet with firewall running Linux 2.4 and FreeSWAN. ... I'm trying to create an IPSec tunnel to the central office from another small branch office, using FreeBSD 6.2 with it's integrated IPSec and ipsec-tools. ... The tunneling is generally working, both internal networks can see each other, but I'm having some problems with traffic originating from the FreeBSD firewall itself. ...
    (freebsd-net)
  • Re: attack alert on port 1080
    ... the firewall access to the Internet through a single IP address. ... it should only tunnel inside traffic out towards the Internet. ... masking their attacks as if they were coming from you. ... Windows personal firewall, ...
    (RedHat)
  • Re: Numpty VPN questions
    ... What kind of tunnel are we talking about and what do you need to do ... VPN tunnels are bi-directional. ... your Internet traffic is routed through your BB router as normal. ... monopoly is successfully blocking voip services like Skype. ...
    (uk.comp.sys.mac)
  • Re: LAN access while VPN is up
    ... > appear on the Internet, and no one else is going to know you are using it. ... >>the tunnel, and disconnects the tunnel if I mess with the routing table. ... Use the Netscreen to create a second local network ... segregate home/work. ...
    (comp.security.firewalls)
  • RE: [fw-wiz] L2L VPN redundancy for T1 link
    ... 'merger several Internet T1s to get the bandwidth desired and to do BGP ... The GRE tunnel passes the internal routing information between site ... A & B. Because the GRE Tunnel is passing thru the VPN Tunnel the firewall ...
    (Firewall-Wizards)