Re: Configuring NAT/Basic Firewall

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Bill Grant (not.available_at_online)
Date: 02/22/05


Date: Wed, 23 Feb 2005 09:41:32 +1100


   You have the PPPoE interface configured as the public interface for NAT.
All you need is to add you local NIC as a private interface for NAT. NAT
will then accept private traffic arriving at its local NIC and send the
translated packets out through the public interface.

    Check that the server's default route is out through the public
interface.

    What is the DNS setting on your LAN clients? If they use your local DNS
server, make sure it is set up to forward to a DNS server which can resolve
public URLs.

"Andy L" <Droid13@online.nospam> wrote in message
news:%23gGaIiSGFHA.3376@TK2MSFTNGP12.phx.gbl...
> Although I've configured NAT on several different kids of routers, I'm
> having trouble to understand the exact steps to take to configure this in
> Win2003 RRAS. I have a 2003 server that is multi-roled for a small branch
> office (DC, DNS, DHCP, APPLICATION, VPN) as part of a larger AD forest.
> The server currently has a single local area network connection.
>
> The RRAS, in addition to the standard interfaces, has a PPPoE interface
> running to the Internet (over the local area network to a DSL modem), and
> L2TP connections to another DC in the forest (connecting over the PPPoE
> interface to the Internet). What I'm trying to do is setup the NAT/Basic
> Firewall for the handful of local computers to allow them to access
> Internet. I setup a new interface on the NAT/Basic firewall, referenced
> the Internet (PPPoE) interface and set "Public interface / enable NAT".
> From here I'm not sure what else needs doing, as this doesn't seem to work
> by itself.
> Do I need to specify an address pool if I just want to hide the clients
> behind the RRAS PPPoE IP address?
> I did not turn on and Services and Ports, as these clients will be
> outbound connections only...
> I have not turned on any firewall or filters yet.
> I did not turn on any DHCP allocator or DNS proxy because the server
> already has the standard DNS and DHCP services running.
> Do I need to also define a NAT interface on the Internal or Local Area
> interface as well and define it as "Private" for this to work?
> The server is the default gateway for the clients, no client static
> routes. I have set the necessary RRAS static routes and the L2TP
> connection to the other office works great, but any RRAS routes that send
> users out the PPPoE connection go unanswered (I assume NAT is not doing
> it's stuff).
>
> ?
>



Relevant Pages

  • Re: NAT without DHCP? (w2k3)
    ... My guess is that you have not configured the public interface correctly. ... How does your server connect to the Internet? ... set to the private address of the NAT machine? ...
    (microsoft.public.windows.server.networking)
  • Re: cisco static nat
    ... so your setup would route traffic looking for a server at 85.86.87.2 to ... ip nat inside source route-map nonat interface Dialer0 overload ... ip nat inside source static 192.168.1.1 85.86.87.1 route-map nonat ... no ip directed-broadcast ...
    (microsoft.public.windows.server.networking)
  • Re: FIREBOX II IP CONFIGURATION
    ... If your web server is in the DMZ at 192.168.3.100 you need to create ... ANY traffic from the Trusted to the Optional network, ... The firewall will not NAT traffic from inside the ... Trusted interface out through the External Interface and then back into ...
    (comp.security.firewalls)
  • Re: NAT without DHCP? (w2k3)
    ... How does your server connect to the Internet? ... I also enabled NAT tracing - may be this can help? ... interface 65543 not found ...
    (microsoft.public.windows.server.networking)
  • Re: NAT without DHCP? (w2k3)
    ... the private address of the NAT machine? ... I also enabled NAT tracing - may be this can help? ... right-click on my public interface, I see "Address pool" tab but it ... server, just leave the area for IP addresses blank", what do you ...
    (microsoft.public.windows.server.networking)