Win2k3 single NIC VPN routing problem

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hi,

I have an all-in-one standalone Win2k3 server (DNS, WINS, DHCP, no-AD, Fileserver + Apache + other apps) that i've got RRAS installed on and setup as a home VPN server. The server is an old laptop with a built-in *single* NIC. I travel in various parts of the middle east where internet access is more restricted and governments (or hotels) block a variety of protocols and websites (not just for anti-Pr0n.. business stuff too - e.g. anywhere in Israel) and I want to be able to VPN connect to home, route all of my traffic through the tunnel, and thus bypass some of the blocking hassles whenever possible.

I have a Netgear ADSL firewall/modem box that uses PAT mappings to direct the required VPN ports from my single static public IP to the VPN/Win2k3 server. I can connect remotely to the server over PPTP with no problems and my VPN client is given an IP address on the same subnet as the VPN server. I have a small 20-IP DHCP range for LAN connected clients (other laptops and the odd server). The VPN server uses another small group of addresses in the same subnet. When VPN connected I can access any resources on the Win2k3 server, ping it, resolve DNS names via the server.. but I can't access any other network resources (eg. ping the Netgear router) or anything on the internet.

My VPN client is the native one built into OSX 10.4. This works fine at a whole bunch of other places, so while it's not a Windows client, it's not assumed to be part of the problem.

I strongly suspect this is a routing issue.. which is where my knowledge falls short.

This is the routing table on the VPN server with my client dialled in:

IPv4 Route Table
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x10002 ...00 53 45 00 00 00 ...... WAN (PPP/SLIP) Interface
0x10003 ...00 d0 59 0c 80 10 ...... Intel(R) PRO/100+ MiniPCI - SecuRemote Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.16.1 192.168.16.250 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.16.0 255.255.255.0 192.168.16.250 192.168.16.250 20
192.168.16.100 255.255.255.255 127.0.0.1 127.0.0.1 50
192.168.16.102 255.255.255.255 192.168.16.100 192.168.16.100 1
192.168.16.250 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.16.255 255.255.255.255 192.168.16.250 192.168.16.250 20
207.237.44.80 255.255.255.255 192.168.16.1 192.168.16.250 20
224.0.0.0 240.0.0.0 192.168.16.250 192.168.16.250 20
255.255.255.255 255.255.255.255 192.168.16.250 192.168.16.250 1
Default Gateway: 192.168.16.1
===========================================================================
Persistent Routes:
None


Other info:

Netgear Router = 192.168.16.1
VPN server = 192.168.16.250
My VPN client IP = 192.168.16.102
My remote IP = 207.237.44.80
VPN DHCP range = 192.168.16.100 thru 109 (my client = 102)

Any ideas?

Christian

.



Relevant Pages

  • RE: Route added by RRAS that overrides local LAN route on NIC
    ... I am using SBS as the VPN server. ... The route I am speaking of is the route to local LAN that is put in the ... After the RAS client connects there is another route added so the two ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN
    ... Run CEICW on SBS ... You have to rerun the CEICW to make sure your SBS 2003 server have right ... Click Next, click Enable Remote Access, click to select the VPN Access ... Please ensure the VPN client computers' DNS and WINS are your SBS ...
    (microsoft.public.windows.server.sbs)
  • Re: DNS and NetBIOS names not resolving over a PPTP VPN using RRAS
    ... by all VPN clients. ... What if the VPN server has more than one network ... I have a separate DHCP server on the remote ... To assign the DNS and WINS to a VPN client for name resolution, ...
    (microsoft.public.windows.server.networking)
  • Re: Use to be able to VPN/RDP. After installing SBS2003, can only VPN
    ... disconnected the VPN since it's a) only showing one IP address for the nic. ... server and it where you are getting VPN authenticated, IP address, DNS ... With our PPTP connection while you were connected the routing table would ... The 1.1.1.1 route is used in order to keep the physical connection for the ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN
    ... Server 2003 SP2 or the Scalable Networking Pack ... This newsgroup only focuses on SBS technical issues. ... | Subject: RE: VPN ... Please ensure the VPN client computers' DNS and WINS are your SBS ...
    (microsoft.public.windows.server.sbs)