Re: VPN and Ports
- From: "Richard Hrubizna" <hrubizna@xxxxxxx>
- Date: Wed, 8 Mar 2006 18:37:16 +0100
I'm using L2TP/IPSEC VPN and not PPTP VPN.
Therefore ports 500,4500,1701,and protocol 50.
And it is not true that source ports are always random espescialy with
L2TP/IPSEC.
"Phillip Windell" <@.> wrote in message
news:egFr70sQGHA.2816@xxxxxxxxxxxxxxxxxxxxxxx
"Richard Hrubizna" <hrubizna@xxxxxxx> wrote in message
news:%23dIWkNsQGHA.4952@xxxxxxxxxxxxxxxxxxxxxxx
Hi all,are
my question is about ports. I had set up a MsWin2003 VPN server and
configured firewall.
My firewall and ports :
Client Ports <-> VPN Server Ports
UDP 500 <-> UDP 500
UDP 4500 <-> UDP 4500
UDP 1701 <-> UDP 1701
Protocol 50 <-> Protocol 50
VPN is working fine. But several our users are behind some routers that
changing theirs source ports.
Source ports are always random and are different with every connection,
that
isn't something you can do anything about. You can not do things the way
you are trying.
Assuming the users are on the Outside, the VPN Server is on the
Inside,..and
the firewall is between them....
You have to use Static NAT on the firewall to make the VPN Server
available
to the users. You also need to enable "VPN Passthrough" or whatever your
particular brand of router calls it, (some can't do it at all)...without
that it will not pass the GRE packets (Protocol 47, not 50). The Static
NAT
should be done with 1701 unless your particular firewall automatically
takes
care of that when you enable "VPN Passthrough". Not all firewall devices
are capable of doing this,...and I also see no point in fooling with 500
and
4500 or Protocol 50.
The bottom line it that you have to read the Docs for your Firewall and do
it *their way* and your firewall may limit your choices by its design.
--
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com
.
- Follow-Ups:
- Re: VPN and Ports
- From: Ace Fekay [MVP]
- Re: VPN and Ports
- References:
- VPN and Ports
- From: Richard Hrubizna
- VPN and Ports
- Prev by Date: Re: Server login via LAN...
- Next by Date: Re: Wireless Radius Clients
- Previous by thread: VPN and Ports
- Next by thread: Re: VPN and Ports
- Index(es):
Relevant Pages
|
Loading