Re: Help on RRAS



Glad to hear that it worked for you.

"massmax" <massmax@xxxxxxxxxxx> wrote in message
news:1158566963.406120.61070@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
OK! It works! Changed the IP address to the second nic, removed the NAT
on RRAS.

Thanks everybody.

Max

Bill Grant ha scritto:

As Bob said, the RRAS router should not have its two NICs in the same IP
subnet. A router routes between subnets, so it doesn't work if both sides
are in the same subnet. (You use a bridge for that).

You will need to put the LAN machines in a different IP subnet from
the
"link" segment (ie the segment which links the RRAS router to the
firewall).

I would not have used NAT on this router. Surely the firewall is
already
doing NAT. With this setup you would be doing NAT twice. You can do
without
NAT as long as you add an extra route to the firewall to direct traffic
to
the RRAS router. (ie the firewall knows how to reach the internal subnet
via the RRAS router). eg

Internet
|
firewall (static route 192.168.252.0 255.255.255.0
192.168.250.240)
|
192.168.250.240 dg 192.168.250.241
RRAS router
192.168.252.1/24 dg blank
|
LAN machines
192.168.252.x/24 dg 192.168.252.1

"Robert L [MVP - Networking]" <noreply@xxxxxxxxxxx> wrote in message
news:%23rTLMiE2GHA.1588@xxxxxxxxxxxxxxxxxxxxxxx
You should not assign the same subnet in a multihomed computers. This
search
result may help,

Routing Don't add default gateway across disjoint networks Is it possible
both sites of the VPN using the same IP range Metric is the same for both
the remote ...
www.chicagotech.net/routing.htm


Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on
http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on
http://www.HowToNetworking.com
"massmax" <massmax@xxxxxxxxxxx> wrote in message
news:1158241413.983449.172480@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi all,

I have two LAN's to be managed.
I have (in the first LAN, assuming as LAN 1) a Win2003 server acting as
a router, using RRAS. I have two NIC on it, one direct to the internal
LAN, the second connected to a firewall (and from this to the internet)
installed and managed by my ISP.

The NIC A (internal LAN) has 192.168.250.101, no default gw.
The NIC B (internet) has 192.168.250.240, default gw: 192.168.250.241
(the firewall).
The firewall has 192.168.250.241
Clients are 192.168.250.x, default gw: 192.168.250.101
The NIC A is connected to a switch, together with the rest of LAN.
The NIC B and the firewall are connected to a second switch.
Clients are currently going in internet, no problems.

This is the configuration in the remote LAN (LAN 2):

The firewall, also installed and managed by my ISP, has
192.168.251.245.
Clients are 192.168.251.x default gw: 192.168.251.245.
No server acting as a router here; easier situation.
Clients here also use internet, no problems.

Well, I can connect from LAN 1 (the first one described above) to LAN
2, I can ping all IP's, use remote desktop etc.
But users working in LAN 2 can just ping the firewall (192.168.250.241)
and the NIC B (192.168.250.240) in the LAN 1, the devices that are on
the same switch.

I have configured RRAS as default wizard, using NAT as option; IP
routing is enabled. It works fine, because clients on LAN 1 can go to
internet and ping LAN 2.
I cannot understand why LAN 2 clients can't see LAN 1...

Any help would be appreciated.
Thanks.
Max



.



Relevant Pages

  • Re: [SLE] Firewall zones
    ... Looking at the firewall configuration in Yast, ... My network card is assigned its IP address by the router using DHCP. ... It connects to the LAN and to the router; the router in turn talks to the ... All the systems on the LAN are supposed to have the same firewall protection, ...
    (SuSE)
  • Re: How to stealth against ping/echo requests?
    ... I just started using the Online-Armor firewall. ... Some ports are even open. ... Are you behind a router? ... Every time it founds a new LAN, it asks if you want to trust it ...
    (comp.security.firewalls)
  • Re: Which home user router has a decent firewall inside it?
    ... Not for your LAN. ... The NAT translation on the router will ... NAT will inspect any packets if at all. ... public IP addresses in your LAN) and keep the firewall active. ...
    (comp.security.firewalls)
  • Re: Help on RRAS
    ... You will need to put the LAN machines in a different IP subnet from the ... "link" segment (ie the segment which links the RRAS router to the firewall). ...
    (microsoft.public.windows.server.networking)
  • Re: problem after SP1
    ... I'm using RRAS and I think I'm required to do so, because our server ... I think that our server is working as a router because we have 2 NICs ... So I think we need that RRAS, ... Install an external firewall and also install another router so then I ...
    (microsoft.public.windows.server.general)