Re: VPN not working when client behind another firewall

From: Mark Richards (mark.richards_at_expw.co.uk)
Date: 08/05/04


Date: Thu, 5 Aug 2004 06:48:31 -0700

Please excuse my ignorance Franz!

We have a Thomson / Speedtouch 510 and a Symantec 200
Firewall Appliance. I believe that these are configured
correctly as we have used VPN successfully before. The
difference now is that we have guys trying to VPN from
behind another firewall. However, other guys (not from
our company) are able to VPN into their own server from
behind this same firewall. So it would seem that the
other firewall is also configured correctly.

Regards
Mark

>-----Original Message-----
>Mark,
>
>It's not "port 47". It's "GRE-protocol 47".
>Your router need to pass it through. You can close port
47. Maybe there
>is setting which enables VPM pass-thru in general.
>What type of router is it?
>
>Franz
>
>
>"Mark Richards" <mark.richards@expw.co.uk> schrieb im
Newsbeitrag
>news:07bf01c47acd$82f5d5d0$a401280a@phx.gbl...
>> Hi Marina,
>>
>> OK - so our VPN is working fine when the client is NOT
>> behind another firewall - and our port 47 is definately
>> open on our firewall.
>>
>> Do we need to make sure that the other firewall has port
>> 47 open too?
>>
>> Regards
>> Mark
>>
>>
>>
>> >-----Original Message-----
>> >Hi Mark,
>> >
>> >Error 721 means that the router is not passing through
>> the GRE-protocol 47,
>> >which is needed for VPN.
>> >Check the documentation of the router/firewall or the
>> website for firmware
>> >upgrade or even downgrade.
>> >
>> >--
>> >Regards,
>> >
>> >Marina
>> >Microsoft SBS-MVP
>> >
>> >"Mark Richards" <mark.richards@expw.co.uk> schreef in
>> bericht
>> >news:c1da01c47a30$9def6fb0$a301280a@phx.gbl...
>> >> Hi,
>> >>
>> >> VPN is not working for our client PCs currently
trying
>> to
>> >> connect from behind another firewall. The
>> administrators
>> >> of the "other" firewall have opened up ports 1721,
1723
>> >> and 500, 1701, but our PCs get the following error
after
>> >> the dialog box says "Checking password":
>> >>
>> >> "The remote computer did not respond. For further
>> >> assistance, click More Info or search Help and
Support
>> >> Center for this error number. (Error 721) For
customized
>> >> troubleshooting information for this connection,
click
>> >> Help.
>> >> Pausing before reconnecting (3 seconds)..."
>> >>
>> >> We've tried opening ALL ports on our firewall but to
no
>> >> avail. I am also unable to telnet to any of the
ports,
>> >> although I may be attempting to do this incorrectly.
>> >>
>> >> Any thoughts / help would be much appreciated.
>> >>
>> >> Regards
>> >>
>> >> Mark
>> >
>> >
>> >.
>> >
>
>.
>



Relevant Pages

  • Re: Routers Firewall
    ... I ask him do you have a firewall and he says yes. ... I still have an IDS/firewall on all my machines behind the router. ... > to connect to a port your public IP address the router would reject the ... > An open port on the router could be connected to a service running on the ...
    (comp.security.firewalls)
  • Re: Possible Mail Relay or just new usages of returned mail by spammers
    ... If you have ANY type of firewall, be it a NAT router or true firewall ... ISA can be used in conjunction with the router/firewall, but if you do, you ... to be done twice...once in ISA, and once in the router to port forward to ...
    (microsoft.public.windows.server.sbs)
  • Re: Home firewall Hits
    ... >Port 162 with a UDP message. ... than theres nothing blocking access from the internet to your router. ... >Subject: Home firewall Hits ... >simplify the management and deployment of PGP and reduce overall PGP costs ...
    (Security-Basics)
  • Re: Routers Firewall
    ... > indicates that it has firewall technology, then the router doesn't have a ... What your router does have is NAT. ... ZA is a fine product which will protect a computer ... Port 80 is the WEB access port and port 21 is the FTP ...
    (comp.security.firewalls)
  • Re: VPN Setup Q
    ... As the firewall is built in the router, ... will be better to consult the router manufacture to see if it supports VPN ... |> 2004 as the firewall server, I believe the below article in Microsoft ...
    (microsoft.public.win2000.ras_routing)