Re: VPN Setup



Ok, so what is an A record?

"Cris Hanna (SBS-MVP)" wrote:

well I don't know who your ISP is, but if this is a business and you need reliable VPN, you need a static Public IP and then you should have an A record on a DNS server which points to the public static IP that business connections usually have.

I also believe you should only have one method of VPN. either the standard windows or Symantec device.
I believe you should turn off DCHP on the Symantec Device and configure DCHP on the SBS server. SBS should also be providing internal DNS and WINS.

--
Cris Hanna [SBS-MVP]
--------------------------------------
Please do not respond directly to me, but only post in the newsgroup so all can take advantage
"Johnt" <Johnt@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:E9BB9881-97AD-4112-9007-C0CC2B7577D4@xxxxxxxxxxxxxxxx
The modem is provided by the ISP and the account is dynamic. If I want to
have static IP's I need a different account, therefore I am considering the
modem Dynamic for the sake of this discussion.

Although the IP's on the server and the router do not change (static). I
believe that basically you could say that the router and the server are not
truly "static" as the ISP does not know they exist and the IP's were just
generated by me. This is in fact part of my question.The internal IP for the
server and the router are the standard 192.168.xx.xx. The external IP for the
router was selected by the modem and is now "static" perse'.
"Cris Hanna (SBS-MVP)" wrote:

> why do you consider the DLink DSL modem to be "dynamic"
>
>
> --
> Cris Hanna [SBS-MVP]
> --------------------------------------
> Please do not respond directly to me, but only post in the newsgroup so all can take advantage
> "Johnt" <Johnt@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:D505049D-B787-4E70-A423-33F4D9F7E638@xxxxxxxxxxxxxxxx
> Internet - D-Link ADSL Modem (dynamic)- Symantec 300 Series Router (Static
> External and Internal, currently providing DHCP)- SBS 2003 NIC (Static
> Internal).
>
> "Cris Hanna (SBS-MVP)" wrote:
>
> > Well you mentioned that you have a D-Link router in there too, so where does that connect to?
> > --
> > Cris Hanna [SBS-MVP]
> > --------------------------------------
> > Please do not respond directly to me, but only post in the newsgroup so all can take advantage
> > "Johnt" <Johnt@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:3C7283F3-EDAC-41C9-8116-95483BEA6CF7@xxxxxxxxxxxxxxxx
> > Only 1 nic. The only purpose of this server is for VPN.
> >
> > The only public static IP address I have is on the symantec router. Users
> > were able to log on to the sever using the Symatec VPN client but I have
> > users that are at sites where the isp is satellite based and the symantec
> > client won't work. I'm told that the windows client will. To accomodate this
> > all I did was create the pass thru rule on the router. Do I have a security
> > issue if I get rid of the router and get a static IP for the server from my
> > ISP??
> >
> >
> >
> > "Cris Hanna (SBS-MVP)" wrote:
> >
> > > Well to be blunt John, you are completely setup incorrectly
> > >
> > > DHCP should be shut off on all devices except the SBS Server, it should be your DHCP, DNS, and WINS server, period.
> > >
> > > 1. How many nics in your server?
> > > 2. What are they assigned to?
> > > 3. Do you have a public, static IP address, and if so, what device is this address assigned to?
> > >
> > > We will eventually get to where they can VPN in, but gotta get all the ducks lined up
> > >
> > > --
> > > Cris Hanna [SBS-MVP]
> > > --------------------------------------
> > > Please do not respond directly to me, but only post in the newsgroup so all can take advantage
> > > "Johnt" <Johnt@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:A4DB86EB-4CE0-4249-8FCA-2AC88FCC1C0D@xxxxxxxxxxxxxxxx
> > > I have an SBS 2003 and am trying to get a VPN setup. I have a D-Link router
> > > that supplies dynamic IP Addresses but between there and the server I have a
> > > Symantec Router. The router is being used as a DHCP and is providing IP's for
> > > the internal network. The router has a static external address assigned to
> > > it. I aslo have a domain registered but it is currently just used for third
> > > party provided email.
> > >
> > > Clients are trying to logon with the Windows VPN client and I have created
> > > the pass-thru rule on the router. In the VPN Server name I have used the
> > > external static IP on the router, is this right? I have not registered this
> > > number with my ISP. Do I need to do this or have a static IP assigned from my
> > > ISP for the server.
> > >
> > > Thanks in advance
.



Relevant Pages

  • Re: VPN Advice...do I need a purchased static ip address on the external interface?
    ... >> Server then that server must have a been assigned a purchased static IP ... >> if I was to try and use Windows 2000 SBS as the server for the VPN, ... >> If I used a router instead then the router would have this purchased IP ... > supports dynamic dns, then users connect to the dynamic dns name and ...
    (comp.dcom.vpn)
  • Re: vpn probl
    ... not to vpn server, so when workstations needed to reply to the ping requests ... they were trying to respond though their gateway that was the adsl router ... static route 172.16.x..x pointing to vpn remote router in rras, ...
    (microsoft.public.windows.server.networking)
  • Re: Problem
    ... telephoned the office where the server was and asked her to re-boot the ... Once I saw the config of the VPN router there, I knew what to do on the ... on the remote site and see if they have the connection manager installed. ...
    (microsoft.public.windows.server.sbs)
  • Re: Please Help Site-To-Site without ISA
    ... You can configure more than one site to site VPN connection on the ... You set up a new demand-dial interface and configure a new site to ... public IP of the VPN server at the second site on the front. ... to router connection. ...
    (microsoft.public.windows.server.networking)
  • Re: vpn probl
    ... fact that you have ISA server at one end and not at the other. ... site to site link in ISA creates a file to configure the "answering" router. ... hub (as all other sites have a VPN link to the hub). ... > static routes redirecting the their needs. ...
    (microsoft.public.windows.server.networking)

Loading