Re: Error 720 connecting to server via VPN



In article <EA0A618B-4EF3-4335-8E82-0FCDB58DA631@xxxxxxxxxxxxx>,
CraigHughes@xxxxxxxxxxxxxxxxxxxxxxxxx says...
Port 1723 (PPTP) is allowed in my router for any WAN users to the server.

I've not got a rule for GRE (Port 43 I think) as I read it was a IP protocol
rather than TCP or UDP. My router only allows TCP, UDP or TCP/UDP. Should
I create a rule for port 43 as TCP/UDP?

My router is Netgear. I can't see any existing rule I can select for GRE or
port 43.

GRE is not a port, you can't forward it.

Many home/residential routers, which are not real firewalls, don't
support more than 2 PPTP sessions and some don't properly forward GRE.

720 is a common GRE error.

Some vendors have a "work around" of forwarding TCP 43 inbound, others
forward UDP 43, still others forward TCP/UDP 43 inbound....

Since Netgear "Routers" are not firewalls, why not buy a firewall to
properly protect your network and to PPTP into the firewall instead of
the server.

Also, you mentioned that you allow HTTP (TCP 80) - why, that's a serious
risk.

--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@xxxxxxxxxx (remove 999 for proper email address)
.



Relevant Pages

  • Re: Open port PIX 501
    ... :i can't open the port in my PIX. ... :I need open the port 1000 to point to the IP 10.254.254.222. ... in practice only DNS servers doing zone transfers need tcp. ... of UDP, it would be a highly unusual client which did not stick ...
    (comp.dcom.sys.cisco)
  • RE: DNS Records
    ... tcp>1023 53 Client queries with long replies ... On other client types, ... if you lock down all but port ... a client queries an initial server from an unreserved port number to UDP ...
    (Security-Basics)
  • Windows Update Scrammed My Server
    ... The Simple TCP/IP Services could not find the TCP Echo port. ... The Simple TCP/IP Services could not find the UDP Echo port. ...
    (microsoft.public.windowsupdate)
  • Re: Settings for Mercenaries and MS MN500 Wireless Router
    ... When you type "27960-27960 tcp and udp" exactly where are those entries ... Enable Description Outbound Port Trigger Type Inbound Port Public Type ... > inside the game. ...
    (microsoft.public.games)
  • Re: using routers ACL to substitute firewall
    ... > You can handle TCP responses with a statement such as ... > systems have any programs that dynamically allocate UDP source ... > packets with a UDP source port of 137, ... > For incoming connections, UDP is again a problem, in that UDP ...
    (comp.security.misc)