Re: Connection Wizard - VPN Problem



-Draino- wrote:
Hi all,

I am getting an error with the "connect to sbs" (I think it's the connection
wizard that I downloaded from the RWW interface) When I try to connect it's
fails. I see it's trying to connect with a vpn connection but I get this
error:

Unable to establish the VPN connection. The VPN server may be unreachable,
or security parameters may not be configured properly for this connection.
(Error 800) For customized troubleshooting information for this connection,
click Help

Help doesn't provide much help :)

Any suggestions


What the others suggest is basically correct, but routers differ considerably. What you want to do is to use the PPTP type of VPN, which requires TCP port 1723 and IP protocol 47 (GRE) to be forwarded to the server. Many routers will have a single facility, called 'PPTP service' or 'PPTP passthrough' or something similar.

More advanced routers can accept PPTP connections themselves, which is not what you want here. If there are multiple PPTP entries, you want 'passthrough'. You do also need to have requested VPN in both the CEICW and RRAS wizards, and users need to be in the Mobile Users security group.

You are now also making a direct TCP/IP network connection, which RWW doesn't do. The usual routing rule that all network addresses (ranges) must be different applies here. If the SBS LAN is using 192.168.16.x addresses, for example, any remote client must not use this range on any of its own network interfaces.

There are two stages in making the connection, and your client software will report success after just the first stage. You get error 800 if the first stage doesn't complete, which means the TCP/1723 connection wasn't made. The usual error if that works but the GRE tunnel is not made is 723, after a timeout, but there are other possibilities.

Finally, VPN is the right answer to a very limited range of questions, as it offers a significant security risk to the network. If a user has a laptop which is regularly used on the LAN and remotely, then VPN allows him to see the same network environment, although much more slowly through the VPN. Almost all other purposes for which VPN is used can be achieved more securely by other means.

There is also a group of applications, particularly the low-end accounting packages, which should *not* be used over a network prone to interruptions, which VPN is. The use of a split Access database is also a bad idea, the backend data file being very fragile and easily broken by a disconnection.
.



Relevant Pages

  • Re: OT By a mile in parts comments on Viet Nam
    ... check bank accouts etc etc whilst away but is safe to do so over wireless and using the hotel network.. ... you should regard your connection as insecure and use some ... form of encryption to protect your passwords and privacy. ... My recommendation would be to set up a VPN endpoint in the UK that you ...
    (uk.comp.sys.mac)
  • Re: OT By a mile in parts comments on Viet Nam
    ... compared with the risks already inherent in the average hotel network. ... you should regard your connection as insecure and use some ... form of encryption to protect your passwords and privacy. ... My recommendation would be to set up a VPN endpoint in the UK that you ...
    (uk.comp.sys.mac)
  • Re: Remote Client Configuration
    ... > remote computer to SBS 2003 domain via VPN connection after the remote ... > connection when user logon to the remote computer. ... I dont think that the Network Configuration website would work to connect to ... "The Small Business Server Network Configuration Wizard ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN issues on SBS2003 with ISA 2004 installed
    ... I had to create a VPN connection using the network connection wizard on ... Based on our work above, it seems the problem in client side, so I suggest ...
    (microsoft.public.windows.server.sbs)
  • RE: VPNs - Firewalls and Security
    ... we turned off sysopt connection permit ipsec and then added the ... VPN connections. ... VPN's - Firewall's and Security ... You had configured that vpn users access internal network, ...
    (Security-Basics)

Loading