Advertisement

04.25.2007 at 03:41PM PDT, ID: 22534628
[x]
Attachment Details

Cant get VPN working..

Asked by andrewjb in IPSec Security Protocol, Virtual Private Networking (VPN)

Tags: vpn, ipsec

OK, so I'm a newbie at this, and may well be trying to do something that's impossible.

What I finally want is..
a) Main company office, running Win2K3 server
b) Access from individual users, connected from home, typically via ADSL + a modem/router.
One of these home users actually has 2 computers + 2 users, so maybe it's like (c) below?
c) Access from sub-office with an internal LAN

What I'm trying to do first:
- I've got Win2K3 being a VPN server
- It's also a CA and I've issued machine and user certs as necessary
- I really wanted to use IPSec (with certs) for machine confirmation, then the domain user+password as 'user confirmation' Which, I think, means using L2TP/IPSEC + MsChap2 (is that right?)
- As an alternative, I've tried it with L2TP/IPSEC + EAP-TLS

I've had both working 'locally' i.e. I can connect to the VPN on the local LAN. So the certificates are working. But I can't get a remote user to connect - presumably it's some NAT and/or firewall issue

The IPSec IKE seems to work OK - I can see a sucess logged on the server. I presume the next stage isn't working.

Is this possible? I'd therefore have:

Remote user -> Modem/Router -> Internet -> Modem/Router -> Win2K3 VPN server

The first modem/router will be using NAT. Can the second one? I've tried it in NAT mode, and with the server on a DMZ - the latter worked better (IKE worked).


Any pointers appreciated. I've read so many links!


By 'eck - isn't it confusing!
Start Free Trial
[+][-]04.25.2007 at 06:54PM PDT, ID: 18978878

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.25.2007 at 08:43PM PDT, ID: 18979152

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.26.2007 at 01:52AM PDT, ID: 18979959

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.26.2007 at 08:33AM PDT, ID: 18982427

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: IPSec Security Protocol, Virtual Private Networking (VPN)
Tags: vpn, ipsec
Sign Up Now!
Solution Provided By: RobWill
Participating Experts: 2
Solution Grade: A
 
 
[+][-]04.28.2007 at 07:32PM PDT, ID: 18995993

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]05.13.2007 at 04:11PM PDT, ID: 19082314

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]05.13.2007 at 09:13PM PDT, ID: 19082929

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32