The only firewall is:
LINKSYS BEFSR11 firmware 1.44.2
Filters set to allow IPSec and PPTP Pass through
Forwarding of 1723 and 47, allowing both UDP and TCP, to RRAS Server.
Main Topics
Browse All TopicsW2k, RRAS, PPTP, NAT, 1723/47=fwded, FilterPassTru=PPTP&IPSec
Static address pool 10.20.0.1 - 10.20.0.254
On my notebook at the office on the LAN/intranet with a 10.10.10.x address I can VPN to the server 10.10.10.x.
I can Login get assigned a 10.20.0.x address.
While still at the office same as above, same connection profile as above except aiming at our WAN address; it sits at "Verifying user and password..." for 30 seconds the returns Error 721 = "the remote computer is not responding".
(Not error: 678 = "no answer")
Also tried remotely from home to WAN address with of course no success, same Error 721.
I can successfully use pcAnywhere thru the WAN IP address firewall via forwarding ports 5631&5632.
Any VPN Idea's?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
GRE is not UDP or TCP port 47, it is Protocol #47 which cannot be port-forwarded.
With your linksys, you have to do two things:
1. forward TCP port 1723 to RRAS server
2. Disable DHCP service on the router (one small notation in the user manual that if you are going to use port forwarding, you must turn off DHCP service)
If that fails, try putting the RRAS server as a DMZ host. If that works, then work on tightening down security of the RRAS server because it will be bare naked on the Internet.
Microsoft's story:
PPTP traffic consists of a TCP connection for tunnel maintenance and GRE encapsulation for tunneled data. The TCP connection is NAT-translatable because the source TCP port numbers can be transparently translated. However, the GRE-encapsulated data is not NAT-translatable
The W2kAdvServer is a DHCP, DNS, AD, RRAS, Exchange2k, Stand Alone Compaq Prolient ML530.
Router's DHCP not enabled, it is in Gateway mode.
The router does have UPnP Forwarding and Port Triggering functions, however I am not using them.
I have the router's logging enabled and it shows the WAN/Internet connect attempt to the server.
Is their a testing tool like telnet, SamSpade, or something to troubleshoot RRAS connectivity?
Since this is becomming a bigger issue I increased the points to 500
I got PPTP maximum security MS CHAP v2, and EAP for the VPN working without DMZ!
I suggest nobody ever ever allows a DMZ to any computer.
If you absolutely have to, get another firewall to block the other 65 thousand doors (ports) DMZ opens.
DMZ is the same as in front of the firewall; remove DMZed PC from your LAN would be a good idea.
Access it like the hackers will, thru the internet/WAN with pcAnywhere or similar.
I found a RRAS "Remote access policy" that was blocking connections.
Did I mention I inherited this Server, yep the previous admin had blocked access with a RAS policy.
You could use them to lock down a DMZed RRAS.
Now on to the nightmare of L2TP certificates and SSL Outlook web access.
I even tried DMZ to the pptp host (server) and it still wouldn't work until they got the firmware right.
I still can't get L2TP to work.
PPTP isn't secure at login (handshake), use IPSec.
I suggest the Linksys BEFSX41 VPN End Point Firewall, but not the latest firmware only to next to latest (befsx41_1453_fw)
or any router with built in IPSec VPNs, I just know the linksys ones do not require special client software.
Business Accounts
Answer for Membership
by: lrmoorePosted on 2003-07-01 at 16:10:28ID: 8836245
> You should not be able to VPN to the WAN address from the LAN side through your firewall. That would be an egregious security issue.
PPTP passthru is for internal users going to an external server (not the external address of your own server).
If you are at home and can't connect, the firewall nearest the server is not passing GRE Protocol 47.
What kind of firewall do you have?