Hello,
I am attempting to set up a VPN using the Windows XP built-in VPN client. The server is behind a Linksys RV042 load balancing router (connected to two DSL lines, one with a static IP, one dynamic) and is a Windows 2000 Small Business Server.
I can successfully connect, authenticate, and communicate with the server via VPN from inside the network, and if I place the Server in the DMZ setting on the router. I cannot get it to function properly by using the port forwarding options as needed.
These are not the actual IP's, but for the sake of explanation we can use these:
Windows XP Client on a home network, IP 10.1.1.100 NAT'd behind 71.1.1.2
Server IP in the corporate network, IP 192.168.1.100 (Static) provides DHCP for internal network
RV042 Router WAN1 68.1.1.2 , WAN2 64.1.1.2, LAN 192.168.1.1
I have tried a few settings on the router. I have specified to direct all traffic from 192.168.1.100 through WAN1 (the static IP) as well as not; neither seem to matter. I have setup the port forwarding to pass PPTP (1723), IPSec (500), and L2TP (1701) all to 192.168.1.100. I have setup firewall rules to allow PPTP, IPSec, and L2TP to go from any interface to any interface with no restrictions. Alternately, I have disabled the firewall.
I do have PPTP, IPSec andL2TP set to "Enabled" in the VPN Pass Through section of the router configuration.
The only thing that lets the traffic properly flow is to set the server in the DMZ zone. This is not a very good solution in my opinion as it opens the Server up to various security issues.
As a temporary fix I have a Firewall/VPN appliance inside the network and accessible through the DMZ setting at 192.168.1.9, and allows VPN traffic to authenticate and communicate properly.
My last step will be to place a packet sniffer into the corporate LAN and find out what traffic is being blocked, I suppose. I was hoping someone here might have an answer before I go through that process, though.
Other than "How can this work", some specific questions I have include the following:
1) What is the processing order of the various components of the Linksys RV042 Appliance; Port Forwarding, DMZ, Firewall Rulesets, VPN-Passthroughs.
2) Does the SPI firewall feature conflict with the other sections, such that may require rulesets to allow port-forwarding to occur?
3) Does the router keep a state table for incoming connections so that it knows that traffic originating on the WAN1 port should return to the WAN1 port (as opposed to the WAN2 port since it's in load-balancing mode)
Thanks in advance for any information that can be provided.
-
Start Free Trial