Routing and Remote Access

Posted on 2001-06-06
Last Modified: 2010-04-13
I have a W2K Server box setup doing NAT between my ADSL modem and the internal LAN. No probs really in setting it up and the translation seems to work fine for all the machines in the LAN.

I've also installed a modem on this server and would like to dial into it for remote access. I can establish a RAS session (from another W2K machine with a modem) and can see (ping) the machines on the inside LAN.

What I cannot seem to figure out is how to configure the server so that the RAS dialled in user can also access the Internet via the DSL.

For some reason when I do an ipconfig (on the dialled in box) it shows my gateway as the same as the ip address (i.e. something like

The Gateway should (I would have thought) be set to the server itself

Any ideas on how to set the gateway for RAS users?

Am I barking up the wrong tree?

Can this even be done at all?

Do I need some static routes or something like that?

You help is appreciated.

Question by:mravell
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 14

Accepted Solution

AvonWyss earned 200 total points
ID: 6159327
In RRAS on the server (!), create a dial-on-demand interface named exactly the same as the dialin user. Put anything as password and destination number.

This interface will be used on the server when the user dials in. Because of this, you can add the user's interface to the NAT as private interface, et voila, he will have access via the NAT.

This wortks also for VPN connection, and it's also useful if you need to assign some special routes to a specific user.

Expert Comment

ID: 6159882

Can you point to some info on this or elaborate a bit? This sounds like a useful technique.


Expert Comment

ID: 6159977

The limitation of Windows 2000 RRAS is that you can only have no more than one NAT routing.

And ... Windows 2000's implementation of NAT requires exactly two interfaces - one, and only one private, and one, and only one public.

Surely you're free to create as many interfaces as you like. But you can only assign ONE private interface for NAT. Unfortunately, that one happens to be the internal LAN adapter, so anything else is out of luck.

ONE, and only ONE private interface!
U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

LVL 14

Expert Comment

ID: 6160043
Portang, sorry but you're wrong. You can have as many interfaces (both public and private) as you want for NAT. The routing is done in regards of the routing table and can include several interfaces. I use this all the time myself.

Dave, Windows 2000 RAS will connect an existing DOD interface to a connecting user if the interface has the user's name. This allows to have special routes or bindings (NAT for instance) for single users. You could say that DOD interfaces are not only outgoing, but also ingoing.

Expert Comment

ID: 6160096
> You can have as many interfaces (both public and private) as you want for NAT.

Maybe I'm wrong ... but I do have trouble adding more than two interfaces into the "Network Address Translation" routing protocol.
LVL 14

Expert Comment

ID: 6160124
Portang, be my guest and look at my NAT config (it's in German, but you'll get the idea) here:

I have two public interfaces ("Internet" and "Internet ISDN") and three private interfaces ("LAN-Verbindung", "VPN-Mammut" and "VPN-Goliath"). This works like a charm.

Expert Comment

ID: 6161430
This is amazing. I'll go ahead and give it a try.

Thanks a lot Avon. A picture is worth a thousand words!

Expert Comment

ID: 8194829
Dear questionner/expert(s)

No comment has been added lately, so it's time to clean up this TA.
I'll leave a recommendation in the Cleanup topic area that this question is to be:

- Answered by: AvonWyss

Please leave any comments here within the next seven days.



Cleanup volunteer


Expert Comment

ID: 8241349
As recommended

Community Support Moderator @Experts Exchange

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Add bar graphs to Access queries using Unicode block characters. Graphs appear on every record in the color you want. Give life to numbers. Hopes this gives you ideas on visualizing your data in new ways ~ Create a calculated field in a query: …

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question