Solved

Routing and Remote Access

Posted on 2001-06-06
9
142 Views
Last Modified: 2010-04-13
I have a W2K Server box setup doing NAT between my ADSL modem and the internal LAN. No probs really in setting it up and the translation seems to work fine for all the machines in the LAN.

I've also installed a modem on this server and would like to dial into it for remote access. I can establish a RAS session (from another W2K machine with a modem) and can see (ping) the machines on the inside LAN.

What I cannot seem to figure out is how to configure the server so that the RAS dialled in user can also access the Internet via the DSL.

For some reason when I do an ipconfig (on the dialled in box) it shows my gateway as the same as the ip address (i.e. something like 192.168.0.100)

The Gateway should (I would have thought) be set to the server itself 192.168.0.1

Any ideas on how to set the gateway for RAS users?

Am I barking up the wrong tree?

Can this even be done at all?

Do I need some static routes or something like that?

You help is appreciated.


Regards
Marty
0
Comment
Question by:mravell
9 Comments
 
LVL 14

Accepted Solution

by:
AvonWyss earned 200 total points
ID: 6159327
In RRAS on the server (!), create a dial-on-demand interface named exactly the same as the dialin user. Put anything as password and destination number.

This interface will be used on the server when the user dials in. Because of this, you can add the user's interface to the NAT as private interface, et voila, he will have access via the NAT.

This wortks also for VPN connection, and it's also useful if you need to assign some special routes to a specific user.
0
 
LVL 5

Expert Comment

by:dcgames
ID: 6159882
Avon,

Can you point to some info on this or elaborate a bit? This sounds like a useful technique.

Dave
0
 
LVL 6

Expert Comment

by:Portang
ID: 6159977
???

The limitation of Windows 2000 RRAS is that you can only have no more than one NAT routing.

And ... Windows 2000's implementation of NAT requires exactly two interfaces - one, and only one private, and one, and only one public.

Surely you're free to create as many interfaces as you like. But you can only assign ONE private interface for NAT. Unfortunately, that one happens to be the internal LAN adapter, so anything else is out of luck.

ONE, and only ONE private interface!
0
 
LVL 14

Expert Comment

by:AvonWyss
ID: 6160043
Portang, sorry but you're wrong. You can have as many interfaces (both public and private) as you want for NAT. The routing is done in regards of the routing table and can include several interfaces. I use this all the time myself.

Dave, Windows 2000 RAS will connect an existing DOD interface to a connecting user if the interface has the user's name. This allows to have special routes or bindings (NAT for instance) for single users. You could say that DOD interfaces are not only outgoing, but also ingoing.
0
Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

 
LVL 6

Expert Comment

by:Portang
ID: 6160096
> You can have as many interfaces (both public and private) as you want for NAT.

Maybe I'm wrong ... but I do have trouble adding more than two interfaces into the "Network Address Translation" routing protocol.
0
 
LVL 14

Expert Comment

by:AvonWyss
ID: 6160124
Portang, be my guest and look at my NAT config (it's in German, but you'll get the idea) here: http://snoopy.horsenet.ch/nat.gif

I have two public interfaces ("Internet" and "Internet ISDN") and three private interfaces ("LAN-Verbindung", "VPN-Mammut" and "VPN-Goliath"). This works like a charm.
0
 
LVL 6

Expert Comment

by:Portang
ID: 6161430
This is amazing. I'll go ahead and give it a try.

Thanks a lot Avon. A picture is worth a thousand words!
0
 
LVL 5

Expert Comment

by:cempasha
ID: 8194829
Dear questionner/expert(s)

No comment has been added lately, so it's time to clean up this TA.
I'll leave a recommendation in the Cleanup topic area that this question is to be:

- Answered by: AvonWyss

Please leave any comments here within the next seven days.

==> PLEASE DO NOT ACCEPT THIS COMMENT AS AN ANSWER ! <==

PaSHa

Cleanup volunteer



0
 

Expert Comment

by:Chmod
ID: 8241349
As recommended

Chmod
Community Support Moderator @Experts Exchange
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

Suggested Solutions

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Is your company's data protection keeping pace with virtualization? Here are 7 dynamic ways to adapt to rapid breakthroughs in technology.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now