How to open ports on Win2k Server

Posted on 2004-04-29
Last Modified: 2007-12-19
I have a routing setup with Windows 2000 Advanced Server.  On the computers behind this router, (using the router as their gateway) all ports are closed so I can't get incoming connections.  Should I use VPN or make a new connection in My Network Places, or should I enable Demand Dialing in Routing and Remote Access?

I know how to open ports with Internet Connection Sharing but can't find a way to do this with the built in Network Manager.
Question by:happispider
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3

Author Comment

ID: 10955312
I tried something and it failed...  I enabled Internet Connection Sharing and managed to open ports (NOT the way I want to do it), then I ran COMMAND /C NETSH DUMP >>C:\DUMP to dump the configuration.  I dumped the configuration with ICS turned off.  The only difference (I did file compare on the 2 files) was in the great big Base64 "blob".  I decoded the base64 and it still looked pretty awful.  I removed binary characters from it and it still made no sense whatsoever.        
:  () ->help!

Expert Comment

ID: 10955558
You will want to use IPSec to lock down (filter) specific ports.
Here is a helpful link -;en-us;813878

Expert Comment

ID: 10955562
To add or block a specific port is about half way down the page.
SharePoint Admin?

Enable Your Employees To Focus On The Core With Intuitive Onscreen Guidance That is With You At The Moment of Need.


Author Comment

ID: 10956309
I could kindof understand the article but I need to reread it.  Can u tell me though how to allow access on ports?  Do I just replace BLOCK with ALLOW?  I opened IPSec in MMC console and fooled with it a bit nothing seemed to work.

I also tried deleting HKEY_LOCAL_MACHINE/System/Policies/IPSec or something like that with no luck (I didn't expect luck there)...  I have a connection to Internet on and a connection to LAN ( on the multihomed computer...  Could you give me an example command for IPsecpol or directions thru an MMC console because [for now] I'm a bit confused.

The article said to use IPSecpol so I probably need to learn more about it, but if there's another way besides ICS, like working thru MMC or regedit that'd be great.

I guess I'll try to be a bit more specific on exactly what I've tried lateron... thanks for help

Author Comment

ID: 10958145
Looks like I simply had to use NAT routing's 'special ports' feature.  I'm almost happy with this router setup, but it'd be great if I could open more ports than just the ones I specify.  Is that related to IPSec?  I thought IPSec just blocked access.  Can IPSec also allow access to a port (without help from NAT)??

Accepted Solution

matalyn1016 earned 300 total points
ID: 10962660
You'll find the router is limited and that using IPSec will truley be a joy to use when you better understand it.

To answer your question >> Can IPSec also allow access to a port (without help from NAT)?? << YES!!
You will be able to eliminate NAT all together in most circumstances.

As for the question >> Do I just replace BLOCK with ALLOW? << YES!! again, take some time to better understand how IPSec works and you'll be fine.

Good Luck...

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Have you ever set up your wireless router at home or in the office to find that you little pop-up bubble in the bottom right-hand corner of Windows read "IP Conflict - One of more computers on the network have been assigned the following IP address"…
An article on effective troubleshooting
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor ( Top Charts is a view in which you can set seve…
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question