Solved

What port needs opened?

Posted on 2004-09-17
9
262 Views
Last Modified: 2010-04-12
Here's my set up:

I have a Firewalled Cisco Router provided by my ISP.  (I do not manage this)
I have a Windows 2003 Domain server behind the firewall.
I need for my users to be able to access the domain server from outside the firewall.
I can have an external IP bound to the internal ip of the Domain Server through the router.
My ISP wants to know what port(s) they need to open to allow VPN access through.  I have no idea.  Is there a standard port?  Please help.
0
Comment
Question by:QueenKretee
  • 4
  • 4
9 Comments
 
LVL 15

Expert Comment

by:Yan_west
Comment Utility
You have a firewall behind your router? what is this firewall, a cisco pix?
0
 
LVL 79

Expert Comment

by:lrmoore
Comment Utility
If you want to use Terminal Services to access the server, you need TCP port 3389 only.
0
 

Author Comment

by:QueenKretee
Comment Utility
I want some of my users to be able to VPN into the domain server using Windows XP's VPN functionality.
0
 
LVL 79

Expert Comment

by:lrmoore
Comment Utility
Then you need to open TCP 1723, and you need to have a 1-1 static NAT with GRE protocol along with that..
0
Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

 

Author Comment

by:QueenKretee
Comment Utility
What? What? Huh?  Please elaborate on what you just stated lrmoore.  Here's a little more info on what I've done from information that I have gathered here on experts exchange on my own.  I have asked my ISP to do the following.  Bind the public ip 24.xxx.xxx.xxx to internal ip 192.168.1.44, which is my domain server.  I have asked the to open ports 500, 1723 and 3389, also Protocol 50 and Protocol 51.  Now, I can use Teminal Services to access my domain server from my home.  However, I still cannot vpn in.   The message box first states, "Connecting to 24.xxx.xxx.xxx".  Then "Verifying User Name and Password.  Following,  I am getting the error:

Error 721: The remote computer did not resond.

It is also possible that I have not set up my xp vpn client properly or my Remote Access setting on my domain server.  Please excuse my ignorance as my expertise is programming, not network administation.  

On the server end, my user id in the "Dial in settings" is set for to "Allow Access"
I have used the Windows 2003 Wizard to set up my RAS.  And the Windows XP wizard to set up my vpn.

Please assist.  Many thanks in advance.
Kristi

0
 

Author Comment

by:QueenKretee
Comment Utility
Oh, also what does this mean?  "you need to have a 1-1 static NAT with GRE protocol along with that.."
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
Comment Utility
>Bind the public ip 24.xxx.xxx.xxx to internal ip 192.168.1.44, which is my domain server
This is a 1-to-1 static NAT so you're OK on that

>also Protocol 50 and Protocol 51.
You also need Protocol 47, GRE

Here's a guide on VPN w/2003

http://www.microsoft.com/windowsserver2003/technologies/networking/vpn/default.mspx

0
 

Author Comment

by:QueenKretee
Comment Utility
It worked.  Many, many thanks.
0
 
LVL 79

Expert Comment

by:lrmoore
Comment Utility
Yea!!

Glad to help..
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Sometimes, you want your microsoft VPN to route all the traffic to the remote network. Usually your employer network. This makes it possible to access all the nodes inside this remote LAN, even if they have no "public DNS" entries. To do so, you wo…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now