Solved

What port needs opened?

Posted on 2004-09-17
9
302 Views
Last Modified: 2010-04-12
Here's my set up:

I have a Firewalled Cisco Router provided by my ISP.  (I do not manage this)
I have a Windows 2003 Domain server behind the firewall.
I need for my users to be able to access the domain server from outside the firewall.
I can have an external IP bound to the internal ip of the Domain Server through the router.
My ISP wants to know what port(s) they need to open to allow VPN access through.  I have no idea.  Is there a standard port?  Please help.
0
Comment
Question by:QueenKretee
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
9 Comments
 
LVL 15

Expert Comment

by:Yan_west
ID: 12087021
You have a firewall behind your router? what is this firewall, a cisco pix?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 12089138
If you want to use Terminal Services to access the server, you need TCP port 3389 only.
0
 

Author Comment

by:QueenKretee
ID: 12089555
I want some of my users to be able to VPN into the domain server using Windows XP's VPN functionality.
0
Is your NGFW recommended by NSS Labs?

Ours is! NSS Labs Next Generation Firewall Test gives the WatchGuard Firebox M4600 a "Recommended" rating! Curious where your NGFW landed on the  Security Value Map? See the map and download the full report today!

 
LVL 79

Expert Comment

by:lrmoore
ID: 12089750
Then you need to open TCP 1723, and you need to have a 1-1 static NAT with GRE protocol along with that..
0
 

Author Comment

by:QueenKretee
ID: 12090183
What? What? Huh?  Please elaborate on what you just stated lrmoore.  Here's a little more info on what I've done from information that I have gathered here on experts exchange on my own.  I have asked my ISP to do the following.  Bind the public ip 24.xxx.xxx.xxx to internal ip 192.168.1.44, which is my domain server.  I have asked the to open ports 500, 1723 and 3389, also Protocol 50 and Protocol 51.  Now, I can use Teminal Services to access my domain server from my home.  However, I still cannot vpn in.   The message box first states, "Connecting to 24.xxx.xxx.xxx".  Then "Verifying User Name and Password.  Following,  I am getting the error:

Error 721: The remote computer did not resond.

It is also possible that I have not set up my xp vpn client properly or my Remote Access setting on my domain server.  Please excuse my ignorance as my expertise is programming, not network administation.  

On the server end, my user id in the "Dial in settings" is set for to "Allow Access"
I have used the Windows 2003 Wizard to set up my RAS.  And the Windows XP wizard to set up my vpn.

Please assist.  Many thanks in advance.
Kristi

0
 

Author Comment

by:QueenKretee
ID: 12090191
Oh, also what does this mean?  "you need to have a 1-1 static NAT with GRE protocol along with that.."
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 12091434
>Bind the public ip 24.xxx.xxx.xxx to internal ip 192.168.1.44, which is my domain server
This is a 1-to-1 static NAT so you're OK on that

>also Protocol 50 and Protocol 51.
You also need Protocol 47, GRE

Here's a guide on VPN w/2003

http://www.microsoft.com/windowsserver2003/technologies/networking/vpn/default.mspx

0
 

Author Comment

by:QueenKretee
ID: 12096129
It worked.  Many, many thanks.
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 12096250
Yea!!

Glad to help..
0

Featured Post

Don't Miss ATEN at InfoComm 2017!

Visit booth #2167 to see the  new ATEN VM3200 32 x 32 Modular Matrix Switch. Other highlights include the VE8950 4K HDMI Over IP Extender, VS1912 12-Port DP Video Wall Media Player  and VK2100 ATEN Control System. Register now with Free Pass Code ATEN288!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Using Windows 2008 RRAS, I was able to successfully VPN into the network, but I was having problems restricting my test user from accessing certain things on the network.  I used Google in order to try to find out how to stop people from accessing c…
Let’s list some of the technologies that enable smooth teleworking. 
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question