Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

VPN client through SG 203 firewall to windows server

Posted on 2004-09-21
9
359 Views
Last Modified: 2013-11-16
Hi,

We currently have a sonicwall firewall on our network which is forwarding PPTP (port 1723) requests to a local Windows 2000 Remote Access server.  This is allowing clients to create a VPN connection through the firewall to the server.  This appears to be the only rule on the firewall relating to VPN's.

We are trying to swap this firewall with an Avaya SG 203 firewall - I have replaced the sonicwall and set the 203 up in exactly the same way (same ip addresses, port forwarding rules etc).  However when I try to connect a VPN client, it gets as far as verifying username and password and then fails with error 628 (the client is windows 98).

Any idea what I'm doing wrong?

Thanks in advance,
Edd
0
Comment
Question by:Eddparsons
  • 4
  • 4
9 Comments
 
LVL 16

Expert Comment

by:samccarthy
ID: 12111037
I just changed from a PIX to a SGS Firwall.  In addition to the port forward, on the new firewall I also needed a rule to let it in and a rule to let it back out.
0
 

Author Comment

by:Eddparsons
ID: 12113173
Hmm....I have setup firewall rules to allow pptp in and out, and I've tried turning the firewall security off entirely - still no joy.
0
 
LVL 16

Expert Comment

by:samccarthy
ID: 12118373
If your firewall security is fully off you may have another issue.  I would reverify that the VPN works fine internally.  As long as it's good inside, it's back to the firewall.  

OK,  With my small VPN/Firewall appliances, all I do is the port forwarding.  With the SGS I had to do the Port Forward, Rule in and out as well as setup a NAT pool.  I thought the NAT pool was a little weird, but that's what the SGS required.  Also make sure your port is TCP and not UDP.  Oh, one more thing, you may have to enable GRE which is TCP Protocol 47.  I had to do that on my SGS.

Here is a link to the Port 47 Issue.  I would try this first before fooling with NAT pools, etc.

http://support.microsoft.com/?id=241251
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 

Author Comment

by:Eddparsons
ID: 12168976
Ok, I have finally found where to enable custom protocols and have enable GRE and added it to the rules, but still am not getting anywhere.

I can't see any options for NAT pools - what are they for?

0
 

Author Comment

by:Eddparsons
ID: 12168995
Oh and the VPN works fine with the old firewall, so I'm assuming the problem is not with the VPN server/client.
0
 
LVL 16

Accepted Solution

by:
samccarthy earned 125 total points
ID: 12638836
I believe with the time and effort expended, points should be awarded.  If you go to a Doctor or computer store, you still have to pay the doctor or technician for their time and whatever tests.  If points were refunded to everyone who got help and then just disappeared, then everyone could get their questions answered and not have to give up points.

I have done this same thing with both SGS and Watchguard firewalls and am sure that is issue is in a NAT pool or one-to-one NAT for his issue.  I'll ask for the points as I presented good, logical troublehsooting with some of the suggestions he did use.  As for the rest, we might not know or it may have fixed his issue.
0
 

Author Comment

by:Eddparsons
ID: 12654736
Hey,

Sorry, had forgotten all about this.  The points are yours.  The problem still isn't fixed sadly - any tips on NAT pools?

Ta,
Edd
0
 
LVL 16

Expert Comment

by:samccarthy
ID: 12664722
Thank you, I appreciate that.  

    With my SGS, I had to create the rule and do port forwarding.  I also had to setup a NAT pool to make it work.  The pool would not work on the physical IP address of the firewall, so I had to assign it another address.  For example, the interface might be 12.108.43.10.  I had to assign the VPN Nat Pool .11 and direct all my vpn traffic to that address to make it work.

   With the Watchguard, everything is the same, but they use a one to one NAT only for the PPTP.  So, I still had to create the rule and do the forwarding, assign a different IP address than the physical one and direct the VPN traffic to that IP.  The only difference is the Watchguard has you setup a one to one NAT for the PPTP to use.  

     Have you looked at the manufacturer's web site or called them about the PPTP?
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

861 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question