Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

VPN client through SG 203 firewall to windows server

Posted on 2004-09-21
9
Medium Priority
?
394 Views
Last Modified: 2013-11-16
Hi,

We currently have a sonicwall firewall on our network which is forwarding PPTP (port 1723) requests to a local Windows 2000 Remote Access server.  This is allowing clients to create a VPN connection through the firewall to the server.  This appears to be the only rule on the firewall relating to VPN's.

We are trying to swap this firewall with an Avaya SG 203 firewall - I have replaced the sonicwall and set the 203 up in exactly the same way (same ip addresses, port forwarding rules etc).  However when I try to connect a VPN client, it gets as far as verifying username and password and then fails with error 628 (the client is windows 98).

Any idea what I'm doing wrong?

Thanks in advance,
Edd
0
Comment
Question by:Eddparsons
  • 4
  • 4
8 Comments
 
LVL 18
ID: 12111037
I just changed from a PIX to a SGS Firwall.  In addition to the port forward, on the new firewall I also needed a rule to let it in and a rule to let it back out.
0
 

Author Comment

by:Eddparsons
ID: 12113173
Hmm....I have setup firewall rules to allow pptp in and out, and I've tried turning the firewall security off entirely - still no joy.
0
 
LVL 18
ID: 12118373
If your firewall security is fully off you may have another issue.  I would reverify that the VPN works fine internally.  As long as it's good inside, it's back to the firewall.  

OK,  With my small VPN/Firewall appliances, all I do is the port forwarding.  With the SGS I had to do the Port Forward, Rule in and out as well as setup a NAT pool.  I thought the NAT pool was a little weird, but that's what the SGS required.  Also make sure your port is TCP and not UDP.  Oh, one more thing, you may have to enable GRE which is TCP Protocol 47.  I had to do that on my SGS.

Here is a link to the Port 47 Issue.  I would try this first before fooling with NAT pools, etc.

http://support.microsoft.com/?id=241251
0
Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

 

Author Comment

by:Eddparsons
ID: 12168976
Ok, I have finally found where to enable custom protocols and have enable GRE and added it to the rules, but still am not getting anywhere.

I can't see any options for NAT pools - what are they for?

0
 

Author Comment

by:Eddparsons
ID: 12168995
Oh and the VPN works fine with the old firewall, so I'm assuming the problem is not with the VPN server/client.
0
 
LVL 18

Accepted Solution

by:
Steve McCarthy, MCSE, MCSA, MCP x8, Network+, i-Net+, A+, CIWA, CCNA, FDLE FCIC, HIPAA Security Officer earned 375 total points
ID: 12638836
I believe with the time and effort expended, points should be awarded.  If you go to a Doctor or computer store, you still have to pay the doctor or technician for their time and whatever tests.  If points were refunded to everyone who got help and then just disappeared, then everyone could get their questions answered and not have to give up points.

I have done this same thing with both SGS and Watchguard firewalls and am sure that is issue is in a NAT pool or one-to-one NAT for his issue.  I'll ask for the points as I presented good, logical troublehsooting with some of the suggestions he did use.  As for the rest, we might not know or it may have fixed his issue.
0
 

Author Comment

by:Eddparsons
ID: 12654736
Hey,

Sorry, had forgotten all about this.  The points are yours.  The problem still isn't fixed sadly - any tips on NAT pools?

Ta,
Edd
0
 
LVL 18
ID: 12664722
Thank you, I appreciate that.  

    With my SGS, I had to create the rule and do port forwarding.  I also had to setup a NAT pool to make it work.  The pool would not work on the physical IP address of the firewall, so I had to assign it another address.  For example, the interface might be 12.108.43.10.  I had to assign the VPN Nat Pool .11 and direct all my vpn traffic to that address to make it work.

   With the Watchguard, everything is the same, but they use a one to one NAT only for the PPTP.  So, I still had to create the rule and do the forwarding, assign a different IP address than the physical one and direct the VPN traffic to that IP.  The only difference is the Watchguard has you setup a one to one NAT for the PPTP to use.  

     Have you looked at the manufacturer's web site or called them about the PPTP?
0

Featured Post

New Tabletop Appliances Blow Competitors Away!

WatchGuard’s new T15, T35 and T55 tabletop UTMs provide the highest-performing security inspection in their class, allowing users at small offices, home offices and distributed enterprises to experience blazing-fast Internet speeds without sacrificing enterprise-grade security.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will show you step-by-step instructions to build your own NTP CentOS server.  The network diagram shows the best practice to setup the NTP server farm for redundancy.  This article also serves as your NTP server documentation.
In this article I will be showing you how to subnet the easiest way possible for IPv4 (Internet Protocol version 4). This article does not cover IPv6. Keep in mind that subnetting requires lots of practice and time.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question