?
Solved

VPN client through SG 203 firewall to windows server

Posted on 2004-09-21
9
Medium Priority
?
383 Views
Last Modified: 2013-11-16
Hi,

We currently have a sonicwall firewall on our network which is forwarding PPTP (port 1723) requests to a local Windows 2000 Remote Access server.  This is allowing clients to create a VPN connection through the firewall to the server.  This appears to be the only rule on the firewall relating to VPN's.

We are trying to swap this firewall with an Avaya SG 203 firewall - I have replaced the sonicwall and set the 203 up in exactly the same way (same ip addresses, port forwarding rules etc).  However when I try to connect a VPN client, it gets as far as verifying username and password and then fails with error 628 (the client is windows 98).

Any idea what I'm doing wrong?

Thanks in advance,
Edd
0
Comment
Question by:Eddparsons
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
9 Comments
 
LVL 16

Expert Comment

by:samccarthy
ID: 12111037
I just changed from a PIX to a SGS Firwall.  In addition to the port forward, on the new firewall I also needed a rule to let it in and a rule to let it back out.
0
 

Author Comment

by:Eddparsons
ID: 12113173
Hmm....I have setup firewall rules to allow pptp in and out, and I've tried turning the firewall security off entirely - still no joy.
0
 
LVL 16

Expert Comment

by:samccarthy
ID: 12118373
If your firewall security is fully off you may have another issue.  I would reverify that the VPN works fine internally.  As long as it's good inside, it's back to the firewall.  

OK,  With my small VPN/Firewall appliances, all I do is the port forwarding.  With the SGS I had to do the Port Forward, Rule in and out as well as setup a NAT pool.  I thought the NAT pool was a little weird, but that's what the SGS required.  Also make sure your port is TCP and not UDP.  Oh, one more thing, you may have to enable GRE which is TCP Protocol 47.  I had to do that on my SGS.

Here is a link to the Port 47 Issue.  I would try this first before fooling with NAT pools, etc.

http://support.microsoft.com/?id=241251
0
WordPress Tutorial 1: Installation & Setup

WordPress is a very popular option for running your web site and can be used to get your content online quickly for the world to see. This guide will walk you through installing the WordPress server software and the initial setup process.

 

Author Comment

by:Eddparsons
ID: 12168976
Ok, I have finally found where to enable custom protocols and have enable GRE and added it to the rules, but still am not getting anywhere.

I can't see any options for NAT pools - what are they for?

0
 

Author Comment

by:Eddparsons
ID: 12168995
Oh and the VPN works fine with the old firewall, so I'm assuming the problem is not with the VPN server/client.
0
 
LVL 16

Accepted Solution

by:
samccarthy earned 375 total points
ID: 12638836
I believe with the time and effort expended, points should be awarded.  If you go to a Doctor or computer store, you still have to pay the doctor or technician for their time and whatever tests.  If points were refunded to everyone who got help and then just disappeared, then everyone could get their questions answered and not have to give up points.

I have done this same thing with both SGS and Watchguard firewalls and am sure that is issue is in a NAT pool or one-to-one NAT for his issue.  I'll ask for the points as I presented good, logical troublehsooting with some of the suggestions he did use.  As for the rest, we might not know or it may have fixed his issue.
0
 

Author Comment

by:Eddparsons
ID: 12654736
Hey,

Sorry, had forgotten all about this.  The points are yours.  The problem still isn't fixed sadly - any tips on NAT pools?

Ta,
Edd
0
 
LVL 16

Expert Comment

by:samccarthy
ID: 12664722
Thank you, I appreciate that.  

    With my SGS, I had to create the rule and do port forwarding.  I also had to setup a NAT pool to make it work.  The pool would not work on the physical IP address of the firewall, so I had to assign it another address.  For example, the interface might be 12.108.43.10.  I had to assign the VPN Nat Pool .11 and direct all my vpn traffic to that address to make it work.

   With the Watchguard, everything is the same, but they use a one to one NAT only for the PPTP.  So, I still had to create the rule and do the forwarding, assign a different IP address than the physical one and direct the VPN traffic to that IP.  The only difference is the Watchguard has you setup a one to one NAT for the PPTP to use.  

     Have you looked at the manufacturer's web site or called them about the PPTP?
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
Originally, this post was published on Monitis Blog, you can check it here . It goes without saying that technology has transformed society and the very nature of how we live, work, and communicate in ways that would’ve been incomprehensible 5 ye…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Suggested Courses
Course of the Month9 days, 23 hours left to enroll

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question