Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


VPN client through SG 203 firewall to windows server

Posted on 2004-09-21
Medium Priority
Last Modified: 2013-11-16

We currently have a sonicwall firewall on our network which is forwarding PPTP (port 1723) requests to a local Windows 2000 Remote Access server.  This is allowing clients to create a VPN connection through the firewall to the server.  This appears to be the only rule on the firewall relating to VPN's.

We are trying to swap this firewall with an Avaya SG 203 firewall - I have replaced the sonicwall and set the 203 up in exactly the same way (same ip addresses, port forwarding rules etc).  However when I try to connect a VPN client, it gets as far as verifying username and password and then fails with error 628 (the client is windows 98).

Any idea what I'm doing wrong?

Thanks in advance,
Question by:Eddparsons
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
LVL 17
ID: 12111037
I just changed from a PIX to a SGS Firwall.  In addition to the port forward, on the new firewall I also needed a rule to let it in and a rule to let it back out.

Author Comment

ID: 12113173
Hmm....I have setup firewall rules to allow pptp in and out, and I've tried turning the firewall security off entirely - still no joy.
LVL 17
ID: 12118373
If your firewall security is fully off you may have another issue.  I would reverify that the VPN works fine internally.  As long as it's good inside, it's back to the firewall.  

OK,  With my small VPN/Firewall appliances, all I do is the port forwarding.  With the SGS I had to do the Port Forward, Rule in and out as well as setup a NAT pool.  I thought the NAT pool was a little weird, but that's what the SGS required.  Also make sure your port is TCP and not UDP.  Oh, one more thing, you may have to enable GRE which is TCP Protocol 47.  I had to do that on my SGS.

Here is a link to the Port 47 Issue.  I would try this first before fooling with NAT pools, etc.

Cyber Threats to Small Businesses (Part 1)

This past May, Webroot surveyed more than 600 IT decision-makers at medium-sized companies to see how these small businesses perceived new threats facing their organizations.  Read what Webroot CISO, Gary Hayslip, has to say about the survey in part 1 of this 2-part blog series.


Author Comment

ID: 12168976
Ok, I have finally found where to enable custom protocols and have enable GRE and added it to the rules, but still am not getting anywhere.

I can't see any options for NAT pools - what are they for?


Author Comment

ID: 12168995
Oh and the VPN works fine with the old firewall, so I'm assuming the problem is not with the VPN server/client.
LVL 17

Accepted Solution

Steve McCarthy, MCSE, MCSA, MCP x8, Network+, i-Net+, A+, CIWA, CCNA, FDLE FCIC, HIPAA Security Officer earned 375 total points
ID: 12638836
I believe with the time and effort expended, points should be awarded.  If you go to a Doctor or computer store, you still have to pay the doctor or technician for their time and whatever tests.  If points were refunded to everyone who got help and then just disappeared, then everyone could get their questions answered and not have to give up points.

I have done this same thing with both SGS and Watchguard firewalls and am sure that is issue is in a NAT pool or one-to-one NAT for his issue.  I'll ask for the points as I presented good, logical troublehsooting with some of the suggestions he did use.  As for the rest, we might not know or it may have fixed his issue.

Author Comment

ID: 12654736

Sorry, had forgotten all about this.  The points are yours.  The problem still isn't fixed sadly - any tips on NAT pools?

LVL 17
ID: 12664722
Thank you, I appreciate that.  

    With my SGS, I had to create the rule and do port forwarding.  I also had to setup a NAT pool to make it work.  The pool would not work on the physical IP address of the firewall, so I had to assign it another address.  For example, the interface might be  I had to assign the VPN Nat Pool .11 and direct all my vpn traffic to that address to make it work.

   With the Watchguard, everything is the same, but they use a one to one NAT only for the PPTP.  So, I still had to create the rule and do the forwarding, assign a different IP address than the physical one and direct the VPN traffic to that IP.  The only difference is the Watchguard has you setup a one to one NAT for the PPTP to use.  

     Have you looked at the manufacturer's web site or called them about the PPTP?

Featured Post

Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as the high-speed power of the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
Suggested Courses

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question