Solved

VPN server at home

Posted on 2004-10-12
8
238 Views
Last Modified: 2013-11-30
I want to set up a VPN server at home so that i can share files with friends... and play vid. games with them. Here is my set up right now

1 Linksys wireless router also a DHCP server
4 client computers (both wireless and wired)
1 server which i plan to use for a VPN server (has Windows 2000 Advanced Server installed) w/2 NIC cards

Here is the set up i am thinking about

(Internet) -> (Cable Modem IP: xx.xx.xx.xx) -> (VPN Srvr) -> (Linksys router 192.168.1.1) -> (..clients..)

Questions:

i)   Can i do this and if so, How?
ii)  Will i need to have my VPN server on ALL the time for my clients to be able to connect to the internet?
0
Comment
Question by:thefallguy
  • 3
8 Comments
 
LVL 2

Accepted Solution

by:
cwisofsky earned 75 total points
ID: 12294844
You can do this, but if you have Windows 2000 server, I would just use it as the router.  It has all the features of the Linksys and more such as DHCP, DNS forwarding, WINS for your internal network, the VPN server (remote access), NAT translation would need to be done there anyways since it is the device that is connected to the Internet.  Yes you will need to have the server on all the time, since you are placing it in the middle.  

The alternative is to leave the Internet on the linksys and then setup port forwarding on the linksys to the Windows VPN ports.  Then the connections would pass through the router to the server and establish a LAN IP for your local network.

Look here for more info:
     http://support.microsoft.com/default.aspx?scid=kb;en-us;255784#kb2
0
 
LVL 3

Expert Comment

by:_anom_
ID: 12294912
In addition, if you plan to use the router, you had best connect the devices like this:   internet-->cable modem-->router-->vpn server (set as DMZ in router config)   because the VPN server needs to be able to assign IP addresses in and communicate with the LAN (which is behind the router).  Also, assuming your friends are connecting through their own internet connections, you would not need to leave it on all the time as they already have a connection, and will only be utilizing the VPN when it is on (or so we should hope ;))

Cheers
0
 
LVL 1

Expert Comment

by:rccbi
ID: 12301679
I think the config I would use would look like:


Internet>Cable modem> NAT router>
And plugged into the switched ports on the router:
> WIndows 2000 Server with VPN enabled in routing and remote access  
and
>Rest of the PCs


In the NAT router forward PPTP traffic (port 1723) to the Windows 2000 server which you can configure to be your VPN server.

I have done this in some offices...works fantastic.

Jason
0
 
LVL 1

Expert Comment

by:rccbi
ID: 12301695
ALSO, I forgot.

I would not make any PC the DMZ server, the security risks are pretty high and not at all necessary for what you are trying to accomplish.
0
 
LVL 1

Expert Comment

by:rccbi
ID: 12301706
Also,

Geez, I could try to get it in all posts.

Routing and Router access can be started and stopped on the W2k server whenever you do not want people to have  VPN access. Or you could stop the PPTP port forwarding on the NAT router too.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Setup another VLAN on Fortigate 3 30
Monitor Bandwidth throughput in Fortigate 100D 1 35
VLAN Question 13 44
USB management software on a network of computers 4 30
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question