• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 199
  • Last Modified:

VPN and Windows 2000

I am using Windows 2000 Server as a VPN server through its routing and remote accesss.  I can connect to the VPN and access the Internet through the VPN but can not map to the server.  In fact I can not even ping the server.  However, I am still able to access the server (that is not on the VPN network) on my side.  I dont know how this works since I am connected to another network through VPN.  I know I am using the VPN network because when I do a tracert it orginates from the VPN network.  
0
cellophanecore
Asked:
cellophanecore
  • 8
  • 6
1 Solution
 
Nirmal SharmaSolution ArchitectCommented:
>>>I can connect to the VPN and access the Internet through the VPN but can not map to the server
Its confusing...could you please explain it clearly?

Are you using DHCP or Static IP Address ?
0
 
Nirmal SharmaSolution ArchitectCommented:
If you are using DHCP on the same server then Internal Interface must be configured for DHCP server to transfer IP Options to client machines. If you are using Static IP Addresses (a pool created on RRAS Server) then you should configure a Static Route back to VPN Server.

Also make sure NetBIOS over TCP/IP is enabled on Server. Enable IP Routing on IP Tab if you want clients to access network resources.

Let me know.

Thanks
0
 
cellophanecoreAuthor Commented:
I found the problem, the 2 networks had to be on different subnets in order to route correctly.  I do not have NetBIOS installed, why did you think it needed to be?
0
Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

 
Nirmal SharmaSolution ArchitectCommented:
No when browsing shared resources....Browser Service collects informations about resources using NetBIOS Names and not domain names. That's the reason i said that :-)

Anyway you solved it.
0
 
cellophanecoreAuthor Commented:
how do you install netbios on win2k, the only protocals I see to install are Appletalk, DLC, netbeui, and IPX
0
 
Nirmal SharmaSolution ArchitectCommented:
>>>how do you install netbios on win2k, the only protocals I see to install are Appletalk, DLC, netbeui, and IPX

No, i have told you to enable NetBIOS session service over TCP/IP.
Please see this: -

 NetBIOS is an ancient session-level interface and transport protocol developed by IBM to network together PCs. It is a broadcast-based, non-routable and insecure protocol, and it scales poorly mostly because it was designed with a flat namespace. Since the late 1980s Microsoft has adopted NetBIOS for their LAN Manager product, and from there it found its way into early versions of Windows and all the way into Windows NT.

Since Windows 2000 however, DNS has become the default name resolution method for Windows-based networks and is required if you want to deploy Active Directory domains, as seen in the How to Install Active Directory on Windows 2000, Install and Configure Windows 2000 DNS Server to Prepare for AD and the How to Install Active Directory on Windows 2003 articles.

Although Windows 2000, Windows XP, and Windows Server 2003 provide for the ability to disable NetBIOS over TCP/IP (NetBT), many corporate networks will remain reluctant to do so because of the fact that most of them still have legacy (Windows 9x or Windows NT) machines on their network. These machines need NetBIOS to function properly on a network because they use NetBIOS to logon to domains, find one another, and establish sessions for accessing shared resources.

But for networks that are "free" of legacy systems you may want to consider disabling the NetBT transport altogether on all computers (it can be easily accomplished by using DHCP) or at least on critical file and print servers.

In order to disable NetBIOS over TCP/IPin Windows 2000/XP/2003 you should right-click on My Network Places and select Properties. Then right-click on the appropriate Local Area Connection icon, and select Properties.

Ref: -
http://www.petri.co.il/disable_netbios_in_w2k_xp_2003.htm

Thanks
0
 
cellophanecoreAuthor Commented:
I followed the steps in http://techrepublic.com.com/5100-6268-1032135.html to setup a VPN.  VPN works fine but I keep getting an error in my system log, event ID: 4199.

The system detected an address conflict for IP address 23.233.136.10 with the system having network hardware address 00:12:15:39:20:D9. Network operations on this system may be disrupted as a result.

I followed this instruction:

"During installation, you should choose to statically assign IP addresses. You’ll need to set up one network card with a true Internet IP address and the default gateway of your Internet router. The other network card should have an IP address assigned to the local network, and it should not contain a default gateway. http://techrepublic.com.com/5100-6268-1032135.html"

Even though I did this, why would I be getting an error? the vpn works fine..
0
 
Nirmal SharmaSolution ArchitectCommented:
>>>Even though I did this, why would I be getting an error? the vpn works fine..

Did you stop and restart RRAS service?
0
 
cellophanecoreAuthor Commented:
yes
0
 
Nirmal SharmaSolution ArchitectCommented:
>>>The system detected an address conflict for IP address 23.233.136.10 with the system having network hardware address 00:12:15:39:20:D9. Network operations on this system may be disrupted as a result.

You get this error...which client is assigned this IP Address ?
0
 
cellophanecoreAuthor Commented:
23.233.136.10 is my WAN IP, no one is assigned to it but that NIC.
0
 
Nirmal SharmaSolution ArchitectCommented:
Sorry for late response.

Did you solve the problem or we shall continue now?

Thanks
0
 
cellophanecoreAuthor Commented:
I just took the nic out of the server, it seems you can run a vpn server with only 1 nic.  Is there a reason the article says you need 2?
0
 
Nirmal SharmaSolution ArchitectCommented:
>>>Is there a reason the article says you need 2?

Which article says? Two NICs conflict only if your system is Master Browser and you have difficult browsing the network.

0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 8
  • 6
Tackle projects and never again get stuck behind a technical roadblock.
Join Now