Solved

xp vpn server behind BEFSR81 router with NAT

Posted on 2006-11-09
5
4,351 Views
Last Modified: 2009-12-16
I'm trying to setup a VPN between my home network and my office. I can remote desktop to (1) fine from (6), forwarding TCP 3389 in router (2) just fine.

-----------------------HOME-------------------------------- Internet --------------------------- Office ----------------------------
1. XP sp2 ----- 2. BEFSR81 ----- 3. Cable Modem ----- Internet ----- 4. Verison DSL ----- 5. DLink Router ----- 6. XP sp2

1. XP Pro VPN Server, Static IP, Windows Firewall Ports TCP 1723, UDP 500 open
2. Linksys Befsr81 v.3 latest firmware. PPTP forwarding enabled, forwarding 1723, 500 to xp vpn server
3. Comcast RCA modem model unknown for now
4. Verison Westel DSL Modem
5. DLink router, model unknown
6. my office XP Pro sp2

I know there is NAT taking place between (1) and (2). I don't want to place a single machine in the Linksys DMZ. The error I'm getting when I try to connect to (1) from (6) is 800. The VPN connection doesn't even seem to see the router (2).

Have tried to find an answer in this database, so now I ask the question. what am I missing?
0
Comment
Question by:trbagpiper
  • 2
5 Comments
 
LVL 32

Accepted Solution

by:
Luc Franken earned 125 total points
ID: 17909658
Hello trbagpiper,

I see you've opened up port 1723 TCP which is used for PPTP connections and port 500 UDP which is for IPSec connections, please verify which one you really need to have opened up. (and also, please mention which location you're using as a server)
Apart from this, I'm guessing that both Windows XP computers are in the 192.168.1.x subnet which will cause your VPN not to work, please move one of them out of that range by changing the local subnet on one end.

Greetings,

LucF
0
 
LVL 77

Assisted Solution

by:Rob Williams
Rob Williams earned 125 total points
ID: 17910229
A few suggestions:
You can confirm the XP VPN server and client configurations at:
http://www.onecomputerguy.com/networking/xp_vpn_server.htm
http://www.onecomputerguy.com/networking/xp_vpn.htm

-I assume the port forwarding method is fine where your RD works fine.
-You need PPTP pass-through enabled on #2 as you have done, and some folks also recomend doing so on #5 As LucF, stated you do not need UDP 500 as you are using PPTP not IPSec (Windows client)
-You do not need to remove #2 NAT but you shouldn't have multiple NAT devices at one end. If either modem is a combined modem and router it should be put in Bridge mode. I believe the Westell is one of these units, the Comcast is likely a basic modem. Westel instructions:
http://www.broadbandreports.com/faq/6323
-Some routers do not support VPN pass-through. Verify the D-Link model is OK, the Linksys should be fine.
-Try disabling the Windows firewall on #1, you may be still be blocking GRE (the PPTP encapsulation protocol)
-A few ISP's do not support PPTP. If still having problems verify with your service providers that they are not blocking that service.
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 18005083
trbagpiper, were you able to get your VPN functioning?
--Rob
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

914 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now