Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

xp vpn server behind BEFSR81 router with NAT

Posted on 2006-11-09
5
Medium Priority
?
4,401 Views
Last Modified: 2009-12-16
I'm trying to setup a VPN between my home network and my office. I can remote desktop to (1) fine from (6), forwarding TCP 3389 in router (2) just fine.

-----------------------HOME-------------------------------- Internet --------------------------- Office ----------------------------
1. XP sp2 ----- 2. BEFSR81 ----- 3. Cable Modem ----- Internet ----- 4. Verison DSL ----- 5. DLink Router ----- 6. XP sp2

1. XP Pro VPN Server, Static IP, Windows Firewall Ports TCP 1723, UDP 500 open
2. Linksys Befsr81 v.3 latest firmware. PPTP forwarding enabled, forwarding 1723, 500 to xp vpn server
3. Comcast RCA modem model unknown for now
4. Verison Westel DSL Modem
5. DLink router, model unknown
6. my office XP Pro sp2

I know there is NAT taking place between (1) and (2). I don't want to place a single machine in the Linksys DMZ. The error I'm getting when I try to connect to (1) from (6) is 800. The VPN connection doesn't even seem to see the router (2).

Have tried to find an answer in this database, so now I ask the question. what am I missing?
0
Comment
Question by:trbagpiper
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
5 Comments
 
LVL 32

Accepted Solution

by:
LucF earned 500 total points
ID: 17909658
Hello trbagpiper,

I see you've opened up port 1723 TCP which is used for PPTP connections and port 500 UDP which is for IPSec connections, please verify which one you really need to have opened up. (and also, please mention which location you're using as a server)
Apart from this, I'm guessing that both Windows XP computers are in the 192.168.1.x subnet which will cause your VPN not to work, please move one of them out of that range by changing the local subnet on one end.

Greetings,

LucF
0
 
LVL 77

Assisted Solution

by:Rob Williams
Rob Williams earned 500 total points
ID: 17910229
A few suggestions:
You can confirm the XP VPN server and client configurations at:
http://www.onecomputerguy.com/networking/xp_vpn_server.htm
http://www.onecomputerguy.com/networking/xp_vpn.htm

-I assume the port forwarding method is fine where your RD works fine.
-You need PPTP pass-through enabled on #2 as you have done, and some folks also recomend doing so on #5 As LucF, stated you do not need UDP 500 as you are using PPTP not IPSec (Windows client)
-You do not need to remove #2 NAT but you shouldn't have multiple NAT devices at one end. If either modem is a combined modem and router it should be put in Bridge mode. I believe the Westell is one of these units, the Comcast is likely a basic modem. Westel instructions:
http://www.broadbandreports.com/faq/6323
-Some routers do not support VPN pass-through. Verify the D-Link model is OK, the Linksys should be fine.
-Try disabling the Windows firewall on #1, you may be still be blocking GRE (the PPTP encapsulation protocol)
-A few ISP's do not support PPTP. If still having problems verify with your service providers that they are not blocking that service.
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 18005083
trbagpiper, were you able to get your VPN functioning?
--Rob
0

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Using Windows 2008 RRAS, I was able to successfully VPN into the network, but I was having problems restricting my test user from accessing certain things on the network.  I used Google in order to try to find out how to stop people from accessing c…
If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question