[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

I have 2 people who get an error 721 if either one of the 2 people are connected.

Posted on 2008-01-29
7
Medium Priority
?
237 Views
Last Modified: 2010-04-12
HI,

I have 2 people who authenticate to a Windows 2000 VPN server. Both client systems are Windows XP.  I have them set up to connect via a unique static IP address, which works fine if one or the other is not connected.  If either one is connected, the other one gets an error 721.  No one else of the potential 18 VPN users have any problems.  Do you have any suggestions as to what can cause this?  All help greatly appreciated!
0
Comment
Question by:jmattson30
  • 3
  • 3
7 Comments
 
LVL 5

Expert Comment

by:jlanderson1
ID: 20770922
Could it be a duplicate computer name?
0
 
LVL 15

Expert Comment

by:Robert Sutton Jr
ID: 20771253
There could be a few different reasons, but im thinking you are using PPTP? Is this correct? If so, read below...

> ports 1723 and 47
It's not port 47, it is protocol #47, GRE that needs to be forwarded. Since GRE has no concept of ports, you can't forward it to an inside host on the low-end routers like the Netopia.

Microsoft VPN Network Server

Microsoft's story:
PPTP traffic consists of a TCP connection for tunnel maintenance and GRE encapsulation for tunneled data. The TCP connection is NAT-translatable because the source TCP port numbers can be transparently translated. However, the GRE-encapsulated data is not NAT-translatable

From Cisco documentation:
Because the connection is initiated as TCP on one port and the response is GRE protocol, it is necessary to configure ACLs to allow the return traffic into the PIX, as the PIX Adaptive Security Algorithm (ASA) does not know the traffic flows are related. PPTP through the PIX with NAT (one-to-one address mapping) works because the PIX uses the port information in the TCP or User Datagram Protocol (UDP) header to keep track of translation. PPTP through the PIX with Port Address Translation (PAT) does not work because there is no concept of ports in GRE.


Setting up VPN server behind ICS system:
http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B309524


References:
http://www.labmice.net/networking/vpn.htm
http://www.microsoft.com/windows2000/technologies/communications/vpn/default.asp
http://support.microsoft.com/default.aspx?scid=kb;en-us;308208
http://www.microsoft.com/windows2000/techinfo/reskit/en-us/default.asp?url=/windows2000/techinfo/reskit/en-us/intwork/inbe_vpn_hidv.asp
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/columns/cableguy/cg0103.asp
http://www.microsoft.com/technet/treeview/default.asp?url=/TechNet/columns/tips/15tipsfo.asp

VPN w/ 2003 Server
http://www.microsoft.com/windowsserver2003/technologies/networking/vpn/default.mspx


Please read this post:
http://www.experts-exchange.com/Networking/Broadband/VPN/Q_21104260.html
0
 

Author Comment

by:jmattson30
ID: 20771786
Hi jlanderson1, The computer names are different.  

Hi Warlock, if there was any problem with the Gre or 1723 port which is open on both as all other VPN uses can connect fine.  The 2 people in question are only denied when one or the other individual is already connected.  I also have more PPTP ports available than I have users, so that would not be an issue either. Do you have any others suggestions?
0
Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

 
LVL 15

Accepted Solution

by:
Robert Sutton Jr earned 1500 total points
ID: 20772015
Map them to different ports.?? I would try anything at this point, but Im still leaning towards PPTP with the error:721
0
 

Author Comment

by:jmattson30
ID: 20878466
Although the problem was not about ports, it did have to do with PPTP in that the VPN connection was set for Automatic and not PPTP as it was supposed to be.  This seemed to have solved the problem.
0
 
LVL 15

Expert Comment

by:Robert Sutton Jr
ID: 20878810
Im glad I could point you in the right direction. Typically any 721 error points to PPTP. If it wasn't evident at first look, always go back and double check the settings.... Im glad you have it working now.
0
 

Author Comment

by:jmattson30
ID: 20878888
Thanks again!
0

Featured Post

Get expert help—faster!

Need expert help—fast? Use the Help Bell for personalized assistance getting answers to your important questions.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will show how Aten was able to supply easy management and control for Artear's video walls and wide range display configurations of their newsroom.
If you try to migrate from Elastix to Issabel, you will face a lot of issues. These problems are inevitable but fortunately, you can fix them. In the guide below, I will explain how I performed the migration while keeping all data and successfully t…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

590 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question