Solved

2Wire 1800-HG and GTA GB200 VPN Issues

Posted on 2008-06-11
3
734 Views
Last Modified: 2008-06-26
A few days ago the BT supplied router at one of our residential homes failed completely and has been replaced by a 2Wire 1800-HG, this in turn is plugged into the GB200 firewall which is then plugged into the LAN switch.  The home has internet access and can access email using OWA however the secure VPN's on the firewall that we use to connect to our main servers will not accept any traffic.  This means that while the home can get email via OWA they cannot access the remote server based pay system, Exchange through the Outlook client, or any of he shared server resources.  None of the settings have been changed on the firewall box which worked quite happily with the original router.  Any suggestions would be much appreciated.
0
Comment
Question by:Brookdaleal
  • 2
3 Comments
 
LVL 77

Expert Comment

by:Rob Williams
ID: 21765415
Was the previous device a combined modem and firewall or just a basic Modem? The new unit is both. As a rule, you cannot connect to a VPN if you are behind 2 NAT devices (routers). To get around this the normal procedure would be to put the 2 wire unit in bridge mode, effectively making it a basic modem.
The following are for different model 2 wires but hopefully the instructions for changing to Bridge mode are similar:
http://www.dslreports.com/faq/10495
http://www.tek-tips.com/viewthread.cfm?qid=1212752&page=1
0
 

Accepted Solution

by:
Brookdaleal earned 0 total points
ID: 21810925
Thanks for your comments RobWill.  I managed to get some help from British Telecom (no mean feat) - their ethernet team called the soultion "port forwarding" not bridging.  It seems that using the bridge method would have disabled the router entirely rather than just its native firewall functionality.

I am not sure what the EE etiquette is here - your answer  - while appreciated - was not the solution.  As you were the only respondant - must i give the points anyway or can I opt to close the question as "solved by user".

I'm dont want to annoy you by closing incorrectly as i may need your help in the future!!

please advise

regards
alex
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 21812488
Hi Alex.
Port forwarding is a common solution for non-VPN services. However, VPN's do not like having the client address NATed (Network Address Translation) twice. This is why you put the outer most router in bridge mode effectively disabling all but it's modem capabilities. You are correct this would disable its router and firewall features, however there was an existing GB200 firewall in place as protection.

Normally; 1) port forwarding will not resolve the issue, and 2) port forwarding is done at the VPN server end, not the client.

However, if it works, great!
I am not offended at all if you would like to close and award your last response as the accepted answer, it is <G>. I do appreciate your taking the time to post your findings. I learn from that as well as those that follow with similar problems.
Cheers !
--Rob
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question