Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Comcast SMC Modem blocking PPTP

Posted on 2008-06-19
7
Medium Priority
?
7,201 Views
Last Modified: 2013-12-14
Hi,

We have a Comcast Business SMC Networks modem hardware version 1B and are having problems getting PPTP to pass through.  I have called Comcast and they say it should work.  The only options for port forwarding on this modem are for TCP and UDP.  We need the GRE packet forwarded to enable PPTP to reach the server.  If we enable DMZ to the server, we can VPN to the server.  However, this opens up all ports.  We have called in and asked if they can enable PPTP passthrough on their end and they say they cannot.  Is there a way to forward the GRE packet on this modem without using DMZ?  
0
Comment
Question by:OAC Technology
  • 4
  • 2
7 Comments
 
LVL 44

Expert Comment

by:Darr247
ID: 21831413
According to http://www.iana.org/assignments/port-numbers PPTP should use TCP or UDP port 1723.
Did you try forwarding port 1723 on both TCP and UDP?
0
 
LVL 2

Author Comment

by:OAC Technology
ID: 21833103
yes, it is already forwarded.
0
 
LVL 44

Expert Comment

by:Darr247
ID: 21834943
Does the comcast unit have port triggering, too?
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 2

Author Comment

by:OAC Technology
ID: 21838337
yes
0
 
LVL 44

Accepted Solution

by:
Darr247 earned 2000 total points
ID: 21839452
With 1723 TCP/UDP entered in the port triggering can you initiate the connection going in the other direction?

Here is the technical description of PPTP connections:
http://www.ietf.org/rfc/rfc2637.txt?number=2637
Rather dry reading, though.

You don't mention what OS either end is using, but if they're microsoft, here are some troubleshooting tips:
http://support.microsoft.com/kb/241251
http://support.microsoft.com/kb/241252
http://support.microsoft.com/kb/164601

I also saw a couple articles that described a problem that occurs when both ends are using subnets that can appear in the subnets of the other end too (e.g. 10.10.10.0/24 and 10.10.0.0/18) ... but your description doesn't mention the other end employing a private subnet from behind a router.

Do you have another router to try forwarding port 1723 on so you can ask comcast to replace the SMC unit if that works?
Do you have to manually apply firmware updates to the SMC or are they pushed out automatically by comcast during low-traffic periods?
0
 

Expert Comment

by:SublimeComputerServices
ID: 34992959
This is an old post but Comcast has added the GRE protocol in the port forwarding tab of the firewall.

You have to create two rules:

You still have to have port 1723 forwarded to your server.  Then you add the GRE protocol to forward to your server as well.
0
 
LVL 44

Expert Comment

by:Darr247
ID: 36536051
Another update...
The Internet Assigned Numbers Authority (IANA) has changed the link to their list of well-known/assigned ports...

here are the new URLs:

XML version - http://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
Text version - http://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…

783 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question