Solved

Windows 2003 VPN through Netopia router & Firebox 1000

Posted on 2009-07-10
11
280 Views
Last Modified: 2012-05-07
I am trying to setup a VPN for my users to connect to the office as they are doing more and more out of town work. I'm using the built in VPN stuff on my 2003 server and did the custom config during the routing and remote access setup because I'm using only 1 NIC. The Netopia router is a pass through to the Firebox III 1000. The Firebox is successfully forwarding (NATing) the PPTP request to my VPN server. I installed Wireshark (sniffer) on the VPN server and I can see the PPTP request being acknowledged by the server, but the connection is not made. The client errors out with 721.

I cant figure out what I'm missing...

0
Comment
Question by:chawness
  • 6
  • 5
11 Comments
 
LVL 32

Expert Comment

by:dpk_wal
Comment Utility
Are you using custom service or pre-defined PPTP service; please note other than TCP port 1723 we also need to allow IP protocol number 47 [GRE] [which is included in the predefined service].

If you are using PPTP predefined service with 1-1 NAT then things should work. Enable logging for the service and if you see allowed packets in system manager->Traffic monitor then the firewall is configured properly.

Can you check if you can make VPN tunnel to the server from the inside network; this would ensure that the server itself is accepting connections and the settings are correct.

Please check and update.

Thank you.
0
 
LVL 1

Author Comment

by:chawness
Comment Utility
I have both the custom and pre defined services (PPTP and wg_PPTP). I can see in the traffic monitor that both are allowing the connection through. Isn't IP 47 allowed through with the PPTP service?

Even tried adding the any service opening a hole to the VPN server and it still did not work.

I can make a tunnel from inside the network.
0
 
LVL 32

Expert Comment

by:dpk_wal
Comment Utility
As you using 1-1 NAT, please make sure that you have added NAT exceptions; also, that you do not have the IP used for 1-1 NAT in the external alias.

From the server if you access website, http://www.whatismyip.com you should be able to see the 1-1 NAT IP and not the external IP of firewall.

If above are correct then this should work.

Please check and update.

Thank you.
0
 
LVL 1

Author Comment

by:chawness
Comment Utility
Couple of questions. Where do I add NAT exceptions?

When you say external alias do you mean under network, configuration, interfaces tab - aliases?

whatismyip.com shows the external IP of the firewall.
0
 
LVL 32

Expert Comment

by:dpk_wal
Comment Utility
In Policy Manager, go to Setup->NAT->Advanced->1-1 NAT Setup [here you would have an entry like:
external, 1, x.x.x.x, y.y.y.y]; now click Dynamic NAT Exceptions tabl click Add; in the From type the internal IP of the server; in the To box from drop down select "external" keyword. Click Ok all the way back.

For alias, go to Network->Configuration->Interfaces->click Aliases, here ensure the public IP is not listed; if listed; please remove it, the firebox would reboot after you saved changes.

From the server you should not see 1-1 NAT IP.

The things should work now.

Thank you.
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 1

Author Comment

by:chawness
Comment Utility
I made the changes you suggested. Now I can see the 1-1 NAT IP from the server. However I still cant make the connection from outside. Using Wireshark I can see the communication begin on the server when I try to connect from the outside. The server will send a PPTP ACK command to the client, then the client will send a call-clear-request?

Just FYI - The computer I am trying to connect with is a VISTA machine with a Sprint air card. I have also tried with a XP Pro machine and the air card, both produce the same results.
0
 
LVL 32

Expert Comment

by:dpk_wal
Comment Utility
Hmm if the traffic is going through fine then the firewall settings are correct; this brings us to the point that the problem is either with client or the server itself.
As you can establish the tunnel internally without problem this seems that the server settings are also correct.

As you have already tried two different machines this means that the machine is not the problem here.

Have you tried connecting from a different ISP. may be this ISP is blocking the PTPP traffic and causing the problem.

Please check and update.

Thank you.
0
 
LVL 1

Author Comment

by:chawness
Comment Utility
OK I just called home and talked my 12 year old daughter through setting up a new VPN connection on our XP Pro machine. Its using a DSL connection.  When trying to connect she received error 721.

I noticed in Wireshark after the server sends the pptp ACK message, then it starts communicating with the DC via the TCP protocol. After the 2 servers are through communicating, the client sends a call-clear-request. The connection errors out just afterward...
0
 
LVL 32

Accepted Solution

by:
dpk_wal earned 500 total points
Comment Utility
Sorry but as this is more to do with VPN server configuration/settings and not the firewall; I would not be best of help here.

May be some other expert would be able to assist you further with.

One more thing before I let go; can you check if the Netopia is blocking anything [if possible; put the server directly behind Netopia bypassing the WG, this would make few things clear].

Thank you.
0
 
LVL 1

Author Comment

by:chawness
Comment Utility
My friend I have but one word for you.... SUCCESS!!!!!!!!!!!!!!!!!!!

The Netopia was the culprit. I basically had to do everything you said plus the following in the Netopia:

Main Menu
System Configuration...
 Filter Sets...
 IP filter sets...

display change IP filter set

basic firewall

add input filter to filter set

source IP 0.0.0.0  Dest IP 0.0.0.0 Protocol ANY On=yes Forward=yes

And yes I fell out of my chair when it worked...

FYI for anyone reading this: Netopia R5300 T1 Router, Watchguard Firebox III 1000, Windows Server 2003 VPN.
0
 
LVL 32

Expert Comment

by:dpk_wal
Comment Utility
Thank you for the update and the points! :)
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

When you connect to your workplace's VPN, you may not notice that you are using your workplace's servers to serve up webpages.  This might be undesirable since the workplace can log all the places you've been.  It also might be very slow to load pag…
Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now