?
Solved

How to setup Windows 2003 as Router or site to site VPN

Posted on 2010-01-09
12
Medium Priority
?
546 Views
Last Modified: 2012-05-08
I have two question in regards to windows:

1. In what situations is Windows 2003 should be used as a router. Has anyone uses it and how would you do it?

2. I know how you can it as VPn server for Client-VPN, but is there any way to do a site to site vpn to another device or another windows 2003 server.
0
Comment
Question by:netcomp
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 3
  • +1
12 Comments
 
LVL 1

Assisted Solution

by:gktech
gktech earned 400 total points
ID: 26275155
1. it can be used for basic routing tasks but would not trust it as much as a real router

2. can be done but prone to problems, not as reliable as using 2 cisco pixes

start here
http://technet.microsoft.com/en-us/library/cc758232(WS.10).aspx

G
0
 
LVL 21

Accepted Solution

by:
farazhkhan earned 800 total points
ID: 26275205
Hi,

Q. 1 -a-. In what situations is Windows 2003 should be used as a router.
Ans:  Because you can? Okay, thats not really a good answer. But youve probably wondered why you'd use Windows Server 2003 as a router rather than using a dedicated router from Cisco, Bay Networks, or another manufacturer. In a lot of situations, a dedicated router makes more sense and is generally less expensive. There are situations, however, where it makes sense to use Windows Server 2003 for routing. Check this for complete details: http://articles.techrepublic.com.com/5100-22_11-5302652.html

Q. 1-b-. Has anyone uses it and how would you do it?
Ans: This is how you do it: http://articles.techrepublic.com.com/5100-10878_11-5844624.html

Q. 2. I know how you can it as VPn server for Client-VPN, but is there any way to do a site to site vpn to another device or another windows 2003 server.

Ans: http://technet.microsoft.com/en-us/library/cc758232(WS.10).aspx 
or
http://blog.netnerds.net/2006/04/site-to-site-vpn-using-windows-2003/

Regards,
Faraz H. Khan
0
 
LVL 2

Expert Comment

by:kishg
ID: 26275921
i have used Windows-VPN site to site for several years , it worked fine except ocassional breakups. You need to configure your RAS , add static routes , gateways and NAT. Its quite simple to achieve. I wrote a script which sent me an e-mail everytime it sensed a broken connection which lasted for more than 15 minutes.  
0
ATEN's HDBaseT Presentation at InfoComm 2017

Hear ATEN Product Manager YT Liang review HDBaseT technology, highlighting ATEN’s latest solutions as they relate to real-world applications during her presentation at the HDBaseT booth at InfoComm 2017.

 
LVL 1

Author Comment

by:netcomp
ID: 26276050
Kishg,
 I would love to do a site to site, but not sure how to go about crating the routes, gateway and the NAT.
It wold help if you can give me some pointers and also anywhere I can get the scrip. I guess it keeps checking the link??
0
 
LVL 2

Assisted Solution

by:kishg
kishg earned 800 total points
ID: 26276104
Lets start with site 1, configure a server for Routing and Remote Access for VPN, once done add New Demand and Dial interface (Right click on Netowkr Interface and click New Demand and Dial interface) for site 2 specifying site 2's public IP , configure other details including static route for site 2's LAN, user name/password for site 2 access. Now add NAT/Basic Firewall and use the above created DAD .

Now left click on Network Interface and click connect.

Do the same setup on Site 2 for Site 1 and connect.

You should now be able to ping to both site's internal IPs . You might want to configure DAD to be persistent in its properties and reconnect after disconnection options.

(IMPORTANT: Ensure that any firewalls at either sites are configured to forward RAS port to these servers).

Yes, the script could be a simple which pings to the other site's internal IP and sends e-mail address when ping request times out. You could also configure outlook instead of script at each site to constantly send out e-mails to each other which uses this link to send and receive e-mails, if you didn't recevie e-mail for longer than defined times , there is something wrong.

 
0
 
LVL 21

Expert Comment

by:farazhkhan
ID: 26277631
Hi,

Static Routes
The old standby and most peoples introduction to IP routing, static routes are also available in RRAS. Static routes allow you to manually define routes for this server rather than using a routing protocol such as RIP or OSPF. Static routing is generally used on small, static networks.

To create a new static route, right-click Static Routes under IP Routing and select New Static Route from the shortcut menu. To define a static route, you need the destination networks address (the network address for a network route or the host address for a host route), the network mask for the destination, and the IP address of the gateway used to get to this network.

Check this: http://articles.techrepublic.com.com/5100-10878_11-5089192.html

Regards,
Faraz H. Khan
0
 
LVL 1

Author Comment

by:netcomp
ID: 26279826
Greate.,
I just wanted to re-ask the second part of the question.

Is there any way to do a site to stie VPN to antoher device. For instance, a site to site to a Cisco firewall or vpn rotuer.
0
 
LVL 1

Expert Comment

by:gktech
ID: 26279840
0
 
LVL 21

Expert Comment

by:farazhkhan
ID: 26281791
Hi,

Yes, it is possible simple define the filter & select proper authentication mode from Windows 2003 which is negotiated by the Cisco, so that Windows RRAS can recognize it, check this: http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800b12b5.shtml

This thread is for Windows 2003 and would help you much: http://www.petri.co.il/forums/showthread.php?t=37937

Regards,
Faraz H. Khan
0
 
LVL 1

Author Comment

by:netcomp
ID: 26289882
Wow, lots of great info on this post.
I got one last question ( I promise :-) )  

Farazhkhan: mentioned above:
           "Static routes allow you to manually define routes for this server rather than using a routing protocol such as RIP or OSPF. Static routing is generally used on small, static networks."

Does that mean that Windows 2003 does not support RIP or OSPF???
0
 
LVL 1

Expert Comment

by:gktech
ID: 26290725
0
 
LVL 21

Expert Comment

by:farazhkhan
ID: 26312188
Hi,

That is about the Static route which can also be defined but feasible for the smaller networks, other then that OSPF, RIP all are supported by Windows 2003 RRAS.

Regards,
Faraz H. Khan
0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…
Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question