Avatar of cfwilbur
cfwilbur
 asked on

Problems setting up VPN from Vista

I'm on a laptop running Vista Ultimate and I'm trying to create a VPN connection to my office.  The router at my office is a Linksys WRT54GS.  I've got it forwarding requests on port 1723 to a Windows Server 2008 R2 (64 bit) server.  I've opened port 1723 using an inbound rule on the 2008 Server firewall.

When I try to connect to the VPN, it fails and when I have Vista diagnose the problem, it gives me the following message:

Error Message on Vista Ultimate client
Can anyone help me out?

Thanks!
VPNWindows VistaWindows Server 2008

Avatar of undefined
Last Comment
cfwilbur

8/22/2022 - Mon
Qlemo

Did you also set up PPTP/VPN passthru on the WRT?

Also, there seem to be firmware releases which are not able to support PPTP passthru as needed.

You could try to switch to L2TP/IPSec, which needs udp/1701 (and udp/500, udp/4500 for IPSec might also be needed to be forwarded). L2TP just needs a secret password, called a pre-shared key, which is common for the server and all clients, and is hence easy to set up.

And there is always the free DD-WRT firmware, which allows to use the router itself as VPN server, eliminating many issues with port forwarding and firewalling.
Jackie Man

Have you created an outbound rule of the TCP port 1723 for the windows firewall of your Vista Ultimate?
cfwilbur

ASKER
Olemo - Yes, I've set up PPTP/VPN passthru on the router.

Jackie - I haven't specifically done that, but I can VPN into other networks, so I'm assuming that port is clear.

If anyone has thoughts on this, I'd love to hear them!

Thanks.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
Jackie Man

It is better to check the rules in windows firewall of your vista pc.
Qlemo

The Windows Firewall is (usually) not configured to filter outbound connections, only inbound. Even more unlikely a filter is applied to allow only a single gateway. But it might be the case.
Switch off the firewall for the test, to exclude any issue related to it.
BTW, it is not sufficient to only open port 1723, you need protocol 47 (GRE), too. W2008 & Co have a particular firewall policy to allow inbound VPN connections, which should be active automatically as soon as you configure RRAS on the server.
cfwilbur

ASKER
Tried turning off firewall in Vista, and enabling the pre-set firewall inbound rule on the router for GRE.  No luck.  I'm attaching screen shots.  I thought you might have meant having GRE as a port-forwarding setting, so I tried that also.  Still a "no go".  Thanks so much for helping me out!! Port Forwarding Settings on Router Windows Diagnosis on Vista Remote Client
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Qlemo

I've emphasized the word protocol in conjunction with 47 - you defined port 47, a common misunderstanding. However, your Linksys should already manage that if you switch on PPTP/VPN passthru.
cfwilbur

ASKER
Forgive my stupidity, but where would I go to see if that port is open? Are we talking about windows firewall inbound rules, or a setting on the router?

Thanks again for your time, patience and willingness to share your knowledge!
Qlemo

That is the issue with GRE - since it is an own protocol, it is more like UDP without ports, and so you cannot check on active connections whether it is used and forwarded or not. Your router is not that sophisticated to support you in debugging, so the only means to see what happens is by capturing related network traffic.

Reallly, PPTP is not worth going thru all that trouble. L2TP/IPSec is similar easy to set up, and has less potential issues.
Your help has saved me hundreds of hours of internet surfing.
fblack61
cfwilbur

ASKER
I've tried setting up L2TP as you can see in my screen shot posted earlier, but still can't get connected.  Am I missing a step, other than setting up those ports on my router's port-forwarding table?

Thanks....
Qlemo

All you should need to do is to forward L2TP (1701/udp). IPSec (500/udp and 4500/udp) should not be required to be forwarded, but it doesn't harm to do so.
cfwilbur

ASKER
Looking at my screen shot above, haven't I already done that?
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
cfwilbur

ASKER
Here are my current port forwarding settings on my router:

 Router Settings
Qlemo

Do you need to excempt that ports in the firewall, maybe?
cfwilbur

ASKER
Firewall already adjusted, still can't connect.
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
ASKER CERTIFIED SOLUTION
Qlemo

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
cfwilbur

ASKER
Although I haven't attempted the proposed solution yet, I believe this is as far as I can go on this question.  Qlemo has been very generous with his time and I really appreciate the effort!  If a new issue branches off of this one, I'll just post a new question.  Thanks so much!