Link to home
Start Free TrialLog in
Avatar of Joe Frusci
Joe FrusciFlag for United States of America

asked on

Creating a PPTP Tunnel with two routers on network.

I would like to create a PPTP tunnel to my computer at home.  However, at home I have Verizon FIOS.  They provide a router/firewall with IP address of 192.168.1.1.  While still using the one Verizon provided, I also have a Cisco WRVS4400N VPN router/firewall that I put behind the Verizon router.  To get this to work, I just assigned the Cisco router an IP address of 192.168.5.1 and have all my PC's assigned an IP of 192.168.5.2-100.  

I now want to create PPTP from my work computer to my computer at home.  I enabled port forwarding from the verizon router to the cisco router, and from the cisco router, I am doing port forwarding to my home PC, but am still not able to create the PPTP connection.  I receive error 720 from my work computer.  

If I remove the Cisco router and leave the verizon router, as well as change all the port forwarding to go just from the verizon router to the home PC, I can connect.  

Any ideas on how to get this to work with the cisco router in place?
ASKER CERTIFIED SOLUTION
Avatar of Qlemo
Qlemo
Flag of Germany image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Joe Frusci

ASKER

Ok...If i go with the alternative of "Try to put the Verizon into Bridge/Routing Mode, not performing any NAT. The Cisco should then perform any necessary NAT."  How do I do this?  I am weak in the networking area, so keep that in mind when explaining this.
L2TP with IPSec as Qlemo suggests above is, IMO, the best option for this type of VPN, pptp is hard to secure and very contrary. No answer here, just backing above recommendation.
Bridging or Routing Mode is usually set up by just switching a setting in the router usually. But don't ask for details ;-). Your ISP should be able to provide you with the necessary procedure.
Would that be a Static NAT feature?
No, no NAT. The Verizon just relays the packets received on each side to the other one, not changing anything but the next router IP. So all traffic from the Web would be transferred to the Cisco with its public IP, and the Cisco then does the NAT and port forwarding to your local network.
so you have two routers thats not going to work
Which Verizon supplied router do you have?   What model?  9100EM?
I have the Actiontec MI424WR
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Since the accepted answer is based on my first comment, I would expect the latter to be an assist, with a share of maybe 100 points out of 500. Any reason why you did not?
You are right and I apologize.  I submitted a request to the moderator on splitting the points.  
Since Qlemo first suggested the solution that did work, I am awarding him with most of the points.  However, Jim-R did go into further detail on the solution that worked for me and awarded him with the remainder of the points.
Thank you, though I wanted to suggested it the other way round ... Let's leave it at that.
Qlemo:

I appreciate that you see it that way and have the courtesy to acknowledge it.  In other cases here, I have not been so fortunate, but lets leave it at that.

I did not mean to insult anyone...I hope you see that I was trying to be fair.