Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Using VPN client for web app hosting

Posted on 2014-03-17
Medium Priority
Last Modified: 2014-03-24
My ISP is blocking port 443.  I can get around that by running StrongVPN on my web app server, but it intercepts all traffic including domain traffic intended for the 2nd NIC.  What I want is for all domain traffic to go over NIC2 and all internet to go over NIC1 while the StrongVPN client is running.  I contacted StrongVPN before coming here, but they are unable to assist since it is not a true connectivity problem.

What do I need to do to make this work?
Question by:CPA_MCSE
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
LVL 43

Expert Comment

ID: 39936288
Have you contacted your ISP to allow 443 to be open?  

Have you considered running on a non standard port e.g.  Very easy to set up a redirect to that from a sub domain if your clients need to have an easier address to remember e.g. would redirect to

Author Comment

ID: 39936650
I tested that previously and and other tools told me the alternate port was not open either.  

On the router side, I had it port-forwarding from (using your example) 8443 to 443 on my server (because the web app requires 443).  After that did not work, I also enabled port triggering to send 443 traffic from the server out through 8443.  So, at that point, 8443 was going to 443 and 443 was going out to 8443.  No dice.  Port 8443 not open either.  

The ISP and the server is in a country where nobody on the phones has any idea what is a port.  I also tried with a native speaker as middle-man, but still no clue...

So, my StrongVPN work-around works fine except that the machine cannot communicate with the local domain when the VPN client is turned on.  That is the problem I am hoping someone can help me resolve.

I tried running StrongVPN (DD-WRT) on the router and connecting the internet NIC to that, but for whatever reason 443 reports as blocked although StrongVPN asserts they are not blocking it.  So, now I am back to trying to run the client directly on the machine because that reports 443 as open BUT it cannot communicate with the domain.

At this point, the router is also suspect and so I want to cut that out of the equation and run the client directly on the/a machine.  Suggestions about how to get it to work so that I don't also lose domain traffic?
LVL 43

Expert Comment

ID: 39938288
Have you considered getting your site hosted outside of his restriction?

Aside from that, most VPN clients have a setting whether to route all traffic through the VPN gateway.  What client are you using to connect to the VPN as I know where it is in Windows but not sure in other clients.
Cyber Threats to Small Businesses (Part 1)

This past May, Webroot surveyed more than 600 IT decision-makers at medium-sized companies to see how these small businesses perceived new threats facing their organizations.  Read what Webroot CISO, Gary Hayslip, has to say about the survey in part 1 of this 2-part blog series.


Author Comment

ID: 39938674
I am using StongVPN's client.  I believe it to be an implementation of OpenVPN.  I will look into it to see if maybe I can use vanilla OpenVPN or some implementation with those options.

Hosting it elsewhere is not an option.

Author Comment

ID: 39938688
It looks like you may be on to something there, Rob.  I clueless about how to set routes, but I think it would be possible to force a route in the OpenVPN config file.  Here is what is in one of my old config files (not the one used by the server).

remote 4672 udp
remote 123 udp
remote 53 udp
key-direction 1
dev tun
resolv-retry infinite
;http-proxy-retry # retry on connection failures
;http-proxy [proxy server] [proxy port #]
verb 4
reneg-sec 86400
echo vpn-dc5 ovpn224
tun-mtu 1500
route-method exe
route-delay 2
redirect-gateway def1
comp-lzo adaptive
explicit-exit-notify 2
fragment 1390
mssfix 1390
hand-window 30

Any idea what to put to force internet traffic over a specific NIC (preferred)?  Or (using just one NIC) exclude local domain traffic?

Accepted Solution

CPA_MCSE earned 0 total points
ID: 39940150

Microsoft changes the network profiles to Public for guest machines when Hyper-V guests restart without being able to connect to a DC.  With the network profile set as Public, the guest was blocking everything.  I manually changed the network profile to Private and port-forwarding works just fine now.  No need for StrongVPN...

Thanks, MSFT for wasting my f time.  I am unable to figure how to set one NIC as private and the other as Domain, but whatever.  I can go back to using a single NIC now...
LVL 43

Expert Comment

ID: 39941447
Great news... well done

Author Closing Comment

ID: 39949806
See comment

Featured Post

Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This program is used to assist in finding and resolving common problems with wireless connections.
This article will show how Aten was able to supply easy management and control for Artear's video walls and wide range display configurations of their newsroom.
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question