Link to home
Start Free TrialLog in
Avatar of snooflehammer
snooflehammerFlag for Australia

asked on

Can PPTP VPN be made to go both ways?

Can PPTP VPN be made to go both ways?

Windows Server A connects via PPTP to Windows Server B.

Server A can ping anything on Server B's network but Server B cannot ping anything on Server A's network.

Is there a way to make this two-way?

Only Server B is running RRAS
Avatar of Benjamin Van Ditmars
Benjamin Van Ditmars
Flag of Netherlands image

pptp vpn is a old client server base vpn and it is not save.

for network to network vpn use ipsec vpn.
PPTP is a point to point VPN connecting only the originating client to the remote network.

Only the client gets an ip on the remote LAn or a special ip on the remote side that is granted rights to access the remore lan.
Only the client is directly accessible if routing is properly configured.

Device to device IPSec VPN will achieve what you are after.
Openvpn has the site to site VPN capability.
You want a site to site IPSec VPN, which is more ideally done at the router level. Arnold has best explained out why you cannot use PPTP.

Now that said, *could* you do a site to site with Windows Server? Yes. Would I recommend it? No.
The good old days approach (when PPTP was really used for VPN) has been to set up two RRAS servers, each one acting as a client for one and server for the other direction, using two different connections. Each client had to initiate his own connection.

So with your config it is not possible to do so, even if PPTP would still be acceptable.

To throw in another alternative: SoftEther. Though I prefer OpenVPN.
Why not get 2 firewalls/routers and setup an ipsec site to site vnpn.
then you have a solid solution that will work perfect.
This question needs an answer!
Become an EE member today
7 DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform.
View membership options
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.