Networking Forums

Networking Forums > Computer Networking > Windows Networking > L2TP/IPSec VPN Windows Server 2003

Reply
Thread Tools Display Modes

L2TP/IPSec VPN Windows Server 2003

 
 
kevanh
Guest
Posts: n/a

 
      02-02-2006, 07:30 AM
I have setup a test environment where I have a:
1. 2003 DC,DNS,DHCP,WINS,Certifiate server.
2. 2003 VPN server - 2NICs, RRAS
3. Windows XP Client (SP2) connecting with client certificate

All works OK if VPN server Internet NIC exposed on the Internet
Does not work if Cisco 871W router/firewall/NAT installed
Have tried many different scenarios with no change in the results.
Would like to have the Cisco 871W router provide all the port security & not
expose the VPN server to the Internet.

Any extra lightbulb ideas appreciated.

Thanks in advance.
 
Reply With Quote
 
 
 
 
alexk
Guest
Posts: n/a

 
      02-02-2006, 09:11 PM

Kevnanh,

Are we using IPSEC/L2TP? or MPPE/PPTP?

On the Cisco you will need to pulish IKE UDP 500 and ESP protocol ID 50 for
L2TP with IPSec. You may need UDP 1701 for the connection depending on your
setup (need more info possibly).

For PPTP - Protocol ID 47 GRE packets- the tunnel for PPTP data packets and
TCP 1723 for the PPTP connection.

You need to forward these port- check your IOS version to see what you can
support. These are the only ports and protocols you need for the VPNs.

alex k
"kevanh" wrote:

> I have setup a test environment where I have a:
> 1. 2003 DC,DNS,DHCP,WINS,Certifiate server.
> 2. 2003 VPN server - 2NICs, RRAS
> 3. Windows XP Client (SP2) connecting with client certificate
>
> All works OK if VPN server Internet NIC exposed on the Internet
> Does not work if Cisco 871W router/firewall/NAT installed
> Have tried many different scenarios with no change in the results.
> Would like to have the Cisco 871W router provide all the port security & not
> expose the VPN server to the Internet.
>
> Any extra lightbulb ideas appreciated.
>
> Thanks in advance.

 
Reply With Quote
 
kevanh
Guest
Posts: n/a

 
      02-03-2006, 10:21 AM
Thanks for the reply,
I have already completed all the port forwarding & opened the appropiare
ports required.

I believe that this is a much more advanced issue...currently I have been
recommended to get 2 fixed IPs from the ISP & do Nat on the inside unterface.
Will post any other results as I get them


"alexk" wrote:

>
> Kevnanh,
>
> Are we using IPSEC/L2TP? or MPPE/PPTP?
>
> On the Cisco you will need to pulish IKE UDP 500 and ESP protocol ID 50 for
> L2TP with IPSec. You may need UDP 1701 for the connection depending on your
> setup (need more info possibly).
>
> For PPTP - Protocol ID 47 GRE packets- the tunnel for PPTP data packets and
> TCP 1723 for the PPTP connection.
>
> You need to forward these port- check your IOS version to see what you can
> support. These are the only ports and protocols you need for the VPNs.
>
> alex k
> "kevanh" wrote:
>
> > I have setup a test environment where I have a:
> > 1. 2003 DC,DNS,DHCP,WINS,Certifiate server.
> > 2. 2003 VPN server - 2NICs, RRAS
> > 3. Windows XP Client (SP2) connecting with client certificate
> >
> > All works OK if VPN server Internet NIC exposed on the Internet
> > Does not work if Cisco 871W router/firewall/NAT installed
> > Have tried many different scenarios with no change in the results.
> > Would like to have the Cisco 871W router provide all the port security & not
> > expose the VPN server to the Internet.
> >
> > Any extra lightbulb ideas appreciated.
> >
> > Thanks in advance.

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Step by Step for vpn using l2tp and preshared secret on a single Windows 2003 Server? jbwilson@gmail.com Windows Networking 0 10-16-2006 12:05 PM
windows mobile L2TP/IPSEC to win2k3 chris82 Windows Networking 3 06-06-2006 04:48 AM
2003 VPN Server L2TP/IPSEC HELP chris Windows Networking 0 11-03-2005 03:28 PM
Windows 2003 L2TP/IPSec problem Sameer Windows Networking 0 05-02-2004 11:40 PM
Windows server 2003 IPSec BUG!!?? Maarten Wensveen Windows Networking 0 03-02-2004 02:33 PM



1 2 3 4 5 6 7 8 9 10 11