Networking Forums

Networking Forums > Computer Networking > Windows Networking > SP1 breakes VPN RRAS Server

Reply
Thread Tools Display Modes

SP1 breakes VPN RRAS Server

 
 
Franz Schenk
Guest
Posts: n/a

 
      09-06-2005, 01:13 PM
Have a problem with a Windows 2003 VPN RRAS Server. RRAS is configured as
"VPN Remote Access Server only", allowing only IPSEC/L2TP inbound
connections and enabling the Basic Firewall (without NAT) on the public
interface.

The server works fine, until SP1 installation. After that, the VPN Server
doesn't accept inbound connections anymore. Have found that the problem is
releated to the Basic RRAS Firewall. When removing the public interface from
the "NAT/Basic Firewall" category, the VPN Server accepts inbound
connections. But when adding the public interface to the "NAT/Basic
firewall" category, the server doesn't accept inbound connections anymore,
even when adding inbound and outbound filter rules that allow connections
from any to any over any protocol, and enabling all ICMP protocol rules.
It's also not possible to ping the external interface from a external
client.

When removing the public interface from "NAT/Basic firewall", inbound
connections work fine. Inbound connections also work fine when removing SP1,
with enabled firewalled public interface. Have installed SP1 tcp/ip hotfix
898060, no success. It's not a problem particular to one machine, I was able
to reproduce the problem with two virtual machines on my Notebook.

Thanks all in advance for any help or advice
Franz


 
Reply With Quote
 
 
 
 
Robert L [MS-MVP]
Guest
Posts: n/a

 
      09-06-2005, 08:49 PM
"when adding the public interface to the "NAT/Basic
firewall" category, the server doesn't accept inbound connections anymore,
even when adding inbound and outbound filter rules that allow connections
from any to any over any protocol" Have you check the port services? Or do a simple test to telnet port 1723.

Bob Lin, MS-MVP, MCSE & CNE
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
"Franz Schenk" <franz.schenkNOSPAM@fititNO-_SPAM.ch> wrote in message news:eXOI$(E-Mail Removed)...
Have a problem with a Windows 2003 VPN RRAS Server. RRAS is configured as
"VPN Remote Access Server only", allowing only IPSEC/L2TP inbound
connections and enabling the Basic Firewall (without NAT) on the public
interface.

The server works fine, until SP1 installation. After that, the VPN Server
doesn't accept inbound connections anymore. Have found that the problem is
releated to the Basic RRAS Firewall. When removing the public interface from
the "NAT/Basic Firewall" category, the VPN Server accepts inbound
connections. But when adding the public interface to the "NAT/Basic
firewall" category, the server doesn't accept inbound connections anymore,
even when adding inbound and outbound filter rules that allow connections
from any to any over any protocol, and enabling all ICMP protocol rules.
It's also not possible to ping the external interface from a external
client.

When removing the public interface from "NAT/Basic firewall", inbound
connections work fine. Inbound connections also work fine when removing SP1,
with enabled firewalled public interface. Have installed SP1 tcp/ip hotfix
898060, no success. It's not a problem particular to one machine, I was able
to reproduce the problem with two virtual machines on my Notebook.

Thanks all in advance for any help or advice
Franz


 
Reply With Quote
 
Franz Schenk
Guest
Posts: n/a

 
      09-07-2005, 08:24 AM
- The port services for PPTP and L2TP gateway, as well for IKE Security are open. And it's like I wrote in the previous message: The VPN server doesn't accept any connection to the firewalled interface over any protocol, including a telnet session to this interface over PPTP port 2723 (the connection fails).

- Have also installed Hotfix 897651, doesn't solve the problem as well.

Thank you all in advance for any further advice
Franz
"Robert L [MS-MVP]" <(E-Mail Removed)> schrieb im Newsbeitrag news:%(E-Mail Removed)...
"when adding the public interface to the "NAT/Basic
firewall" category, the server doesn't accept inbound connections anymore,
even when adding inbound and outbound filter rules that allow connections
from any to any over any protocol" Have you check the port services? Or do a simple test to telnet port 1723.

Bob Lin, MS-MVP, MCSE & CNE
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
"Franz Schenk" <franz.schenkNOSPAM@fititNO-_SPAM.ch> wrote in message news:eXOI$(E-Mail Removed)...
Have a problem with a Windows 2003 VPN RRAS Server. RRAS is configured as
"VPN Remote Access Server only", allowing only IPSEC/L2TP inbound
connections and enabling the Basic Firewall (without NAT) on the public
interface.

The server works fine, until SP1 installation. After that, the VPN Server
doesn't accept inbound connections anymore. Have found that the problem is
releated to the Basic RRAS Firewall. When removing the public interface from
the "NAT/Basic Firewall" category, the VPN Server accepts inbound
connections. But when adding the public interface to the "NAT/Basic
firewall" category, the server doesn't accept inbound connections anymore,
even when adding inbound and outbound filter rules that allow connections
from any to any over any protocol, and enabling all ICMP protocol rules.
It's also not possible to ping the external interface from a external
client.

When removing the public interface from "NAT/Basic firewall", inbound
connections work fine. Inbound connections also work fine when removing SP1,
with enabled firewalled public interface. Have installed SP1 tcp/ip hotfix
898060, no success. It's not a problem particular to one machine, I was able
to reproduce the problem with two virtual machines on my Notebook.

Thanks all in advance for any help or advice
Franz


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
RRAS and SQL Server Andrew Kennard Windows Networking 3 07-22-2008 08:18 AM
RRAS Server Barry Alan Windows Networking 6 06-30-2008 08:28 PM
RDP to RRAS server Jeff Vandervoort Windows Networking 2 05-23-2007 02:20 PM
Problems with Win2003 Server RRAS and Netgear print server Michael04 Windows Networking 0 03-06-2006 03:14 PM
I can´t access from Device Mobile to RRAS Server, Windows Server 2 Carlos Ortega-Colombia Windows Networking 1 11-02-2005 10:23 PM



1 2 3 4 5 6 7 8 9 10 11