Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Error 721, vpn100 symantec firewall, 2000 terminal server, red herring

Status
Not open for further replies.

jlgdeveloper

Programmer
Jun 15, 2002
105
0
0
US
Equipment
symantec vpn 100 firewall/router, static ip, dsl
windows 2000 terminal server, one nic
TCP port 1723 and 47 are open to the server from wan
User permissions are correct, policies are correct
Internally, an XP machine could establish the vpn
Externally, error 721 the remote computer is not responding when using the automatic protocol setting (defaults).
Externally error 781, no valid encryption certificate when using the L2TP protocol.
Externally, using SLIP, an NT server could establish a vpn of sorts, which disconnected within minutes and did not allow mapping of network drives nor did it show on the routing and remote access console...red herring?
The dhcp server (router) has leased ten initial dynamic ips to the win2k server.
For testing, did open up (DMZ) all ports to the server, no change.
Noted a post where dhcp serving was moved to the server from the router and the issue was resolved.
Any thoughts on the firewall/issue?
Jonathan Galpin
 
Everything in your message is correct, except for the Port 47 part.
What you really need to do is not open port 47, but instead open all ports to enable protocol 47 (GRE).
GRE is a protocol just like TCP and UDP. For example, in my Cisco 678 router, I can forward all incoming ports that use the GRE protocol to one PC in my network with the ip address of 192.168.0.1 using the following line:

nat entry add 192.168.0.1 0 47

where: 0 is a representation of ALL ports and 47 = GRE protocol.

I hope this helps.

Javier
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top