Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How to correctly set up RRAS and VPN

Status
Not open for further replies.

adiMasher

Programmer
Aug 31, 2001
144
US
I inherited someone else's mess. When I got it RRAS was set up and apparently working for VPN services. I had read that in order to make RRAS work you need two NICs. The last guy only had one enabled.

what I have run into recently was I had made some changes to the RRAS settings when I probably shouldn't have, plus I removed the (redundant) NIC.

here's what I want to accomplish, my VPN users can dial in, authenticate and access the server's files and what not, but they are unable to browse the rest of the network. is this due to a lack of 2nd NIC or am I missing something else (probably obvious)

thanks for your attention to this.

Martin

If the sky is blue and the Sun is yellow.... Why isn't the air Green?
 
There are several MS docs that indicate that two interfaces are required for a VPN server. Most assume that the Windows server is either acting as a firewall or parallel to the firewall and as such has a LAN connection as well as a WAN connection. If you are behind a firewall and NAT, this no longer becomes an issue. You only reside on the LAN, so you only have one IF.

You are missing something else. Not sure what. Yet.

First thing to check, make sure routing is enabled. I suppose removing the card could have monkeyed with that. Start Routing and Remote Access in Administrative tools. Right click the server name, click properties. On the IP tab, make sure the 'Enable IP Routing' box is marked.

Beyond that, some questions first.

Can you ping the other hosts on the LAN from the VPN client? Try by name and by IP. If not, what response do you get to ping?

What about a good old 'net view \\computername'. If that doesn't fly, how bout 'net view \\LANcomputerIP'?? Remeber, specific error messages.

 
The ping works with the IP addresses but not the names.

the errors are as follows
Code:
D:\Documents and Settings\masher\Desktop>net view \\thomas
System error 53 has occurred.

The network path was not found.


D:\Documents and Settings\masher\Desktop>net view \\server
System error 5 has occurred.

Access is denied.

I had heard before that I didn't need the extra interface. And what I've done is actually disabled and re enabled the RRAS stuff so that I could get to the wizard and I followed that to set it up. I'm hoping that it's something like DNS.

Other interesting thing to note about all of this. I didn't start noticing any issues until I installed SP3 for Exchange.

Thanks,
Martin

If the sky is blue and the Sun is yellow.... Why isn't the air Green?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top