Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

New to VPN could use some advice

Status
Not open for further replies.

sethcarter

Technical User
Jun 23, 2005
2
US
Hi all, I have set up RRAS on server 2003 to allow VPN connections. I have configured my user to be allowed to remote "dial in" however, the uses always gets error 800. I thought it may be an issues with my linksys router so I set up port forwarding and pptp passthrough ect. that still didn't work. So to test I make my VPN server the DMZ in the router and the user still got error 800. I'm not sure where to go from here? Any ideas?

Thanks
 
Error 800: Unable to establish the VPN connection. The VPN server may be un-reachable, or security parameters may not be configured properly for this connection.

Resolutions:
1) if you have firewall, open TCP Port 1723, IP Protocol 47 (GRE).
2) make sure you can reach the VPN server by using ping. Sometimes, poor connection can cause this issue too.
3) You may need to updated firmware on a router or firewall if other OS (win9x/nt/me/w2k) works except XP.
4) The VPN server may not be able to get IP from DHCP for the VPN client. So, you may want to re-configure VPN host networking settings. For XP pro VPN host, go to the Properties of the VPN>Network, check Specify TCP/IP address and Allow calling computer to specify its own IP address, and uncheck Assign TCP/IP addresses automatically using DHCP.
5) Make sure other secure software blocks your access, for example, if you use Norton secure software, you may need to add the remote client's IP so that the client can access.
6) If your VPN running on a Windows RRAS with NAT enabled, you may want to check the NAT settings.
 
Okay I ran through those and everything is fine, I tried from another off site location and it worked fine, so the problem lies with the user. However he can connect to a sonicwall VPN. Any idea of something that he can change to allow him to connect?
 
I am not the expert on this (and hopefully someone else may jump in) but I have seen a suggestion to set your client to either PPTP or L2TP (whichever you are using) instead of automatic. This may get a more meaningful error message than 'error 800'.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top