The desire is to allow clients to connect to the lan via an internet connection.
-To start off, the lan is a win2k domain. The domain server is a seperate box on the network running dhcp, dns and wins.
-The vpn server is also running win2k with 2 nics. TCPIP Filtering for nic1(wan) is configured to only permit tcp port 1723 and udp port 47. No other tcp, udp ports or ip protocols are permitted for the wan adapter (this may be a problem, I'm not sure).
-nic1(wan): has a static internal ip which has been mapped by the T1 provider to a static public ip:
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix :
Description . . . . . . . . . . : 10/100adapter
Physical Address. . . . . . . . : 00-20-78-1E-E
DHCP Enabled. . . . . . . . . . : No
IP Address. . . . . . . . . . . : 192.168.0.60
Subnet Mask . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . : 192.168.0.254
DNS Servers . . . . . . . . . . : 64.90.1.22
64.90.1.14
Primary WINS Server . . . . . . : 192.168.0.10
-nic2(lan): has a static internal ip:
Ethernet adapter Local Area Connection 2:
Connection-specific DNS Suffix :
Description . . . . . . . . . . : 10/100adapter #2
Physical Address. . . . . . . . : 00-04-5A-57-D
DHCP Enabled. . . . . . . . . . : No
IP Address. . . . . . . . . . . : 192.168.0.101
Subnet Mask . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . :
DNS Servers . . . . . . . . . . : 192.168.0.57
192.168.0.10
Primary WINS Server . . . . . . : 192.168.0.10
-Used the routing and remote access wizard setup the vpn.
-Added the vpn server to "RAS and IAS Servers" group in the active directory.
-configured DHCP Relay for nic1(wan) using the lan's win2k dhcp server
-allowed "Dial-in" acces to the user account(s) logging in.
At this point I had a client using winME test the connection. The client got as far as "Verifying user name and password" then got the error "Error 603: Unable to establish a connection". The client is behind a router, so I'm not sure if he needs to open any ports or not.
So far I'm stuck. Thanks in advance for any suggestions concerning my configuration.
Jay
-To start off, the lan is a win2k domain. The domain server is a seperate box on the network running dhcp, dns and wins.
-The vpn server is also running win2k with 2 nics. TCPIP Filtering for nic1(wan) is configured to only permit tcp port 1723 and udp port 47. No other tcp, udp ports or ip protocols are permitted for the wan adapter (this may be a problem, I'm not sure).
-nic1(wan): has a static internal ip which has been mapped by the T1 provider to a static public ip:
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix :
Description . . . . . . . . . . : 10/100adapter
Physical Address. . . . . . . . : 00-20-78-1E-E
DHCP Enabled. . . . . . . . . . : No
IP Address. . . . . . . . . . . : 192.168.0.60
Subnet Mask . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . : 192.168.0.254
DNS Servers . . . . . . . . . . : 64.90.1.22
64.90.1.14
Primary WINS Server . . . . . . : 192.168.0.10
-nic2(lan): has a static internal ip:
Ethernet adapter Local Area Connection 2:
Connection-specific DNS Suffix :
Description . . . . . . . . . . : 10/100adapter #2
Physical Address. . . . . . . . : 00-04-5A-57-D
DHCP Enabled. . . . . . . . . . : No
IP Address. . . . . . . . . . . : 192.168.0.101
Subnet Mask . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . :
DNS Servers . . . . . . . . . . : 192.168.0.57
192.168.0.10
Primary WINS Server . . . . . . : 192.168.0.10
-Used the routing and remote access wizard setup the vpn.
-Added the vpn server to "RAS and IAS Servers" group in the active directory.
-configured DHCP Relay for nic1(wan) using the lan's win2k dhcp server
-allowed "Dial-in" acces to the user account(s) logging in.
At this point I had a client using winME test the connection. The client got as far as "Verifying user name and password" then got the error "Error 603: Unable to establish a connection". The client is behind a router, so I'm not sure if he needs to open any ports or not.
So far I'm stuck. Thanks in advance for any suggestions concerning my configuration.
Jay