Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN, W2K server, W2K client setup procedure?

Status
Not open for further replies.

blinkimage

Technical User
Feb 5, 2003
1
GB
(Newbie alert!)

As many people in this group, I am having problems setting up VPN.

My equipment:

OFFICE
LAN - 9 PCs, all running W2K Pro
Server - W2K Server, 2 NICs - 1 Gigabit Netgaer (connected to the LAN), the other an on board 100Base Intel affair (this one is not used)
Netgear DG814 - router/DHCP server - 4.5 RC1
BTOpenworld Broadband DSL connection

REMOTE
Laptop - W2K Pro
Dial-up modem

I have the latest firmware for the router, which is connected into my LAN. I have port forwarded 500, 1723 and 47 to the IP address of my LAN server (192.168.0.6), and set the default DMZ server to be the same (192.168.0.6). 'Respond to ping' is enabled.

As my ISP provides my IP address, I have registered with DynDNS so that my 'public' IP address is available for the VPN connections. So, I have also enabled this dynamic DNS service in my DG814 router configuration.

I setup RRAS for VPN on the server, and it gives me the choice for Server internet connection of:
<no internet connection>
Intel 100 Base LAN (DHCP)
Netgear Gigabit LAN (DHCP).
Logically, I choose the Netgear Gigabit LAN (DHCP). TCP/IP is the protocol that I use, and then I tell it to assign IP addresses automatically, because I have the DG814 router set up to do so. Clicking OK sets up the RRAS so now I should be able to set up a VPN client login connection, right?

BUT, once I have set up RRAS in this way, my LAN goes down. This is problem 1. This is obviously no good!

So, I go back and disable RRAS so that I can configure it again. This time, when presented with:
<no internet connection>
Intel 100 Base LAN (DHCP)
Netgear Gigabit LAN (DHCP)
I choose <no internet connection>. Next I am told that VPN clients must be assigned to one network, and need to select from:
Intel 100 Base LAN (DHCP)
Netgear Gigabit LAN (DHCP)
so I choose the Netgear Gigabit, tell it that IP addresses should be assigned dynamically and click finish.

Still with me?

Next I set up a new user for my domain (called BLINKIMAGE), with, for illustration purposes, username FRED, password BLOGGS. I enable dial-in for this new client.

So, I connect to the internet from the laptop with the dial-up connection, establish a new VPN network connection, use the public IP address that DynDNS has assigned, have the username FRED, the password, BLOGGS, and the domain, BLINKIMAGE (BTW, I can ping this IP address from the laptop). Click connect, it gets to 'verifying username and password', pauses for about 30 seconds and fails with a 721 Error.

That is my situation.

Can anyone help?

Richard
 
I'm not entirely sure. but it sounds like the client and server security configurations are not matching. I have had some trouble with the same errors. You might check the settings on the client machine. It sounds like your router is passing the appropriate ports and you are able to communicate with the server. The next step is to get them speaking the same language. There are all kinds of little settings that can stop them from talking.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top