Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

winkserver AD + netgear 314 + error 721

Status
Not open for further replies.

dmose

Technical User
Sep 29, 2009
12
US
Greetings,

I have a small AD setup at home with 4 servers:

win2k server
AD MDC
RAS installed
DNS installed
ip:192.168.0.99
dns:192.168.0.99
gateway: 192.168.0.1

netgear rt314 router
dynamic ip from isp, using dyndns.org to bind
DHCP enabled
port 1723 forwarding to 192.168.0.99

My problem is, when I connect to the internet via my laptop at work and try to connect to my home network, I get an error 721. I've checked everything, I can telnet to my ISP IP on port 1723 fine and dial in access is enabled to my username. I'm using PPTP and MSCHAP2. My client settings are fine, but I'm not 100% about my server settings. For example, in the RAS MMC under iprouting I have 3 interfaces: loopback, internal and mydomain. Do I need any static routes set?

My question is, what am I doing wrong? Do I need WINS server installed on my AD? I've tested connecting using my external IP instead of dyndns.org and same problem. Could the DNS service be messing things up?

thanks
 
If your Netgear doing NAT? It must be if you only have one network card and a dynamic IP address. Are you sure that the router is passing the PPTP packet on to the VPN server. I don't know netgear very well, but on a Cisco or 3Com router it takes more than just a forwarder or port map to pass on the PPTP packets. The two Microsoft KB articles below might help. You should have to create a static route. Route between what? How are you assigning IP's to the VPN Clients and what are you assigning?

Q227747
Q289732
 
thanks for your reply. Yeah I'm doing NAT on my netgear router which hides my 4 server LAN behind a non-static ip address (that I bind to dyndns.org service).

Anyhow, I've opened both port 1723 and 47 to forward to my VPN server ip: 192.168.0.99.

Hmm a static route..maybe? I'm assigning IP addresses from the SERVER from a static pool of 192.168.0.11-15 . I've actually tried connecting from another workstation on my network and it works using local ips - thats why I think there is a problem with the NAT?

I'll read the articles, thanks for your help. Any other suggestions?
 
Just an FYI, make certain that you are didn't open TCP port 47. You are actually looking for GRE protocol 47. The device may have a configuration for PPTP pass thru.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top