Overclockers Australia Forums
OCAU News - Wiki - QuickLinks - Pix - Sponsors  

Go Back   Overclockers Australia Forums > Specific Hardware Topics > Networking, Telephony & Internet

Notices


Sign up for a free OCAU account and this ad will go away!
Search our forums with Google:
Reply
 
Thread Tools
Old 15th March 2002, 11:10 AM   #1
elvis Thread Starter
Member
 
elvis's Avatar
 
Join Date: Jun 2001
Location: Brisbane
Posts: 19,896
Default MS PPTP over NAT madness

here's the skinny:

i've got a MS RRAS box sitting behind a firewall and the firewall behind a router.

it goes:

internet -> wan_ip:routerublic_ip2 -> public_ip1:firewallrivate_ip1 -> private_ip2:RRAS

the firewall hosts 3 public IPs, one of which is NATed/forwarded to the RRAS box.

the firewall is opened up correctly for port 1723 access and GRE access, and everything is NATed correctly. PPTP over private LAN works, and the RRAS logs show that the external requests are getting in fine.

the external clients connecting over the web get timeout issues, which i think is a routing problem on the RRAS box. i have set up an IP tunnel interface with just about every configuration i can think of, but it still doesnt want to work.

can anyone offer me any advice?
__________________
Child's Play Charity
elvis is offline   Reply With Quote

Join OCAU to remove this ad!
Old 15th March 2002, 3:45 PM   #2
hast
(Banned or Deleted)
 
hast's Avatar
 
Join Date: Sep 2001
Location: dots in the location field break it. note
Posts: 2,034
Default

what OS is the firewall?
hast is offline   Reply With Quote
Old 15th March 2002, 3:57 PM   #3
elvis Thread Starter
Member
 
elvis's Avatar
 
Join Date: Jun 2001
Location: Brisbane
Posts: 19,896
Default

it's a nokia ip330 hardware firewall
__________________
Child's Play Charity
elvis is offline   Reply With Quote
Old 15th March 2002, 4:34 PM   #4
hast
(Banned or Deleted)
 
hast's Avatar
 
Join Date: Sep 2001
Location: dots in the location field break it. note
Posts: 2,034
Default

i think a lot more than the source and destination address need to be rewritten for pptp to work behind NAT
look at the linux vpn masquerade howto's

also pptp has its own protocol number.. and u need to let these packets through the firewall
hast is offline   Reply With Quote
Old 15th March 2002, 7:02 PM   #5
elvis Thread Starter
Member
 
elvis's Avatar
 
Join Date: Jun 2001
Location: Brisbane
Posts: 19,896
Default

protocol 0 type 47 "gre" is what you are talking about, and is allowed through the NAT.

the PPTP logs report that the authenticated user is indeed making it through the nat to the PPTP server, but it's not making back out.

there are "routing interfaces" that you can configure in microsoft RRAS, which is what i am trying to get some help on. i'm not sure if i need to configure several virtual interfaces, or one big one to get me through the NAT and out onto the web.
__________________
Child's Play Charity
elvis is offline   Reply With Quote
Old 18th March 2002, 9:37 AM   #6
elvis Thread Starter
Member
 
elvis's Avatar
 
Join Date: Jun 2001
Location: Brisbane
Posts: 19,896
Default

^bump^
__________________
Child's Play Charity
elvis is offline   Reply With Quote
Old 23rd March 2002, 12:36 PM   #7
stapla
Member
 
Join Date: Aug 2001
Posts: 108
Default

Set a rule to allow all access to 1 ip (vpn client). Log traffic and then tighten rules according to traffic.

Also pptp vpn client can't be running behind NAT. They must have direct internet ip, not NAT/proxy.
stapla is offline   Reply With Quote
Old 23rd March 2002, 1:11 PM   #8
hast
(Banned or Deleted)
 
hast's Avatar
 
Join Date: Sep 2001
Location: dots in the location field break it. note
Posts: 2,034
Default

Quote:

Also pptp vpn client can't be running behind NAT. They must have direct internet ip, not NAT/proxy.
they can, you just need a decent nat device..
hast is offline   Reply With Quote
Old 23rd March 2002, 1:51 PM   #9
stapla
Member
 
Join Date: Aug 2001
Posts: 108
Default

Quote:
Originally posted by hast


they can, you just need a decent nat device..
Yeah that sounds right. What device do you use for NAT translations.

I have read a technet article that said NAT doesn't properly support outgoing VPN calls with our setup.

In our case you needed VPN clients to have internet ip.

Stapla
stapla is offline   Reply With Quote
Old 23rd March 2002, 2:51 PM   #10
hast
(Banned or Deleted)
 
hast's Avatar
 
Join Date: Sep 2001
Location: dots in the location field break it. note
Posts: 2,034
Default

i dont actually have any experience with pptp and nat
but i know there is a linux iptables helper module to facilitate pptp through nat, im not sure if its a complete solution yet.. but its getting there
hast is offline   Reply With Quote
Old 23rd March 2002, 4:25 PM   #11
elvis Thread Starter
Member
 
elvis's Avatar
 
Join Date: Jun 2001
Location: Brisbane
Posts: 19,896
Default

as it so happens, i got the complete shits with the nokia firewall and bypassed it all together. i got sick and tired of being yelled at by my bosses for trying to fix substandard equipment they had chosen.

after all of that i routed around the nokia to an IPCop box and then through it to the RRAS server. works bloody fantastically without a hitch, and is damn fast too.

"hardware" firewalls can kiss my arse.
__________________
Child's Play Charity
elvis is offline   Reply With Quote
Reply

Bookmarks

Sign up for a free OCAU account and this ad will go away!

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +10. The time now is 2:13 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd. -
OCAU is not responsible for the content of individual messages posted by others.
Other content copyright Overclockers Australia.
OCAU is hosted by Internode!