![]() |
![]() OCAU News - Wiki - QuickLinks - Pix - Sponsors |
|
|||||||
| Notices |
|
Sign up for a free OCAU account and this ad will go away! Search our forums with Google: |
![]() |
|
|
Thread Tools |
|
|
#1 |
|
Member
Join Date: Jun 2001
Location: Brisbane
Posts: 19,896
|
here's the skinny:
i've got a MS RRAS box sitting behind a firewall and the firewall behind a router. it goes: internet -> wan_ip:router ublic_ip2 -> public_ip1:firewall rivate_ip1 -> private_ip2:RRASthe firewall hosts 3 public IPs, one of which is NATed/forwarded to the RRAS box. the firewall is opened up correctly for port 1723 access and GRE access, and everything is NATed correctly. PPTP over private LAN works, and the RRAS logs show that the external requests are getting in fine. the external clients connecting over the web get timeout issues, which i think is a routing problem on the RRAS box. i have set up an IP tunnel interface with just about every configuration i can think of, but it still doesnt want to work. can anyone offer me any advice?
__________________
Child's Play Charity |
|
|
|
| Join OCAU to remove this ad! |
|
|
#2 |
|
(Banned or Deleted)
Join Date: Sep 2001
Location: dots in the location field break it. note
Posts: 2,034
|
what OS is the firewall?
|
|
|
|
|
|
#3 |
|
Member
Join Date: Jun 2001
Location: Brisbane
Posts: 19,896
|
it's a nokia ip330 hardware firewall
__________________
Child's Play Charity |
|
|
|
|
|
#4 |
|
(Banned or Deleted)
Join Date: Sep 2001
Location: dots in the location field break it. note
Posts: 2,034
|
i think a lot more than the source and destination address need to be rewritten for pptp to work behind NAT
look at the linux vpn masquerade howto's also pptp has its own protocol number.. and u need to let these packets through the firewall |
|
|
|
|
|
#5 |
|
Member
Join Date: Jun 2001
Location: Brisbane
Posts: 19,896
|
protocol 0 type 47 "gre" is what you are talking about, and is allowed through the NAT.
the PPTP logs report that the authenticated user is indeed making it through the nat to the PPTP server, but it's not making back out. there are "routing interfaces" that you can configure in microsoft RRAS, which is what i am trying to get some help on. i'm not sure if i need to configure several virtual interfaces, or one big one to get me through the NAT and out onto the web.
__________________
Child's Play Charity |
|
|
|
|
|
#6 |
|
Member
Join Date: Jun 2001
Location: Brisbane
Posts: 19,896
|
^bump^
__________________
Child's Play Charity |
|
|
|
|
|
#7 |
|
Member
Join Date: Aug 2001
Posts: 108
|
Set a rule to allow all access to 1 ip (vpn client). Log traffic and then tighten rules according to traffic.
Also pptp vpn client can't be running behind NAT. They must have direct internet ip, not NAT/proxy. |
|
|
|
|
|
#8 | |
|
(Banned or Deleted)
Join Date: Sep 2001
Location: dots in the location field break it. note
Posts: 2,034
|
Quote:
|
|
|
|
|
|
|
#9 | |
|
Member
Join Date: Aug 2001
Posts: 108
|
Quote:
I have read a technet article that said NAT doesn't properly support outgoing VPN calls with our setup. In our case you needed VPN clients to have internet ip. Stapla |
|
|
|
|
|
|
#10 |
|
(Banned or Deleted)
Join Date: Sep 2001
Location: dots in the location field break it. note
Posts: 2,034
|
i dont actually have any experience with pptp and nat
but i know there is a linux iptables helper module to facilitate pptp through nat, im not sure if its a complete solution yet.. but its getting there |
|
|
|
|
|
#11 |
|
Member
Join Date: Jun 2001
Location: Brisbane
Posts: 19,896
|
as it so happens, i got the complete shits with the nokia firewall and bypassed it all together. i got sick and tired of being yelled at by my bosses for trying to fix substandard equipment they had chosen.
after all of that i routed around the nokia to an IPCop box and then through it to the RRAS server. works bloody fantastically without a hitch, and is damn fast too. "hardware" firewalls can kiss my arse.
__________________
Child's Play Charity |
|
|
|
![]() |
| Bookmarks |
|
Sign up for a free OCAU account and this ad will go away! |
| Thread Tools | |
|
|