Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cannot make a VPN connection from outside the LAN 1

Status
Not open for further replies.

highlysceptical

IS-IT--Management
Jul 17, 2003
30
GB
I have an ADSL broadband connection with a static IP address and a Netgear DG814 router.

I have a server behind the router running Windows XP Professional (and Zone Alarm Pro) and a laptop running Windows XP Home

I am wanting to connect to the server from my laptop. I think I have set up the VPN Server correctly, as I can connect to it from inside the LAN. However, I just cannot connect to it from outside the LAN via the router.

I (think) I have forwarded ports 1723 and 47 to the VPN server, as I have forwarded other ports successfully for SMTP, POP3 etc. But when I try to make a VPN connection from outside the LAN, I keep getting error 800. (Zone Alarm does not seem to be the problem, as I cannot get a connection even if I shut Zone Alarm down!)

One thing that puzzles me particularly is what should I use for the IP address of the server in the VPN connection on my laptop. Since its IP address is 192.168.x.x, this will not be "visible" to the web. So I presume I have to use the WAN IP address assigned to the router?
 
error 800 is some things to do with the connection quoted from Error 800: Unable to establish the VPN connection. The VPN server may be un-reachable, or security parameters may not be configured properly for this connection.

Resolutions:
1) if you have firewall, open TCP Port 1723, IP Protocol 47 (GRE).
2) make sure you can reach the VPN server by using ping.
3) You may need to updated firmware on a router or firewall if other OS (win9x/nt/me/w2k) works except XP.
4) The VPN server may not be able to get IP from DHCP for the VPN client. So, you may want to re-configure VPN host networking settings. For XP pro VPN host, go to the Properties of the VPN>Network, check Specify TCP/IP address and Allow calling computer to specify its own IP address, and uncheck Assign TCP/IP addresses automatically using DHCP.
For more tips or information, go to

Robert Lin, MS-MVP, MCSE & CNE
Windows, Network and How to at
 
I have just been advised by Netgear that the DG814 will not allow a VPN tunnel from outside the LAN to a machine behind the router!
 
Thanks very much - no its not too late as I am still battling with it. What you say does not surprise me, because having spent a long time on the phone to Netgear, I came to the conclusion that they did not know what they were talking about, since everyone told me something different!

Can you give me any more details about the settings you have used?
 
How are you setting up your WinXP Pro computer to be a VPN server? As far as i know, and i could be wrong, winXP pro cannot be setup as a VPN server. Windows 2K server and Windows server 2003 both come with Microsoft's Routing and Remote Access Server, which is needed for a server to accept and setup VPN connections. You can buy routers that will let you setup a VPN connection with the router to gain access to the internal network. Also, you need to have the VPN server setup an IP adress for the client upon connection. You can tell the VPN server to use its own address pool or grab some IPs from a DHCP server.

I think that in your situation, the only thing you can use to connect your laptop from outside your router to your winXP Pro workstation is by using the remote desktop features in windows XP.
 
Well, i stand corrected. Did you follow this article to setup your VPN?

One thing you could try is use a packet sniffer to see if your WinXP Pro computer is recieving the request through the router. I use Ethereal. It is a good program.


Install it on your winXP pro computer and then start it, try to make the VPN connection and then see what you get. Also, did you do the firmware upgrade to your router?
 
Thanks - will try the packet sniffer. I upgraded the firmware to the latest version, but am going to try Version 4.6 as suggested by PaulWood
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top