Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ras connection on lan with router/firewall

Status
Not open for further replies.

sos

IS-IT--Management
Apr 10, 2000
53
CA
I have a Gnet 4 port firewall/router with multiple computers connected to the internet running on a win9x/2000 lan.

Is it possible to use windows 2000 server and ras to connect remote user to internet?

What i mean is, if a windows 2000 server is obtaing a 192.168.xxx.xxx type address from Gnet dhcp, can that same server be configured to allow a remote user internet connectivity via dial-in?

I want to give our techs the ability to use dial-up to test customers computers on-site and download drivers etc...

Thanx in advance

sos (pronounced "sauce")
 
Yes, you can, however since you are using an address that is private (non-routable over the internet) you will need to establish a VPN connection. If you have one public ip address, you will need to put a server with RRAS on that ip, or you will need a router with NAT capable of establishing a VPN. That's the internet route. You can also put a modem on one of your servers and dial directly into it through RRAS without the internet. It will cost you an extra phone line and long distance, but the security will be much higher. Alot depends on how good you are at blocking hackers on whether you want to go the internet route (I would suggest an encrypted VPN with either kerberos or certificate authentication).
 
is there any documentation u could point me to that would explain how to setup a vpn?
 
If you carnt VPN with your router then you will need to create a static NAT mapping.
depending on how advance your router is...........

static NAT mapping basically assigns a public ip address to an internal client but only in relation to outside the router.
if you can configure this--you are then able to installe terminal services on the server and people will be able to connect via the internet to terminal serices-- this creates Security issues--so its best if the clients that are conneting have a static public ip address assigned by their ISp- eg one that doesnt change-- and you then configure the firewall to only allow incomming on port 3389(RDP-terminal connections)) from the external clients ip addresses

MCSE NT&2K,CCNA/CCDA,CNA,ASE,NSP

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top