Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN behind a firewall !!!

Status
Not open for further replies.

deathstar

MIS
Aug 28, 2001
49
CA
Can anyone tell me is it possible to have VPN services enabled behind a firewall, I've read several articles and from what it seems all I have to do is enalbe ports 1723 and protocol 47 on the firewall. Is this it????? I'm currently running a Windows 2000 server with the latest service packs, as a Storage server for just data and software access. It is also configured as a DC, just in case this may make a difference.

If anyone has done this already please give me a shout I would greatly appreciate it !!!

Thanks a bunch
 
It would help alot if you told me what type of firewall
 
it works...
put your Win2K in a DMZ,
allow TPC 1723 and IP Protocol 47 (GRE) to the machine in the DMZ and you will be able to run your VPN without problems ---------------------------------------------------------------------
I have not failed, I've just found 10,000 ways that don't work
---------------------------------------------------------------------
Peter Van Eeckhoutte
peter.ve@pandora.be
*:->* Did this post help? Click below to let me know !
 
Hi,
Can you tell me more about IP protocol 47 (GRE) ? Thanks very much .
John Thom
 
You must permit IP Type 47 Generic Routing Encapsulation (GRE) packets for PPTP tunnel data to pass to your RRAS server's IP address

The PPTP uses a TCP connection known as the PPTP control connection to create, maintain, and terminate the tunnel and a modified version of Generic Routing Encapsulation (GRE) to encapsulate PPP frames as tunneled data

Your firewall must support the IP protocol 47 in order to allow this type of VPN traffic...
I know MS ISA server & Checkpoint FW1 both support this... you will have to check with your vendor for other applications... ---------------------------------------------------------------------
I have not failed, I've just found 10,000 ways that don't work
---------------------------------------------------------------------
Peter Van Eeckhoutte
peter.ve@pandora.be
*:->* Did this post help? Click below to let me know !
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top