 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: VPN setup</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/vpn-setup/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/vpn-setup/</link>
	<description></description>
	<lastBuildDate>Tue, 21 May 2013 18:28:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: astronomer</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/vpn-setup/#comment-36358</link>
		<dc:creator>astronomer</dc:creator>
		<pubDate>Mon, 06 Nov 2006 12:07:21 +0000</pubDate>
		<guid isPermaLink="false">#comment-36358</guid>
		<description><![CDATA[Have you opened GRE, (protocol 47)? This is required for PPTP to get through the firewall.
For debugging purposes can you set up a client without going through the firewall? I use our DMZ just outside of the VPN server for testing. This is sometimes very helpful to narrow down the possible causes.
rt]]></description>
		<content:encoded><![CDATA[<p>Have you opened GRE, (protocol 47)? This is required for PPTP to get through the firewall.<br />
For debugging purposes can you set up a client without going through the firewall? I use our DMZ just outside of the VPN server for testing. This is sometimes very helpful to narrow down the possible causes.<br />
rt</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mortree</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/vpn-setup/#comment-36359</link>
		<dc:creator>mortree</dc:creator>
		<pubDate>Fri, 03 Nov 2006 22:49:20 +0000</pubDate>
		<guid isPermaLink="false">#comment-36359</guid>
		<description><![CDATA[Currently the Small Business Server wants to do RRAS authentication of the user before completing the VPN tunnel. Have you configure RRAS fully? Mobile users are allowed remote access by account and RRAS policies? What authentication methods are set in RRAS? When you say you opened port 1723 what do you mean -- port forwarding? 

My bet is on mobile user IPs. How are you doing that in a way that is compatible with your internal network firewalls and filters?

Alternatively consider.

Since you have a VPN firewall you should use your Small Business Server simply for RRAS services to approve logon (allowed remote access on account). Point the firewall to the SBS machines for RRAS services.  Configure RRAS and user account for allowing Remote Access. 

To complete VPN tunnels you might need to set certificates or shared secrets on the firewall to pair with mobile users -- capabilities vary with firewall. Certificates are superior but distribution mechanics vary. Ultimately mobile need access to certificates generated for the firewall and firewall need access to certificates for mobile users.

This will end the VPN tunnel at the firewall. The firewall will decrypt and route IP whereever it needs to go in your network. Those users will be able to communciate anywhere in your network AD allows them without passing through and taxing your SBS machine.


If you want to across a firewall L2TP is supposed to be easier to get to work especially is any NAT is in play.

]]></description>
		<content:encoded><![CDATA[<p>Currently the Small Business Server wants to do RRAS authentication of the user before completing the VPN tunnel. Have you configure RRAS fully? Mobile users are allowed remote access by account and RRAS policies? What authentication methods are set in RRAS? When you say you opened port 1723 what do you mean &#8212; port forwarding? </p>
<p>My bet is on mobile user IPs. How are you doing that in a way that is compatible with your internal network firewalls and filters?</p>
<p>Alternatively consider.</p>
<p>Since you have a VPN firewall you should use your Small Business Server simply for RRAS services to approve logon (allowed remote access on account). Point the firewall to the SBS machines for RRAS services.  Configure RRAS and user account for allowing Remote Access. </p>
<p>To complete VPN tunnels you might need to set certificates or shared secrets on the firewall to pair with mobile users &#8212; capabilities vary with firewall. Certificates are superior but distribution mechanics vary. Ultimately mobile need access to certificates generated for the firewall and firewall need access to certificates for mobile users.</p>
<p>This will end the VPN tunnel at the firewall. The firewall will decrypt and route IP whereever it needs to go in your network. Those users will be able to communciate anywhere in your network AD allows them without passing through and taxing your SBS machine.</p>
<p>If you want to across a firewall L2TP is supposed to be easier to get to work especially is any NAT is in play.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/10 queries in 0.033 seconds using memcached
Object Caching 280/286 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-21 19:16:30 -->