• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

PPTP VPN connection, can't access resources

mkanet

n00b
Joined
Nov 15, 2006
Messages
23
I am working on setting up a PPTP VPN and have been having some issues. I have set up a Windows XP Pro machine as a VPN server using the built in advanced connection features. I have forwarded the PPTP port from my router to this machine (set with a static IP) and have also allowed those ports on my firewall of the machine. The IP range of the network that the server is on is 192.168.100.xxx with a subnet of 255.255.255.0.

The computer I am connecting from right now is on an IP range of 10.0.0.xxx with a subnet of 255.255.255.0. I can establish the connection with the VPN server but I can't see any of the network resources. I can connect to the remote router admin settings but I can't even ping any of the other resources on the remote network.

Any help would be great! Thanks.
 
You can't see anything at all? Have you tried using the resources IP addresses instead of heir names? I know there are some issues with netbios traffic over VPN, and that could be the problem.

You know, instead of saying \\blahserver, try \\192.168.100.xx\resources and so on.

Just a suggestion. Troubleshooting VPN problems, which happen to be one of the most complicated network setups in the world, can be a long process.
 
I have tried connecting to their IP address and names as well. Nothing. I can't even ping them.

Do the subnets need to be different for each network that is connected through the VPN or is having a different IP range good enough?
 
the subnets shouldn't effect anything since they're on entirely different private networks (10.10 and 192.168).

The different networks should be perfectly good enough.

Hmm, I'm sure someone here has some good experience with VPN's. Personally, I stay away from software VPN's and use hardware specifically designed for it. Makes life alot easier, if not more expensive... I'll do some digging and see if I can't come up with something else.
 
mkanet said:
I have tried connecting to their IP address and names as well. Nothing. I can't even ping them.

Do the subnets need to be different for each network that is connected through the VPN or is having a different IP range good enough?

Just need a different IP range...example...
Network A) 192.168.0.xxx
Network B) 192.168.1.xxx or 10.1.1.xxx

Just use IPs with a VPN....everyone insists on name resolution for some reason...netbios passthrough clogs the pipes too much, your data will be glacially slow. Just use make resources you need to access static, and use IP. If something absolutely NEEDS name resolution, use the host file, or DNS complete with DNS suffix.<==important
 
mkanet said:
Do I need to forward any ports on the client side of the VPN?

Negative..no port forwarding needed on the client end. Depending on what you dial INTO..you may have to. If you have a hardware appliance answering your VPN call, such as a Linksys RV0, or a Cisco PIX, or a DD-WRT router...whatever..nothing needed to be forwarded on the host site. If you're running your VPN server on a Windows server...yes you'll need to forward port 1723 on your firewall..to the LAN IP of the NIC you bound your RRAS to. You appear to be connecting..so that's obviously not the issue.

Any other 3rd party software firewalls in the mix?
 
Windows PPTP requires GRE to be passed on the client and server as well as TCP 1723, but since you're connected, that shouldn't be the issue.

Sounds like a routing problem. Is the VPN server multihomed?

On the client, do an ipconfig /all after connecting and post it here.
 
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

F:\Documents and Settings\Mike>ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : mikes
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Wireless Network Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Belkin Wireless Pre-N Notebook Netwo
rk Card
Physical Address. . . . . . . . . : **-**-**-**-**-**
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 10.0.0.105
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 10.0.0.100
DHCP Server . . . . . . . . . . . : 10.0.0.100
DNS Servers . . . . . . . . . . . : 208.57.0.11
208.57.0.10
Lease Obtained. . . . . . . . . . : Wednesday, November 15, 2006 9:48:42
AM
Lease Expires . . . . . . . . . . : Thursday, November 16, 2006 12:48:42
AM

PPP adapter kanet home network:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : WAN (PPP/SLIP) Interface
Physical Address. . . . . . . . . : **-**-**-**-**-**
Dhcp Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.100.10
Subnet Mask . . . . . . . . . . . : 255.255.255.255
Default Gateway . . . . . . . . . : 192.168.100.10
DNS Servers . . . . . . . . . . . : 68.111.16.30
68.111.16.25
 
IP Type 47 GRE isn't the issue..you'd fail to connect if it was and receive error 721. Looks like you're VPN'ing into just a peer to peer network....as you're behind handed public DNS servers. If you had an active directory network...you should be handed your DCs IP address and suffix for DNS.

Are you positive you have no 3rd party software firewalls on either end that need to have the other network added into its safe zone?
 
I have Windows Firewall on the server PC, with ports enabled for PPTP and on the client end I have McAfee Security with Personal Firewall running on the client end. Do I need to enable ICMP Ping Requests or change any other of the settings on McAfee on the client?
 
Is this server multi-homed?

Dunno what to tell you about the McAfee machine...I'd format a machine that had McAfee on it before I had to sit down and work on it. Somehow...somewhere...there should some sort of way to add the "other" networks IP range..into some sort of "safe allowed zone". Most firewalls allow this.

By default, many software firewalls will set the local IP range in the safe zone. Your home LAN is 10.0.0.xxx? So McCrapee sees that at safe. Any other IP range..such as your office network..192.168.100.xxx...is not seen as safe..and blocked just like any other IP address on the internet.

That's my hunch anyways...
 
I enabled the IP range in McAfee of the other network, but still have the same problems. I am starting to think that it may be easier to just bite the bullet and buy a hardware solution. Any recommendations?
 
mkanet said:
I enabled the IP range in McAfee of the other network, but still have the same problems. I am starting to think that it may be easier to just bite the bullet and buy a hardware solution. Any recommendations?

Any way you can totally kill McAfee? PPTP VPN is quite solid....I have dozens of them out there running, IMO it's the most reliable VPN....IPSec can get touchy....SSL can even give you a few scratches on the head when troubleshooting. But PPTP...BAM..in. IMO if something is getting in the way of PPTP VPN...it will surely stand in the way of other types.

Key question yet to be answered...is the server multi-homed?
 
No, it is not multi-homed. I never even thought of having multiple nic cards for it.
 
I have to disable my McAfee when I connect to my Windows2003 SSH box. Just a hint.
 
Back
Top