»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 04-27-2004, 07:51 AM   #1 (permalink)
Registered User
 
Join Date: Apr 2004
Posts: 4
rpiquette is on a distinguished road
can't connect to vpn thru win 2000pro dhcp

I cannot connect to my companies vpn using nortel's extranet client through my win 2000 pro dhcp server. I have no problem when I use a router. The routers I've tried (successfully)both have IPsec passthrough. I'm guessing this might be the problem. How do I fix this?

rpiquette is offline   Reply With Quote
Old 04-27-2004, 08:21 AM   #2 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
Is your W2K DHCP server doing NAT?
DVNT1 is offline   Reply With Quote
Old 04-27-2004, 08:34 AM   #3 (permalink)
Registered User
 
Join Date: Apr 2004
Posts: 4
rpiquette is on a distinguished road
I have 4 machines behind the dhcp server that all work fine.as far as ip assignment, itranet activity and internet acess. So I assume it (NAT) is working fine. Is there a way to disable or enable NAT or is it embedded in the enabling and disabling of dhcp?
rpiquette is offline   Reply With Quote
Old 04-27-2004, 09:03 AM   #4 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
Sounds like W2K NAT is breakign the VPN because of the packet handling.

Three initial solutions come to mind.

1) If offered by the Nortel server software, change the VPN server to allow clients using NAT.

2) Buy another NAT compatible router

3) Put the NAT client on the W2K server and use port mappings to access some of the services on the company LAN.
DVNT1 is offline   Reply With Quote
Old 04-27-2004, 09:22 AM   #5 (permalink)
Registered User
 
Join Date: Apr 2004
Posts: 4
rpiquette is on a distinguished road
why I can connect to the vpn using the NAT in a lynksys router...but not the NAT in my win2k server? I am trying to get away from using a router and solely rely on my win2k dhcp for my LAN administration.
rpiquette is offline   Reply With Quote
Old 04-27-2004, 09:31 AM   #6 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
As I understand it, standard IPSEC uses checksums to ensure the data packet was not altered while in route. The Address Header checksum is one item which gets changed via "normal" NAT devices. NAT also changes transport-layer checksums (since the source and destination addresses are included in the UDP and TCP checksums).

The routers you mentioned working must support IPSEC passthru (aka, they do not change the related checksums).
DVNT1 is offline   Reply With Quote
Old 04-27-2004, 10:11 AM   #7 (permalink)
Registered User
 
Join Date: Apr 2004
Posts: 4
rpiquette is on a distinguished road
they do support ipsec passthru.....Is there a way to enable or configure the same passthru capability to win2k?
rpiquette is offline   Reply With Quote
Old 04-27-2004, 10:37 AM   #8 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
Maybe, but as I mentioned, it is heavily dependent on the VPN server. Read http://www.isaserver.org/articles/IP...ssthrough.html
DVNT1 is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 07:10 PM.