Lab Network

  • Thread starter Thread starter Pat
  • Start date Start date
P

Pat

what I have now is the following
Production network:
W2K with AD and 100 users. on a 192.168.1.0 subnet.

Lab network:
W3K Ras server joined to production network for routing
nic #1 192.168.1.241
nic #2 10.100.0.1
lab network on 10.100.0.0 subnet

lab xp WS 10.100.0.2
lab W3K server 10.100.0.3

I have a route setup in my firewall for the 10.100.0.0 network, so I
can get to the internet from my lab network. I can see the lab network
from my production network. can RRas do any sought of Vlan so I
can't see the lab network from the production network?
 
RAS does not do Vlan (as in swicthes).
However to make lab network in accessible from production network you can
enable NAT/Firewall on your router between lab and production network. On
NAT make lab as private network which can access your productin network as
public network. However public network (or your production network) will not
be able to access lab.

To configure NAT on win2k3 look at
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/proddocs/entserver/mpr_node20.asp

310357 - HOW TO: Configure the NAT Service in Windows 2000
http://support.microsoft.com/default.aspx?scid=kb;en-us;310357

Hope it helps
-Pawan
 
You should be able to see the lab network from the prod network. They
are both private and inside the firewall. You just need RRAS enabled as an
IP router.

If you have a static route on the firewall to route 10.100.0.0 to the
RRAS router at 192.168.1.241 it should work. eg

firewall (static route 10.100.0.0 255.255.255.0 192.168.1.241 )
192.168.1.1
|
clients
192.168.1.x dg 192.168.1.1
|
192.168.1.241 dg 192.168.1.1
RRAS
10.100.0.1 dg blank
|
clients and server
10.100.0.x dg 10.0.0.1
 
Works, thank you

You should be able to see the lab network from the prod network. They
are both private and inside the firewall. You just need RRAS enabled as an
IP router.

If you have a static route on the firewall to route 10.100.0.0 to the
RRAS router at 192.168.1.241 it should work. eg

firewall (static route 10.100.0.0 255.255.255.0 192.168.1.241 )
192.168.1.1
|
clients
192.168.1.x dg 192.168.1.1
|
192.168.1.241 dg 192.168.1.1
RRAS
10.100.0.1 dg blank
|
clients and server
10.100.0.x dg 10.0.0.1
 
Hi Pat,

Thank you for posting here.

RRAS doesn't support VLAN. You may setup NAT/firewall on te Windows Server
2003 computer. To do so, please just enable firewall on the 192.168.1.241
network adapter. Then, the 192.168.1.0 network will not browse the
10.100.0.0 network. The 10.100.0.0 network can access the 192.168.1.0
network and the Internet.

Hope this helps!

Sincerely,
Jack Wang, MCSE 2000, MCSA, MCDBA, MCSD
Microsoft Partner Support

Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================

This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
| From: Pat <[email protected]>
| Subject: Lab Network
| Date: Sat, 28 Feb 2004 06:48:24 -0500
| Message-ID: <[email protected]>
| X-Newsreader: Forte Agent 1.93/32.576 English (American)
| MIME-Version: 1.0
| Content-Type: text/plain; charset=us-ascii
| Content-Transfer-Encoding: 7bit
| Newsgroups: microsoft.public.win2000.ras_routing
| NNTP-Posting-Host: mail.htechnology.com 198.65.193.67
| Lines: 1
| Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
| Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.ras_routing:10953
| X-Tomcat-NG: microsoft.public.win2000.ras_routing
|
| what I have now is the following
| Production network:
| W2K with AD and 100 users. on a 192.168.1.0 subnet.
|
| Lab network:
| W3K Ras server joined to production network for routing
| nic #1 192.168.1.241
| nic #2 10.100.0.1
| lab network on 10.100.0.0 subnet
|
| lab xp WS 10.100.0.2
| lab W3K server 10.100.0.3
|
| I have a route setup in my firewall for the 10.100.0.0 network, so I
| can get to the internet from my lab network. I can see the lab network
| from my production network. can RRas do any sought of Vlan so I
| can't see the lab network from the production network?
|
 
I tried setting up the basic firewall on the 192.168.1.241 interface
and this blocked outgoing requests also. do I need to put in a public
ip in the address pool?
 
Hi Pat,

Thank you for the update!

The ICF of Windows Server 2003 blocks both incoming and outgoing request.
If you only want to disable incoming, you may use the Routing and Remote
Access console.

1. Open the console.

2. Select IP Routing->NAT->network adapter.

3. Open the properties of it and set the firewall.

Hope this answers your question!

Sincerely,
Jack Wang, MCSE 2000, MCSA, MCDBA, MCSD
Microsoft Partner Support

Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================

This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
| From: Pat <[email protected]>
| Subject: Re: Lab Network
| Date: Tue, 02 Mar 2004 12:30:21 -0500
| Message-ID: <[email protected]>
| References: <[email protected]>
<[email protected]>
| X-Newsreader: Forte Agent 1.93/32.576 English (American)
| MIME-Version: 1.0
| Content-Type: text/plain; charset=us-ascii
| Content-Transfer-Encoding: 7bit
| Newsgroups: microsoft.public.win2000.ras_routing
| NNTP-Posting-Host: mail.htechnology.com 198.65.193.67
| Lines: 1
| Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP11.phx.gbl
| Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.ras_routing:11023
| X-Tomcat-NG: microsoft.public.win2000.ras_routing
|
| I tried setting up the basic firewall on the 192.168.1.241 interface
| and this blocked outgoing requests also. do I need to put in a public
| ip in the address pool?
|
| On Mon, 01 Mar 2004 15:56:56 GMT, (e-mail address removed) (Jack
| Wang [MSFT]) wrote:
|
| >Hi Pat,
| >
| >Thank you for posting here.
| >
| >RRAS doesn't support VLAN. You may setup NAT/firewall on te Windows
Server
| >2003 computer. To do so, please just enable firewall on the
192.168.1.241
| >network adapter. Then, the 192.168.1.0 network will not browse the
| >10.100.0.0 network. The 10.100.0.0 network can access the 192.168.1.0
| >network and the Internet.
| >
| >Hope this helps!
| >
| >Sincerely,
| >Jack Wang, MCSE 2000, MCSA, MCDBA, MCSD
| >Microsoft Partner Support
| >
| >Get Secure! - www.microsoft.com/security
| >
| >=====================================================
| >When responding to posts, please "Reply to Group" via
| >your newsreader so that others may learn and benefit
| >from your issue.
| >=====================================================
| >
| >This posting is provided "AS IS" with no warranties, and confers no
rights.
| >--------------------
| >| From: Pat <[email protected]>
| >| Subject: Lab Network
| >| Date: Sat, 28 Feb 2004 06:48:24 -0500
| >| Message-ID: <[email protected]>
| >| X-Newsreader: Forte Agent 1.93/32.576 English (American)
| >| MIME-Version: 1.0
| >| Content-Type: text/plain; charset=us-ascii
| >| Content-Transfer-Encoding: 7bit
| >| Newsgroups: microsoft.public.win2000.ras_routing
| >| NNTP-Posting-Host: mail.htechnology.com 198.65.193.67
| >| Lines: 1
| >| Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
| >| Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.ras_routing:10953
| >| X-Tomcat-NG: microsoft.public.win2000.ras_routing
| >|
| >| what I have now is the following
| >| Production network:
| >| W2K with AD and 100 users. on a 192.168.1.0 subnet.
| >|
| >| Lab network:
| >| W3K Ras server joined to production network for routing
| >| nic #1 192.168.1.241
| >| nic #2 10.100.0.1
| >| lab network on 10.100.0.0 subnet
| >|
| >| lab xp WS 10.100.0.2
| >| lab W3K server 10.100.0.3
| >|
| >| I have a route setup in my firewall for the 10.100.0.0 network, so I
| >| can get to the internet from my lab network. I can see the lab network
| >| from my production network. can RRas do any sought of Vlan so I
| >| can't see the lab network from the production network?
| >|
|
|
 
Jack,
when I try to set the basic firewall of the 192 nic, it blocks both
incoming and outgoing request. I'm looking for a KB article on this.

Hi Pat,

Thank you for the update!

The ICF of Windows Server 2003 blocks both incoming and outgoing request.
If you only want to disable incoming, you may use the Routing and Remote
Access console.

1. Open the console.

2. Select IP Routing->NAT->network adapter.

3. Open the properties of it and set the firewall.

Hope this answers your question!

Sincerely,
Jack Wang, MCSE 2000, MCSA, MCDBA, MCSD
Microsoft Partner Support

Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================

This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
| From: Pat <[email protected]>
| Subject: Re: Lab Network
| Date: Tue, 02 Mar 2004 12:30:21 -0500
| Message-ID: <[email protected]>
| References: <[email protected]>
<[email protected]>
| X-Newsreader: Forte Agent 1.93/32.576 English (American)
| MIME-Version: 1.0
| Content-Type: text/plain; charset=us-ascii
| Content-Transfer-Encoding: 7bit
| Newsgroups: microsoft.public.win2000.ras_routing
| NNTP-Posting-Host: mail.htechnology.com 198.65.193.67
| Lines: 1
| Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP11.phx.gbl
| Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.ras_routing:11023
| X-Tomcat-NG: microsoft.public.win2000.ras_routing
|
| I tried setting up the basic firewall on the 192.168.1.241 interface
| and this blocked outgoing requests also. do I need to put in a public
| ip in the address pool?
|
| On Mon, 01 Mar 2004 15:56:56 GMT, (e-mail address removed) (Jack
| Wang [MSFT]) wrote:
|
| >Hi Pat,
| >
| >Thank you for posting here.
| >
| >RRAS doesn't support VLAN. You may setup NAT/firewall on te Windows
Server
| >2003 computer. To do so, please just enable firewall on the
192.168.1.241
| >network adapter. Then, the 192.168.1.0 network will not browse the
| >10.100.0.0 network. The 10.100.0.0 network can access the 192.168.1.0
| >network and the Internet.
| >
| >Hope this helps!
| >
| >Sincerely,
| >Jack Wang, MCSE 2000, MCSA, MCDBA, MCSD
| >Microsoft Partner Support
| >
| >Get Secure! - www.microsoft.com/security
| >
| >=====================================================
| >When responding to posts, please "Reply to Group" via
| >your newsreader so that others may learn and benefit
| >from your issue.
| >=====================================================
| >
| >This posting is provided "AS IS" with no warranties, and confers no
rights.
| >--------------------
| >| From: Pat <[email protected]>
| >| Subject: Lab Network
| >| Date: Sat, 28 Feb 2004 06:48:24 -0500
| >| Message-ID: <[email protected]>
| >| X-Newsreader: Forte Agent 1.93/32.576 English (American)
| >| MIME-Version: 1.0
| >| Content-Type: text/plain; charset=us-ascii
| >| Content-Transfer-Encoding: 7bit
| >| Newsgroups: microsoft.public.win2000.ras_routing
| >| NNTP-Posting-Host: mail.htechnology.com 198.65.193.67
| >| Lines: 1
| >| Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
| >| Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.ras_routing:10953
| >| X-Tomcat-NG: microsoft.public.win2000.ras_routing
| >|
| >| what I have now is the following
| >| Production network:
| >| W2K with AD and 100 users. on a 192.168.1.0 subnet.
| >|
| >| Lab network:
| >| W3K Ras server joined to production network for routing
| >| nic #1 192.168.1.241
| >| nic #2 10.100.0.1
| >| lab network on 10.100.0.0 subnet
| >|
| >| lab xp WS 10.100.0.2
| >| lab W3K server 10.100.0.3
| >|
| >| I have a route setup in my firewall for the 10.100.0.0 network, so I
| >| can get to the internet from my lab network. I can see the lab network
| >| from my production network. can RRas do any sought of Vlan so I
| >| can't see the lab network from the production network?
| >|
|
|
 
Back
Top