VPN IP Packet Filtering Question

  • Thread starter Thread starter Richard
  • Start date Start date
R

Richard

We have been running Win2000 server as a RAS/VPN server
for some time and it works very well connecting our branch
offices and remote users to us. However I decided that I
should lock out all unnecessary ports that are not needed
from the WAN (hopefully more secure). When I set an IP
Packet Filter on the WAN adapter either through Network
settings/advanced or through the WAN port in RAS, I can
only have 1 user connected to our VPN at a time. Nobody
else will be allowed to log in to the server. Does anyone
know of a way to only allow PPTP traffic from multiple
users using Windows VPN server.

Our configuration is simple:

LAN - VPN server - Internet

There is no firewall on either side of the VPN server just
2 ethernet cards inside.
 
The Packet filters that I set up were

(a) Under RRAS IP Routing/General/WAN Interface

Disable all but the following:
Input filter Destination TCP destination port 1723
Input filter Destination IP Protocol 47
Input filter Destination TCP source port 1723
Output filter Source TCP source port 1723
Output filter Source IP Protocol 47
Output filter Source TCP destination port 1723


Second try after that did not work

(b) Under Network connection/Wan interface/TCPIP/Advanced
TCP/IP filtering

I set Enable TCP/IP Filtering
Permit only TCP Ports 1723
Permit no UDP Ports
Permit only IP Protocols 47

It works but only for 1 (one) user at a time.
What have I done wrong?

:<(
 
Back
Top