VPN to Win2003 connection problems

  • Thread starter Thread starter Daniel vom Saal
  • Start date Start date
D

Daniel vom Saal

I've done extensive reading on similar problems, but cannot find any
definitive way to troubleshoot this so here goes...

- I've got a Win2003 Standard Server running on the LAN configured to accept
Remote Access
- When I try to connect using the standard VPN client provided on WinXP or
Win2000 from an external IP connection (dial up, cable modem, etc.) I get
the 721 error
- The LAN accessed the Internet through a fixed IP address and is behind a
Linksys BEFSR41 router
- I've downgraded to Linksys firmware 1.44.2z as suggested in numerous
places
- I've got port 1723 directed to the server that runs Remote Access
- The router's log indicates it sees the request on 1723
- The server's logs indicates it is hearing from the remote computer, but
gives up after a while. There are a ton of logs in the ...\tracing
directory, and I can see many of them log information but someone will have
to help me decipher it or ask for specifics (sorry)
- The logs in ...\logfiles\RAS does NOT indicate any attempt
- If I connect from a machine on the LAN using the simple name (ZEUS) it
works
- If I connect from a machine on the LAN using the FQDN (to the Router) it
does not work

Can someone point me in correct direction for the next step? From what I've
read others have gotten this working behind the Linksys router as long as
they stay at this level of firmware. It worked for me some time ago, but
since then I've upgraded to Win2003 and upgraded (then downgraded) the
router firmware. I know - don't ever change two things at once...

Thanks a lot,

DvS
 
If you can connect from a LAN machine using the local IP address of the
server, your server config is OK.

To connect from the Internet, you must use the public IP or FQDN of the
router. (This will not work from within your local network). The router
should be configured to forward tcp port 1723 to the RRAS server's LAN IP.

For this to work, your router must allow GRE (IP protocol 47) in both
directions. PPTP just sets up and maintains the tunnel. The actual data
travels as the payload of packets with GRE headers. If GRE is blocked, no
data can be exchanged and the connection fails with a 721 error.
 
Thanks for your ideas, but I've already confirmed most of what you said.

I am using the external address, and the Router is correctly forwarding at
least some of the request - I can view the logs on the RAS server and see
that a conversation is happening. I do not know if the router is correctly
allowing the GRE request to come across Port 1723 - how can I tell this? I
am not familiar with decyphering the logs that are generated in the tracing
directory.
 
Back
Top