Win2K Pro VPN Questions

  • Thread starter Thread starter mcp6453
  • Start date Start date
M

mcp6453

I have a Win2K Professional SP4 machine at home configured to accept an
incoming VPN connection. The computer has a static IP is behind a router
with port 1723 forwarded to it. "Allow callers to access my local
network" is checked in the "Incoming TCP/IP Properties" box. When I VPN
into the computer, the tunnel is established easily. The user name and
password are recognized. The remote computer is on 192.168.4.x subnet,
and the home computer is 192.168.1.x. After the computers connect, the
remote computer is unable to ping anything on the 192.168.1.x subnet,
including the router. The remote machine is Windows XP. How do I
troubleshoot this problem? The shares on the home computer are readily
accessible by the other computers on the LAN, so the problem is not a
sharing problem. I'm lost. It's as if another port needs to be forwarded.

Any helpful sites elaborating on this problem would be welcome!
 
make sure no firewall in the win2k vpn host to block the ping. also, posting the result of ipconfig /all and routing table here may help.

Bob Lin, MS-MVP, MCSE & CNE
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
This posting is provided "AS IS" with no warranties.
Don't send e-mail or reply to me except you need consulting services. Posting on MS newsgroup will benefit all readers and you may get more help.
I have a Win2K Professional SP4 machine at home configured to accept an
incoming VPN connection. The computer has a static IP is behind a router
with port 1723 forwarded to it. "Allow callers to access my local
network" is checked in the "Incoming TCP/IP Properties" box. When I VPN
into the computer, the tunnel is established easily. The user name and
password are recognized. The remote computer is on 192.168.4.x subnet,
and the home computer is 192.168.1.x. After the computers connect, the
remote computer is unable to ping anything on the 192.168.1.x subnet,
including the router. The remote machine is Windows XP. How do I
troubleshoot this problem? The shares on the home computer are readily
accessible by the other computers on the LAN, so the problem is not a
sharing problem. I'm lost. It's as if another port needs to be forwarded.

Any helpful sites elaborating on this problem would be welcome!
 
There is no firewall.

Here's ipconfig. How do I post the routing table?

Windows 2000 IP Configuration

Host Name . . . . . . . . . . . . : 6579
Primary DNS Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Broadcast
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection 2:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek RTL8139/810X Family PCI
Fast Ethernet NIC
Physical Address. . . . . . . . . : 00-40-F4-98-21-FA
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.49
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.1

PPP adapter RAS Server (Dial In) Interface:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : WAN (PPP/SLIP) Interface
Physical Address. . . . . . . . . : 00-54-45-00-00-00
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.102
Subnet Mask . . . . . . . . . . . : 255.255.255.255
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . :
 
From the VPN client ping 192.168.1.012. Can you ping it? If not, post the results of the client ipconfig and routing table. to print out the routing table, use "route print" command. this page may help,

routing issues on vpn
Routing Issues on VPN. Can ping VPN server only but not other resources Can't
access the internal server when remote client establishes VPN ...
www.chicagotech.net/routingissuesonvpn.htm


Bob Lin, MS-MVP, MCSE & CNE
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
This posting is provided "AS IS" with no warranties.
Don't send e-mail or reply to me except you need consulting services. Posting on MS newsgroup will benefit all readers and you may get more help.
There is no firewall.

Here's ipconfig. How do I post the routing table?

Windows 2000 IP Configuration

Host Name . . . . . . . . . . . . : 6579
Primary DNS Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Broadcast
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection 2:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek RTL8139/810X Family PCI
Fast Ethernet NIC
Physical Address. . . . . . . . . : 00-40-F4-98-21-FA
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.49
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.1

PPP adapter RAS Server (Dial In) Interface:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : WAN (PPP/SLIP) Interface
Physical Address. . . . . . . . . : 00-54-45-00-00-00
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.102
Subnet Mask . . . . . . . . . . . : 255.255.255.255
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . :
 
I cannot ping 192.168.1.012.

Ipconfig:


Windows 2000 IP Configuration



Host Name . . . . . . . . . . . . : 6579
Primary DNS Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Broadcast
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection 2:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek RTL8139/810X Family PCI
Fast Ethernet NIC
Physical Address. . . . . . . . . : 00-40-F5-98-21-FD
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.49
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.1

PPP adapter RAS Server (Dial In) Interface:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : WAN (PPP/SLIP) Interface
Physical Address. . . . . . . . . : 00-54-45-00-00-00
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.102
Subnet Mask . . . . . . . . . . . : 255.255.255.255
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . :

Route Print:

===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x1000002 ...00 53 45 00 00 00 ...... WAN (PPP/SLIP) Interface
0x1000003 ...00 40 f4 98 21 fd ...... Realtek 8139-series PCI NIC

===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.49 1
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.49 192.168.1.49 1
192.168.1.49 255.255.255.255 127.0.0.1 127.0.0.1 1
192.168.1.102 255.255.255.255 127.0.0.1 127.0.0.1 1
192.168.1.102 255.255.255.255 192.168.1.102 192.168.1.102 1
192.168.1.255 255.255.255.255 192.168.1.49 192.168.1.49 1
209.170.129.150 255.255.255.255 192.168.1.1 192.168.1.49 1
224.0.0.0 224.0.0.0 192.168.1.49 192.168.1.49 1
255.255.255.255 255.255.255.255 192.168.1.49 192.168.1.49 1
Default Gateway: 192.168.1.1
===========================================================================
Persistent Routes:
None

----------------------------
 
the problem is both sites are using the same ip range. see these pages for the details.

both VPN sites are in the same IP range
(A bridge is a connection between segments which are in the same IP subnet).
Related Topics. VPN Browsing Issues VPN Logon Issues VPN Name Resolution ....
www.chicagotech.net/Q&A/vpn20.htm

vpn using same ip in the different subnet
VPN server and client are using the same IP but in different subnets ... office via
VPN. My home users have the internal IP address range of 192.168.0.X/24 ....
www.chicagotech.net/Q&A/vpn38.htm


Bob Lin, MS-MVP, MCSE & CNE
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
This posting is provided "AS IS" with no warranties.
Don't send e-mail or reply to me except you need consulting services. Posting on MS newsgroup will benefit all readers and you may get more help.

I cannot ping 192.168.1.012.

Ipconfig:


Windows 2000 IP Configuration



Host Name . . . . . . . . . . . . : 6579
Primary DNS Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Broadcast
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection 2:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek RTL8139/810X Family PCI
Fast Ethernet NIC
Physical Address. . . . . . . . . : 00-40-F5-98-21-FD
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.49
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.1

PPP adapter RAS Server (Dial In) Interface:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : WAN (PPP/SLIP) Interface
Physical Address. . . . . . . . . : 00-54-45-00-00-00
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.102
Subnet Mask . . . . . . . . . . . : 255.255.255.255
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . :

Route Print:

===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x1000002 ...00 53 45 00 00 00 ...... WAN (PPP/SLIP) Interface
0x1000003 ...00 40 f4 98 21 fd ...... Realtek 8139-series PCI NIC

===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.49 1
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.49 192.168.1.49 1
192.168.1.49 255.255.255.255 127.0.0.1 127.0.0.1 1
192.168.1.102 255.255.255.255 127.0.0.1 127.0.0.1 1
192.168.1.102 255.255.255.255 192.168.1.102 192.168.1.102 1
192.168.1.255 255.255.255.255 192.168.1.49 192.168.1.49 1
209.170.129.150 255.255.255.255 192.168.1.1 192.168.1.49 1
224.0.0.0 224.0.0.0 192.168.1.49 192.168.1.49 1
255.255.255.255 255.255.255.255 192.168.1.49 192.168.1.49 1
Default Gateway: 192.168.1.1
===========================================================================
Persistent Routes:
None

----------------------------
 
I must have sent the wrong Route Print. Here is the one from the remote
computer, not the one that is accepting the VPN connection. The remote
computer is on 192.168.4.49. The host computer is on 192.168.1.49.
Thanks for your patience!


===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 60 08 16 84 88 ...... 3Com 3C905TX-based Ethernet Adapter
(Generic) - Packet Scheduler Miniport
0x20004 ...00 53 45 00 00 00 ...... WAN (PPP/SLIP) Interface
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.4.1 192.168.4.49 20
24.211.216.14 255.255.255.255 192.168.4.1 192.168.4.49 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.100 192.168.1.100 1
192.168.1.100 255.255.255.255 127.0.0.1 127.0.0.1 50
192.168.1.255 255.255.255.255 192.168.1.100 192.168.1.100 50
192.168.4.0 255.255.255.0 192.168.4.49 192.168.4.49 20
192.168.4.49 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.4.255 255.255.255.255 192.168.4.49 192.168.4.49 20
224.0.0.0 240.0.0.0 192.168.1.100 192.168.1.100 50
224.0.0.0 240.0.0.0 192.168.4.49 192.168.4.49 20
255.255.255.255 255.255.255.255 192.168.1.100 192.168.1.100 1
255.255.255.255 255.255.255.255 192.168.4.49 192.168.4.49 1
Default Gateway: 192.168.4.1
===========================================================================
Persistent Routes:
None
 
Anybody?

I must have sent the wrong Route Print. Here is the one from the remote
computer, not the one that is accepting the VPN connection. The remote
computer is on 192.168.4.49. The host computer is on 192.168.1.49.
Thanks for your patience!


===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 60 08 16 84 88 ...... 3Com 3C905TX-based Ethernet Adapter
(Generic) - Packet Scheduler Miniport
0x20004 ...00 53 45 00 00 00 ...... WAN (PPP/SLIP) Interface
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.4.1 192.168.4.49 20
24.211.216.14 255.255.255.255 192.168.4.1 192.168.4.49 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.100 192.168.1.100 1
192.168.1.100 255.255.255.255 127.0.0.1 127.0.0.1 50
192.168.1.255 255.255.255.255 192.168.1.100 192.168.1.100 50
192.168.4.0 255.255.255.0 192.168.4.49 192.168.4.49 20
192.168.4.49 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.4.255 255.255.255.255 192.168.4.49 192.168.4.49 20
224.0.0.0 240.0.0.0 192.168.1.100 192.168.1.100 50
224.0.0.0 240.0.0.0 192.168.4.49 192.168.4.49 20
255.255.255.255 255.255.255.255 192.168.1.100 192.168.1.100 1
255.255.255.255 255.255.255.255 192.168.4.49 192.168.4.49 1
Default Gateway: 192.168.4.1
===========================================================================
Persistent Routes:
None


the problem is both sites are using the same ip range. see these pages
for the details.


both *VPN* sites are in the *same* *IP* *range*
<http://www.chicagotech.net/Q&A/vpn20.htm>
(A bridge is a connection between segments which are in the *same*
*IP* subnet).
Related Topics. *VPN* Browsing Issues *VPN* Logon Issues *VPN* Name
Resolution *...*
www.chicagotech.net/Q&A/*vpn*20.htm
<http://www.chicagotech.net/Q&A/vpn20.htm>

*vpn* using *same* *ip* in the different subnet
<http://www.chicagotech.net/Q&A/vpn38.htm>
*VPN* server and client are using the *same* *IP* but in different
subnets *...* office via
*VPN*. My home users have the internal *IP* address *range* of
192.168.0.X/24 *...*
www.chicagotech.net/Q&A/*vpn*38.htm
<http://www.chicagotech.net/Q&A/vpn38.htm>


Bob Lin, MS-MVP, MCSE & CNE
How to Setup Windows, Network, VPN & Remote Access on
http://www.HowToNetworking.com
Networking, Internet, Routing, VPN Troubleshooting on
http://www.ChicagoTech.net
This posting is provided "AS IS" with no warranties.
Don't send e-mail or reply to me except you need consulting services.
Posting on MS newsgroup will benefit all readers and you may get more
help.

"mcp6453" <[email protected] <mailto:[email protected]>>
wrote in message I cannot ping 192.168.1.012.

Ipconfig:


Windows 2000 IP Configuration



Host Name . . . . . . . . . . . . : 6579
Primary DNS Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Broadcast
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection 2:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek RTL8139/810X Family PCI
Fast Ethernet NIC
Physical Address. . . . . . . . . : 00-40-F5-98-21-FD
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.49
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.1

PPP adapter RAS Server (Dial In) Interface:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : WAN (PPP/SLIP) Interface
Physical Address. . . . . . . . . : 00-54-45-00-00-00
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.102
Subnet Mask . . . . . . . . . . . : 255.255.255.255
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . :

Route Print:


===========================================================================

Interface List
0x1 ........................... MS TCP Loopback interface
0x1000002 ...00 53 45 00 00 00 ...... WAN (PPP/SLIP) Interface
0x1000003 ...00 40 f4 98 21 fd ...... Realtek 8139-series PCI NIC


===========================================================================


===========================================================================

Active Routes:
Network Destination Netmask Gateway
Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1
192.168.1.49 1
127.0.0.0 255.0.0.0 127.0.0.1
127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.49
192.168.1.49 1
192.168.1.49 255.255.255.255 127.0.0.1
127.0.0.1 1
192.168.1.102 255.255.255.255 127.0.0.1
127.0.0.1 1
192.168.1.102 255.255.255.255 192.168.1.102
192.168.1.102 1
192.168.1.255 255.255.255.255 192.168.1.49
192.168.1.49 1
209.170.129.150 255.255.255.255 192.168.1.1
192.168.1.49 1
224.0.0.0 224.0.0.0 192.168.1.49
192.168.1.49 1
255.255.255.255 255.255.255.255 192.168.1.49
192.168.1.49 1
Default Gateway: 192.168.1.1

===========================================================================

Persistent Routes:
None

----------------------------
From the VPN client ping 192.168.1.012. Can you ping it? If not, post
the results of the client ipconfig and routing table. to print out
the routing table, use "route print" command. this page may help,

*routing* *issues* on *vpn*
<http://www.chicagotech.net/routingissuesonvpn.htm> *Routing*
*Issues* on *VPN*. Can ping *VPN* server only but not other resources
Can't access the internal server when remote client establishes *VPN*
*...* www.chicagotech.net/*routing**issues*on*vpn*.htm
<http://www.chicagotech.net/routingissuesonvpn.htm>


Bob Lin, MS-MVP, MCSE & CNE How to Setup Windows, Network, VPN &
Remote Access on http://www.HowToNetworking.com Networking, Internet,
Routing, VPN Troubleshooting on http://www.ChicagoTech.net This
posting is provided "AS IS" with no warranties. Don't send e-mail or
reply to me except you need consulting services. Posting on MS
newsgroup will benefit all readers and you may get more help.

"mcp6453" <[email protected] <mailto:[email protected]>
wrote in message There is no firewall.

Here's ipconfig. How do I post the routing table?

Windows 2000 IP Configuration

Host Name . . . . . . . . . . . . : 6579 Primary DNS Suffix . . . .
. . . : Node Type . . . . . . . . . . . . : Broadcast IP Routing
Enabled. . . . . . . . : Yes WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection 2:

Connection-specific DNS Suffix . : Description . . . . . . . . . . .
: Realtek RTL8139/810X Family PCI Fast Ethernet NIC Physical Address.
. . . . . . . . : 00-40-F4-98-21-FA DHCP Enabled. . . . . . . . . . .
: No IP Address. . . . . . . . . . . . : 192.168.1.49 Subnet Mask . .
. . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . :
192.168.1.1 DNS Servers . . . . . . . . . . . : 192.168.1.1

PPP adapter RAS Server (Dial In) Interface:

Connection-specific DNS Suffix . : Description . . . . . . . . . . .
: WAN (PPP/SLIP) Interface Physical Address. . . . . . . . . :
00-54-45-00-00-00 DHCP Enabled. . . . . . . . . . . : No IP Address.
. . . . . . . . . . . : 192.168.1.102 Subnet Mask . . . . . . . . . .
. : 255.255.255.255 Default Gateway . . . . . . . . . : DNS Servers .
. . . . . . . . . . :

Robert L [MS-MVP] wrote:
make sure no firewall in the win2k vpn host to block the ping.
also, posting the result of ipconfig /all and routing table here
may help.

Bob Lin, MS-MVP, MCSE & CNE How to Setup Windows, Network, VPN &
Remote Access on http://www.HowToNetworking.com Networking,
Internet, Routing, VPN Troubleshooting on
http://www.ChicagoTech.net This posting is provided "AS IS" with no
warranties. Don't send e-mail or reply to me except you need
consulting
services.
Posting on MS newsgroup will benefit all readers and you may get
more help.

"mcp6453" <[email protected] <mailto:[email protected]>
<mailto:[email protected]> <mailto:[email protected]>>
wrote in message I
have a Win2K Professional SP4 machine at home configured to
accept an
incoming VPN connection. The computer has a static IP is behind a
router with port 1723 forwarded to it. "Allow callers to access my
local network" is checked in the "Incoming TCP/IP Properties" box.
When I VPN
into the computer, the tunnel is established easily. The user
name and
password are recognized. The remote computer is on
192.168.4.x subnet,
and the home computer is 192.168.1.x. After the computers
connect, the
remote computer is unable to ping anything on the 192.168.1.x
subnet,
including the router. The remote machine is Windows XP. How do I
troubleshoot this problem? The shares on the home computer
are readily
accessible by the other computers on the LAN, so the problem
is not a
sharing problem. I'm lost. It's as if another port needs to be
forwarded.

Any helpful sites elaborating on this problem would be welcome!
 
Back
Top