Andy
Wed Jan 14 13:51:30 CST 2004
This is a multi-part message in MIME format.
------=_NextPart_000_00A0_01C3DAAD.E63F6EA0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
GRE is an IP Protocol (IP type 47) just like TCP (IP type 6) and UDP (IP =
type 11) are. Unfortunately, the NetGear Router you are using only does =
port forwarding for TCP and UDP packets.
However in an RT314, which I believe uses the same or very similar =
firmware to an RT311, you can designate one of the LAN IP addresses to =
be a "Default DMZ Server". All packets that aren't forwarded somewhere =
else will be forwarded to this IP address. =20
Before you do this though, make sure that you have ISA locked up good =
because it's as good as on the Internet.
Andy Nestor
"Kevin Weilbacher" <kweilbac@NO_SPAM_gte.net> wrote in message =
news:eny$a8h2DHA.1676@TK2MSFTNGP12.phx.gbl...
> Here is a link from Netgear that defines PPTP:
>
http://kbserver.netgear.com/kb_web_files/n101017.asp
>=20
> I could not find on Netgear's site any documentation for enabling GRE =
47
> (PPTP)
>=20
> Anyone else?
> -kw
>=20
> "dilltech" <support@dilltech.com> wrote in message
> news:016d01c3da0f$9c2dd5c0$a501280a@phx.gbl...
> > Thank you for the quick response Kevin.
> >
> > The router is a netgear rt311 gateway router and I can
> > figure out the port 1723 forwarding....
> >
> > What about the GTE 47?
> >
> > what is that?
> >
> > do I have to do anything in ISA?
> >
> > do the clients need firewall client installed?
> >
> > will the remote users be able to surf the web while
> > connected to the server via a VPN?
> >
> > thanks again
> >
> > RickD
> >
> > >-----Original Message-----
> > >We need to know what kind of router you have to tell you
> > how to forward any
> > >ports or enable PPTP.
> > >
> > >To allow a remote user to access files on your server,
> > they will need to
> > >login as a valid user on your server. So you will need to
> > create logins for
> > >each of them. Remotely, then, all they need to create a
> > VPN session (usually
> > >under dialup/networking, depending on the OS).
> > >-kw
> > >
> > >"dilltech" <support@dilltech.com> wrote in message
> > >news:063b01c3d956$99682520$a301280a@phx.gbl...
> > >> Kevin,
> > >>
> > >> A follow-on question,
> > >>
> > >> in a cable modem--->gateway router(NATTING)>external IAS
> > >> NIC---> internal ISA NIC environment
> > >>
> > >> 1. how do I forward port 1727?
> > >>
> > >> 2. how do i enable PPTP(GTE 47)??
> > >>
> > >> I would like to allow remote users to have access to a
> > >> folder on the server with their data in it.
> > >>
> > >> do I have to "publish" the folder?
> > >> I enabled dial-in in AD User properties and the user can
> > >> reach my "public" IP address of the cable modem.
> > >>
> > >> So can you help me drill-down to the server(SBS2K)folder
> > >> safely?
> > >>
> > >> Thank you for you assistence.
> > >>
> > >> RickD
> > >>
> > >> >-----Original Message-----
> > >> >did you go into the dialin part of AD user properties
> > and
> > >> specifically
> > >> >enable to allow user to have VPN access?
> > >> >
> > >> >also, do you have a router/firewall connected to your
> > >> server's internet NIC
> > >> >card? if so, do you have port 1727 forwarded to your
> > >> server? and do you have
> > >> >PPTP enabled (GTE 47)?
> > >> >
> > >> >"Stuart" <anonymous@discussions.microsoft.com> wrote in
> > >> message
> > >> >news:0b5b01c3d933$0f19e2a0$a001280a@phx.gbl...
> > >> >> Hi all,
> > >> >> Configured Server as per tutorial on
> > >> >> smallbizserver.net & have tried to VPN client that
> > is in
> > >> >> another country & not member of domain. Computer
> > name,
> > >> >> Logon 7 password details are in AD. Remote client
> > tries
> > >> >> to connect via VPN (setup as per smallbizserver.net
> > >> >> tutorial) but get error 649 returned - The account
> > >> >> doesn't have permission to dial in. Anyone have any
> > >> >> ideas / suggestions?
> > >> >>
> > >> >> Thanks,
> > >> >> Stuart
> > >> >
> > >> >
> > >> >.
> > >> >
> > >
> > >
> > >.
> > >
>=20
>
------=_NextPart_000_00A0_01C3DAAD.E63F6EA0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2800.1276" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY>
<DIV><FONT face=3DArial size=3D2>GRE is an IP Protocol (IP type =
47) just=20
like TCP (IP type 6) and UDP (IP type 11) are. =20
Unfortunately, the NetGear Router you are using only does =
port forwarding=20
for TCP and UDP packets.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT> </DIV>
<DIV><FONT face=3DArial size=3D2>However in an RT314, which I believe =
uses the same=20
or very similar firmware to an RT311, you can designate one of the =
LAN IP=20
addresses to be a "Default DMZ Server". All packets that =
aren't=20
forwarded somewhere else will be forwarded to this IP address. =20
</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT> </DIV>
<DIV><FONT face=3DArial size=3D2>Before you do this though, make sure =
that you have=20
ISA locked up good because it's as good as on the Internet.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT> </DIV>
<DIV><FONT face=3DArial size=3D2>Andy Nestor</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT> </DIV>
<DIV><FONT face=3DArial size=3D2>"Kevin Weilbacher" <</FONT><A=20
href=3D"mailto:kweilbac@NO_SPAM_gte.net"><FONT face=3DArial=20
size=3D2>kweilbac@NO_SPAM_gte.net</FONT></A><FONT face=3DArial =
size=3D2>> wrote in=20
message </FONT><A =
href=3D"news:eny$a8h2DHA.1676@TK2MSFTNGP12.phx.gbl"><FONT=20
face=3DArial =
size=3D2>news:eny$a8h2DHA.1676@TK2MSFTNGP12.phx.gbl</FONT></A><FONT=20
face=3DArial size=3D2>...</FONT></DIV><FONT face=3DArial size=3D2>> =
Here is a link=20
from Netgear that defines PPTP:<BR>> </FONT><A=20
href=3D"
http://kbserver.netgear.com/kb_web_files/n101017.asp"><FONT =
face=3DArial=20
size=3D2>
http://kbserver.netgear.com/kb_web_files/n101017.asp</FONT></A><=
BR><FONT=20
face=3DArial size=3D2>> <BR>> I could not find on Netgear's site =
any=20
documentation for enabling GRE 47<BR>> (PPTP)<BR>> <BR>> Anyone =
else?<BR>> -kw<BR>> <BR>> "dilltech" <</FONT><A=20
href=3D"mailto:support@dilltech.com"><FONT face=3DArial=20
size=3D2>support@dilltech.com</FONT></A><FONT face=3DArial size=3D2>> =
wrote in=20
message<BR>> </FONT><A=20
href=3D"news:016d01c3da0f$9c2dd5c0$a501280a@phx.gbl"><FONT face=3DArial=20
size=3D2>news:016d01c3da0f$9c2dd5c0$a501280a@phx.gbl</FONT></A><FONT =
face=3DArial=20
size=3D2>...<BR>> > Thank you for the quick response =
Kevin.<BR>>=20
><BR>> > The router is a netgear rt311 gateway router and I =
can<BR>>=20
> figure out the port 1723 forwarding....<BR>> ><BR>> > =
What=20
about the GTE 47?<BR>> ><BR>> > what is that?<BR>> =
><BR>>=20
> do I have to do anything in ISA?<BR>> ><BR>> > do the =
clients=20
need firewall client installed?<BR>> ><BR>> > will the =
remote users=20
be able to surf the web while<BR>> > connected to the server via a =
VPN?<BR>> ><BR>> > thanks again<BR>> ><BR>> >=20
RickD<BR>> ><BR>> > >-----Original Message-----<BR>> =
>=20
>We need to know what kind of router you have to tell you<BR>> =
> how to=20
forward any<BR>> > >ports or enable PPTP.<BR>> > =
><BR>>=20
> >To allow a remote user to access files on your server,<BR>> =
>=20
they will need to<BR>> > >login as a valid user on your server. =
So you=20
will need to<BR>> > create logins for<BR>> > >each of =
them.=20
Remotely, then, all they need to create a<BR>> > VPN session=20
(usually<BR>> > >under dialup/networking, depending on the =
OS).<BR>>=20
> >-kw<BR>> > ><BR>> > >"dilltech" <</FONT><A =
href=3D"mailto:support@dilltech.com"><FONT face=3DArial=20
size=3D2>support@dilltech.com</FONT></A><FONT face=3DArial size=3D2>> =
wrote in=20
message<BR>> > =
>news:063b01c3d956$99682520$a301280a@phx.gbl...<BR>>=20
> >> Kevin,<BR>> > >><BR>> > >> A =
follow-on=20
question,<BR>> > >><BR>> > >> in a cable=20
modem--->gateway router(NATTING)>external IAS<BR>> > =
>>=20
NIC---> internal ISA NIC environment<BR>> > >><BR>> =
>=20
>> 1. how do I forward port 1727?<BR>> > =
>><BR>> >=20
>> 2. how do i enable PPTP(GTE 47)??<BR>> > =
>><BR>>=20
> >> I would like to allow remote users to have access to =
a<BR>>=20
> >> folder on the server with their data in it.<BR>> >=20
>><BR>> > >> do I have to "publish" the =
folder?<BR>> >=20
>> I enabled dial-in in AD User properties and the user =
can<BR>> >=20
>> reach my "public" IP address of the cable modem.<BR>> >=20
>><BR>> > >> So can you help me drill-down to the=20
server(SBS2K)folder<BR>> > >> safely?<BR>> > =
>><BR>>=20
> >> Thank you for you assistence.<BR>> > =
>><BR>> >=20
>> RickD<BR>> > >><BR>> > >> =
>-----Original=20
Message-----<BR>> > >> >did you go into the dialin part =
of AD=20
user properties<BR>> > and<BR>> > >> =
specifically<BR>> >=20
>> >enable to allow user to have VPN access?<BR>> > =
>>=20
><BR>> > >> >also, do you have a router/firewall =
connected to=20
your<BR>> > >> server's internet NIC<BR>> > >> =
>card?=20
if so, do you have port 1727 forwarded to your<BR>> > >> =
server? and=20
do you have<BR>> > >> >PPTP enabled (GTE 47)?<BR>> =
>=20
>> ><BR>> > >> >"Stuart" <</FONT><A=20
href=3D"mailto:anonymous@discussions.microsoft.com"><FONT face=3DArial=20
size=3D2>anonymous@discussions.microsoft.com</FONT></A><FONT =
face=3DArial=20
size=3D2>> wrote in<BR>> > >> message<BR>> > =
>>=20
>news:0b5b01c3d933$0f19e2a0$a001280a@phx.gbl...<BR>> > >> =
>> Hi all,<BR>> > >>=20
>> Configured =
Server as=20
per tutorial on<BR>> > >> >> smallbizserver.net & =
have=20
tried to VPN client that<BR>> > is in<BR>> > >> =
>>=20
another country & not member of domain. Computer<BR>> > =
name,<BR>>=20
> >> >> Logon 7 password details are in AD. Remote =
client<BR>>=20
> tries<BR>> > >> >> to connect via VPN (setup as =
per=20
smallbizserver.net<BR>> > >> >> tutorial) but get =
error 649=20
returned - The account<BR>> > >> >> doesn't have =
permission to=20
dial in. Anyone have any<BR>> > >> >> ideas /=20
suggestions?<BR>> > >> >><BR>> > >> =
>>=20
Thanks,<BR>> > >> >> Stuart<BR>> > >> =
><BR>>=20
> >> ><BR>> > >> >.<BR>> > >>=20
><BR>> > ><BR>> > ><BR>> > >.<BR>> > =
><BR>> <BR>> </FONT></BODY></HTML>
------=_NextPart_000_00A0_01C3DAAD.E63F6EA0--