<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN setup. Weird results in Windows Server 2003</title>
    <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318229#M892</link>
    <description>No way, no how is remote desktop going to be allowed to work through the firewall.&lt;BR /&gt;&lt;BR /&gt;It is quite wierd honestly that it works just fine on the internal network and not at all on the firewall.&lt;BR /&gt;&lt;BR /&gt;The meaning of this is obvious. The wizard that comes with Windows 2003 doesn't complete the setup.&lt;BR /&gt;&lt;BR /&gt;I will try adding protocol 50 and 51 when I get home.&lt;BR /&gt;&lt;BR /&gt;For a few reasons I'd like to totally redo the OS on the Windows 2003 server. Will I be able to activate the product again?&lt;BR /&gt;&lt;BR /&gt;SEP</description>
    <pubDate>Thu, 01 Jul 2004 08:15:20 GMT</pubDate>
    <dc:creator>Steven E. Protter</dc:creator>
    <dc:date>2004-07-01T08:15:20Z</dc:date>
    <item>
      <title>VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318222#M885</link>
      <description>I set up Windows 2003 Server for VPN Access. I got the general setup to work via a support.microsoft.com document that set go into remote access, turn it off, turn it back on and use the wizard to configure VPN.&lt;BR /&gt;&lt;BR /&gt;I did this and all of the sudden the VPN works great. Inside my local network. VPN works wonderfully using the default setting for Windows 2000 Pro or Windows XP Pro.&lt;BR /&gt;&lt;BR /&gt;I have tried forwarding the Linux firewall and got no results.&lt;BR /&gt;&lt;BR /&gt;So I put the VPN Nic on the public Internet and ran the same configuration wizard. Again, I can  only connect on my internal network.&lt;BR /&gt;&lt;BR /&gt;I am a real newbie and am thoroughly confused.&lt;BR /&gt;&lt;BR /&gt;I have remove active directory because this machine is not my primary domain controller.&lt;BR /&gt;&lt;BR /&gt;Its obvious I should have paid some more attention during installation, but I noticed this:&lt;BR /&gt;&lt;BR /&gt;The VPN setup has lines for Protocol 47, ports 500, 4500 and 1701 and 1723.&lt;BR /&gt;&lt;BR /&gt;The checkbox says accept only traffic on these ports and none other. My support.microsoft.com document says this.&lt;BR /&gt;&lt;BR /&gt;I have a few questions:&lt;BR /&gt;&lt;BR /&gt;1) Are there changes to the VPN client I can make to get this beastie to accept connections.&lt;BR /&gt;2) Are there other server componenents besides DCHP(which works) that need to be configured. Perhaps I need the firewall with NAT.&lt;BR /&gt;3) Does anyone know what firewall ports need to be forwarded to make the VPN work sitting behind a firewall.&lt;BR /&gt;4) Has anyone seen this kind of behavior?&lt;BR /&gt;5) Is there maybe a special VPN client to connect to Windows Server 2003?&lt;BR /&gt;&lt;BR /&gt;Complications: I will be out of the country the next two weeks. I am not sure I can connect to the box via Terminal services but I will try. I'm afraid I might mess up the box anyway.&lt;BR /&gt;&lt;BR /&gt;I can try anything on the client side.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I might need a book. I'm heading to the store at lunch time. &lt;BR /&gt;&lt;BR /&gt;Rules: Client solutions are acceptable for any platform. Server suggestions are welcome but they need to be Windows 2003 Server only. Getting this working on Windows 2000 Server was trivial.&lt;BR /&gt;&lt;BR /&gt;Lots of point opportunities, but I'm not going to be generous for solutions that don't apply to this situation.&lt;BR /&gt;&lt;BR /&gt;I am busily searching support.microsoft.com&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 29 Jun 2004 10:42:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318222#M885</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-06-29T10:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318223#M886</link>
      <description>Additional Question.&lt;BR /&gt;&lt;BR /&gt;I already activated Windows 2003 Server. Can I start over with a cold install?&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 29 Jun 2004 13:56:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318223#M886</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-06-29T13:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318224#M887</link>
      <description>i think u might have seen this page..&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/networking/vpnexamp.mspx" target="_blank"&gt;http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/networking/vpnexamp.mspx&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Ganesh</description>
      <pubDate>Tue, 29 Jun 2004 14:55:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318224#M887</guid>
      <dc:creator>Ganesh Babu</dc:creator>
      <dc:date>2004-06-29T14:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318225#M888</link>
      <description>and this one too..&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.microsoft.com/windowsserver2003/technologies/networking/vpn/default.mspx#XSLTfullModule125121120120" target="_blank"&gt;http://www.microsoft.com/windowsserver2003/technologies/networking/vpn/default.mspx#XSLTfullModule125121120120&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Ganesh</description>
      <pubDate>Tue, 29 Jun 2004 14:56:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318225#M888</guid>
      <dc:creator>Ganesh Babu</dc:creator>
      <dc:date>2004-06-29T14:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318226#M889</link>
      <description>Port-number description for most ports is found in the \WINDOWS\system32\drivers\etc\services file.&lt;BR /&gt;&lt;BR /&gt;1) More probably on the VPN server side and/or firewall. &lt;BR /&gt;2) &lt;A href="http://www.isaserver.org/img/upl/vpnkitbeta2/nat-t-packetfilters.htm" target="_blank"&gt;http://www.isaserver.org/img/upl/vpnkitbeta2/nat-t-packetfilters.htm&lt;/A&gt;&lt;BR /&gt;3) 500 is essential for VPN connections. Also some firewalls (especially the personal kind) may not support more than one connection via VPN.  Look for "multi-VPN" capability of the firewall. Also see point 2.&lt;BR /&gt;4) Haven't tried it yet... :)&lt;BR /&gt;5) Activate Remote Desktop, and allow it in your firewall (port 3389)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Rune</description>
      <pubDate>Wed, 30 Jun 2004 03:28:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318226#M889</guid>
      <dc:creator>Rune J. Winje</dc:creator>
      <dc:date>2004-06-30T03:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318227#M890</link>
      <description>1) Freeswan is known to connect to Windows AD VPN servers, check out &lt;A href="http://www.freeswan.org" target="_blank"&gt;http://www.freeswan.org&lt;/A&gt;&lt;BR /&gt;2) Not that Iâ  m aware of, and NAT is known to break some implementations of IPSEC&lt;BR /&gt;3) In general, you need port 500 (UDP), IP protocols 50 and 51. Some firewalls only accept IP Protocols 6 and 17 (TCP and UDP), so check this. &lt;BR /&gt;5) Windows is the only client Microsoft accepts for obvious reasons.&lt;BR /&gt;&lt;BR /&gt;I have to disagree strongly with rune, though DO NOT ALLOW REMOTE DESKTOP THROUGH YOUR FIREWALl, this is essentally giving hackers a conso</description>
      <pubDate>Wed, 30 Jun 2004 07:09:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318227#M890</guid>
      <dc:creator>Thomas Bianco</dc:creator>
      <dc:date>2004-06-30T07:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318228#M891</link>
      <description>Re: Thomas's comment on my 5)&lt;BR /&gt;&lt;BR /&gt;Yes - totally agree - my brain must've been "out to lunch".  Use VPN first to the internal network then Remote Desktop to the server.  Additionally allow only access to a limited account (meaning use RunAs when necessary).&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Rune</description>
      <pubDate>Thu, 01 Jul 2004 01:55:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318228#M891</guid>
      <dc:creator>Rune J. Winje</dc:creator>
      <dc:date>2004-07-01T01:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318229#M892</link>
      <description>No way, no how is remote desktop going to be allowed to work through the firewall.&lt;BR /&gt;&lt;BR /&gt;It is quite wierd honestly that it works just fine on the internal network and not at all on the firewall.&lt;BR /&gt;&lt;BR /&gt;The meaning of this is obvious. The wizard that comes with Windows 2003 doesn't complete the setup.&lt;BR /&gt;&lt;BR /&gt;I will try adding protocol 50 and 51 when I get home.&lt;BR /&gt;&lt;BR /&gt;For a few reasons I'd like to totally redo the OS on the Windows 2003 server. Will I be able to activate the product again?&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 01 Jul 2004 08:15:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318229#M892</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-07-01T08:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318230#M893</link>
      <description>Two good links Ganesh Babu,&lt;BR /&gt;&lt;BR /&gt;Similar to what I printed, but I believe once I put all of this together and go through the document methodically I will have my answer.&lt;BR /&gt;&lt;BR /&gt;What about the Routing and firewall configuration?&lt;BR /&gt;&lt;BR /&gt;Also, I'd like to check the server logs after connection attempts.&lt;BR /&gt;&lt;BR /&gt;Can someone give me the location and viewing instructions for the logging for the following components:&lt;BR /&gt;&lt;BR /&gt;Firewall&lt;BR /&gt;VPN/Remote Access&lt;BR /&gt;Routing&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 01 Jul 2004 08:19:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318230#M893</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-07-01T08:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318231#M894</link>
      <description>Hi, SEP&lt;BR /&gt;Founded this&lt;BR /&gt;&lt;A href="http://www.tacteam.net/isaserverorg/vpnkit/configisavpn.htm" target="_blank"&gt;http://www.tacteam.net/isaserverorg/vpnkit/configisavpn.htm&lt;/A&gt;&lt;BR /&gt;and&lt;BR /&gt;&lt;A href="http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/networking/vpndeplr.mspx" target="_blank"&gt;http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/networking/vpndeplr.mspx&lt;/A&gt;&lt;BR /&gt; &lt;BR /&gt;Regards&lt;BR /&gt;Bruno&lt;BR /&gt;</description>
      <pubDate>Thu, 01 Jul 2004 12:10:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318231#M894</guid>
      <dc:creator>Bruno Ganino</dc:creator>
      <dc:date>2004-07-01T12:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318232#M895</link>
      <description>I may have those packets forwarding.&lt;BR /&gt;&lt;BR /&gt;I've created a local certificate but when I try and connect through the firewall I get a message saying there is no valid certificate.&lt;BR /&gt;&lt;BR /&gt;I found this doc:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://support.microsoft.com/default.aspx?scid=kb;en-us;323342" target="_blank"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;323342&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Seems trivial to request a certificate for a machine sitting on the lan.&lt;BR /&gt;&lt;BR /&gt;How do I deliver this certificate to a workstation sitting 100 miles away if the server isn't on the public Internet. This is a VPN after all.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 27 Jul 2004 10:07:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318232#M895</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-07-27T10:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318233#M896</link>
      <description>I am now quite satisfied that my Linux boxes are properly forwarding packets.&lt;BR /&gt;&lt;BR /&gt;This article, applying to 2000 Server scares me.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://support.microsoft.com/default.aspx?scid=kb;en-us;247231" target="_blank"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;247231&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The fix suggested here does not work.&lt;BR /&gt;&lt;BR /&gt;This scares me more because the router in this case is a Linux box.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://support.microsoft.com/default.aspx?scid=kb;en-us;329858" target="_blank"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;329858&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I'm going to file a case on support.microsoft.com and perhaps open a incident with Microsoft&lt;BR /&gt;&lt;BR /&gt;After a google search and some other ideas.&lt;BR /&gt;&lt;BR /&gt;Help please, this is getting  ridiculous.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 28 Jul 2004 09:32:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318233#M896</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-07-28T09:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318234#M897</link>
      <description>&lt;A href="http://support.microsoft.com/default.aspx?scid=kb;en-us;829074" target="_blank"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;829074&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I seem to have this symptom.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 28 Jul 2004 09:45:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318234#M897</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-07-28T09:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN setup. Weird results</title>
      <link>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318235#M898</link>
      <description>Microsoft has admitted that there is a defect in the Windows 2003 Server product that prevents it from working behind certain firewalls. A similar defect was found and eventually corrected in the Server 2000 product.&lt;BR /&gt;&lt;BR /&gt;In the case of certain Linksys routers, Microsoft recommends a firmware update. Obviously this is not possible in a Linux ES 3.0 environment. I have done a direct connect to the Internet and locked down the server. It now works the way its supposed to work.&lt;BR /&gt;&lt;BR /&gt;I will continue to test firewall passthrough and as soon as it works report back. There may be a hotfix to the software that works, but Microsoft isn't talking about that right now. I'll report these findings back as well.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Fri, 30 Jul 2004 13:23:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/vpn-setup-weird-results/m-p/3318235#M898</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-07-30T13:23:24Z</dc:date>
    </item>
  </channel>
</rss>

