PDA

View Full Version : PPTP passthrough woes


__OpenGL__
12th June 2008, 08:50
I am having issues related to PPTP passthrough for 'road warriors'

Some routers, including the one in this office dont pass the vpn through reliably/properly.

I am aware that the netgear router in the office can likely only pass one VPN connection at a time. Right now my PC in the office can connect to the VPN reliably - it works fine. However when I first started trouble shooting the issue I couldnt connect from my pc properly, toggling the enabled check box for the VPN-PPTP rule that passes inbound vpn connections to our server fixed it... (just to clarify I am trying to connect to a remote VPN, we also have a VPN hosted on a local server)

I will disconnect the VPN on my pc and try from my laptop, the connection will then hang at verifying username and password before eventually disconnecting with an 'error 619'

Changing the IP address on my PC will replicate the problems the laptop runs into.

Rebooting the router wont help this issue, nor does toggling the VPN-PPTP rule check box on the router - my pc can however connect fine.

This is not VPN connection specific, ie from my pc any vpn connection will now work to several servers.

All the VPN's works fine via 3g card and via my home internet connection - which is firewalled by an ipcop router.

People running into this problem seem to be connecting through: netgear dg834g or a bt home hub.

Any ideas or suggestions welcomed.

SENT
16th June 2008, 12:20
have you created any DHCP rules regarding VPN connection ?
how is the DHCP set up
does the router do DHCP relay to your main DHCP server?

the quick fix is to bind your mac address of your laptop to its own static IP address then try again.

i would do this for all your VPN clients and have NO DHCP pool adresses available to VPN cliets so foriegn PCs cannot connect via VPN as they wont get an IP ..


there is a chance that your getting duplicate IP adress on your laptop and with one of the PC at work thats why the 3g card works ..

__OpenGL__
16th June 2008, 12:53
It doesnt get as far as trying to get an IP address, but the clients already have static ip's. - Connection hangs at verifying username and password then dies. I feel it could be related to the router or something.

Remote ip range is 192.168.250.0/24
Local ip range is 192.168.0.0/24
Local DHCP allocates addresses from .89 upwards
DHCP at the far end allocated addresses from .64 upward

SENT
16th June 2008, 14:06
this is something ive mended before its on the tip of my tongue,
there is a setting in the vpn properties and networking and advanced or something called "use default gateway on remote network" toggle this and try it the other way.

what happens is it connects and then tries to authenticate locally not downthe tunnel its just created ..

Jester
16th June 2008, 14:49
Your internal network is 192.168.0.x ?

The remote(home) users are on bt home hubs - default ip range being 192.168.0.x

If both are true then there is your problem.

Solution: change your internal network ip range.

You can make it work with RRAS as your VPN server but it aint pretty, oh and whilst I have done that, Vista clients say NO.

__OpenGL__
16th June 2008, 16:36
SENT: This is how they are,

Regarding IP addresses, the range at the remote end of the VPN was changed to 192.168.250.0/24 to avoid conflicts with the default ip ranges on homehubs, netgears etc

SENT
16th June 2008, 16:49
try it, its illogical i know, but my last Xp laptop i had to tick it or untick it for seemingly no reason, quite often. sometimes ticked worked sometimes unticked.
cant hurt to try . ..