Re: VPN through NAT?



On 08/13/06 09:21, Troy Settle wrote:
Probably not the best list to ask this on, but it's the closest that I'm subscribed to...

I have several customers who use VPN (Windows PPTP) to connect to their Corporate networks. The first was sitting behind NAT on a FreeBSD router. The PPTP did not work. I moved them out of NAT and onto a regular IP, and it worked fine. I then swapped out the FreeBSD box with a Cisco 2620 and again tried the PPTP via NAT, but still it wouldn't work.

Another customer is behind a Cisco 804 and his PPTP also did not work when his network was behind NAT, so I have to assign a static subnet for him.

From home, sitting behind NAT on my Netgear router, I can turn up PPTP connections all day long. What gives with FreeBSD and Cisco's implementation of NAT that PPTP doesn't want to work?

Thanks,



I'm no expert on the subject, but I recall hitting this in the past and reading about passing GRE packets through, along with a couple of ports to forward to the VPN endpoint.

Eric


--
------------------------------------------------------------------------
Eric Anderson Sr. Systems Administrator Centaur Technology
Anything that works is better than anything that doesn't.
------------------------------------------------------------------------
_______________________________________________
freebsd-isp@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-isp
To unsubscribe, send any mail to "freebsd-isp-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: PPTP VPN using MPD behind NAT help needed
    ... Because PPTP encapsulates PPP ... Some router conqurs this problem by simply "passing ... Pass Through") assuming there is only one PPTP client behind NAT. ... which is capable of handling GRE over NAT with many clients. ...
    (freebsd-net)
  • PPTP VPN pass-thru
    ... it doesn't support PPTP VPN ... didn't encrypt or integrity-check the TCP/UDP headers themselves, so NAT ... so would break the protocol. ...
    (uk.comp.sys.mac)
  • Re: Cisco PIX behind NAT
    ... PPTP will fail when using NAT and hang at the point that you mention unless ... the Aztech router has an option to specifically support PPTP NAT Traversal. ... > I have a Cisco PIX and a Aztech DSL router. ...
    (comp.dcom.sys.cisco)
  • Re: Using VPN (PPTP) behind Windows XP Firewall
    ... >> If you want to PPTP inbound to a device behind a NAT appliance, ... > Windows Firewall is the problem. ...
    (comp.security.firewalls)
  • Re: Checkpoint-1 and PPTP Sessions
    ... In essence, PPTP will work inbound through NAT, but it will not ... > When I try instanciating a PPTP from the PC behind the firewall, ... > connection being established.. ...
    (comp.security.firewalls)