Re: VPN through NAT?



hmm,

I assume you have TCP port 1723 forwarding from the internet/dmz to the PPTP host?. That should be enough for most PPTP based VPN clients.

It's can be difficult with IPSEC as you have to forward UDP 500, Protocol 50 and Protocol 51 to / from the VPN client from your NAT router.



------------------------------------------------------------------------

*/Jeff Norris/*
/~ Web Hosting ~ VPN Solutions ~ Network Management ~
Design, deploy, kick ass. /
*N*orris*Techs* dot net
http://www.norristechs.net
*AOL IM or Yahoo IM: _ ntshelper _*



Troy Settle wrote:
Probably not the best list to ask this on, but it's the closest that I'm subscribed to...

I have several customers who use VPN (Windows PPTP) to connect to their Corporate networks. The first was sitting behind NAT on a FreeBSD router. The PPTP did not work. I moved them out of NAT and onto a regular IP, and it worked fine. I then swapped out the FreeBSD box with a Cisco 2620 and again tried the PPTP via NAT, but still it wouldn't work.

Another customer is behind a Cisco 804 and his PPTP also did not work when his network was behind NAT, so I have to assign a static subnet for him.

From home, sitting behind NAT on my Netgear router, I can turn up PPTP connections all day long. What gives with FreeBSD and Cisco's implementation of NAT that PPTP doesn't want to work?

Thanks,

_______________________________________________
freebsd-isp@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-isp
To unsubscribe, send any mail to "freebsd-isp-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: PPTP VPN using MPD behind NAT help needed
    ... Because PPTP encapsulates PPP ... Some router conqurs this problem by simply "passing ... Pass Through") assuming there is only one PPTP client behind NAT. ... which is capable of handling GRE over NAT with many clients. ...
    (freebsd-net)
  • PPTP VPN pass-thru
    ... it doesn't support PPTP VPN ... didn't encrypt or integrity-check the TCP/UDP headers themselves, so NAT ... so would break the protocol. ...
    (uk.comp.sys.mac)
  • VPN through NAT?
    ... I have several customers who use VPN (Windows PPTP) to connect to their Corporate networks. ... I moved them out of NAT and onto a regular IP, ... I then swapped out the FreeBSD box with a Cisco 2620 and again tried the PPTP via NAT, ...
    (freebsd-isp)
  • Re: Cisco PIX behind NAT
    ... PPTP will fail when using NAT and hang at the point that you mention unless ... the Aztech router has an option to specifically support PPTP NAT Traversal. ... > I have a Cisco PIX and a Aztech DSL router. ...
    (comp.dcom.sys.cisco)
  • Re: VPN through NAT?
    ... That should be enough for most PPTP based VPN clients. ... Protocol 50 and Protocol 51 to / from the VPN client from your NAT router. ... If the *clients* are behind NAT, when running IPSEC there should be nothing ...
    (freebsd-isp)