VPN setup HELP!
Author
Discussion

dcw@pr

Original Poster:

3,516 posts

273 months

Thursday 13th January 2005
quotequote all
Further to my last thread on VPN, we bought a Netgear WGR614 router. We can take it back and change for another model if needs be - but there were no Drayteks at the shop.

the main problem is that I am new to this so I am not sure exactly where my problem is at the moment. Here's the setup,

Computer 1, Windows XP, cable broadband, static IP. Netgear WGR614 router. We have set up this computer to allow an incoming VPN connection, as shown here

www.onecomputerguy.com/networking/xp_vpn_server.htm

The router is set up to forward ports 1723,50,51,500 to the correct IP address. The computers windows firewall has been set up to let these ports through. A user has been set up for this specific purpose.

Computer 2, Windows XP, ADSL broadband, Nokia IP55 router. I have set up a VPN connection to Computer 1's IP address, and entered the correct username/password. When I try to connect with this, it looks up the IP address, then goes to "Verifying username and password " for about 30 seconds. It then goes to error 721 - remote computer not responded. If we delete the incoming VPN connection on computer 1, then attemt to connect to it, it goes to error 800 - unable to establish VPN connection.

I guesss this means that we are making some sort of connection before. Is it possible that the problem could be with computer 2's router? It really is the worst router in the world, so it wouldn't suprise me too much. But basically i'm very stuck, can anyone offer some help?

Edit to add - I have set my router so that it makes computer 2 totally visible to the internet, and it still doesnt work. i guess this means that my router isnt the issue?

>>> Edited by dcw@pr on Thursday 13th January 19:02

BliarOut

72,863 posts

269 months

Thursday 13th January 2005
quotequote all
It's protocol 50, not port 50 you need to forward IIRC. IE, you need to enable PPTP forwarding to the VPN endpoint.

TheExcession

11,669 posts

280 months

Friday 14th January 2005
quotequote all
BliarOut said:
It's protocol 50, not port 50 you need to forward IIRC. IE, you need to enable PPTP forwarding to the VPN endpoint.


You is a sharp cookie!

best
Ex

LaurenceFrost

691 posts

282 months

Friday 14th January 2005
quotequote all
Ah I can see where you're going wrong.

When you use a router for VPN, it is this you must connect to.

Computer 2 has a standalone connection.
Computer 1 has the router right?

Computer 2 must connect through VPN to the router on computer 1, not the machine itself. The router will probably have an internal address of 192.168.1.1 and the machine it's connected to will be 192.168.1.2, so from computer 2, you should be able to ping 192.168.1.2 (computer 1) and get a reply.

If this makes no sense then I don't mind explaining it again.

dcw@pr

Original Poster:

3,516 posts

273 months

Friday 14th January 2005
quotequote all
Right, I bought a new router for Computer 2, and that has fixed it - for now...

I am now connected to the VPN server on computer 1. Unfortuantely it is still not working as needed. the point of the connection is to allow us to sync our ACT contact management databases. But when we try it says it cannot resolve the server hosting the Master database.

What i am looking for is some way of testing if the VPN is working as it should be, so that i know if the fault is with ACT or the VPN. I cannot ping Computer 1 from here (computer 2), when i try his IP address that he uses on his network.

Basically I don't know what to expect from teh VPN, and therefore I don't really know what questions to ask. Should I be able to see his file sharing in "my network places"?

BliarOut

72,863 posts

269 months

Friday 14th January 2005
quotequote all
Check the default gateway on each PC. It should be the IP address of the local router. You MUST be able to ping both ways before trying anything else!

If you can ping router to router it sounds like a default GW problem.

dcw@pr

Original Poster:

3,516 posts

273 months

Friday 14th January 2005
quotequote all
Those settings seem to be right. here are the settings on computer 2





does that help?

>> Edited by dcw@pr on Friday 14th January 18:11

BliarOut

72,863 posts

269 months

Friday 14th January 2005
quotequote all
Post the same for computer 1 seeing as you know how to do it...

Then issue a tracert theothercomputersipaddress

ie tracert 192.168.1.101


and post the results of that test from both machines and we should be able to figure it out from there where the problem is.

dcw@pr

Original Poster:

3,516 posts

273 months

Friday 14th January 2005
quotequote all
I will get that other printscreen asap.

i cant do a tracert as it times out, even if i do it on 192.168.1.120 which is my vpn server (see pic added above during post edit)

dcw@pr

Original Poster:

3,516 posts

273 months

Friday 14th January 2005
quotequote all
computer 1,

malman

2,258 posts

289 months

Friday 14th January 2005
quotequote all
You have computer 1 and computer 2 on the same network (logically)

They are both on 192.168.1 with 255.255.255.0 as a mask So I think you have a routing problem here. There may be a way to get it working with those addresses but it would be easier to work out what is going on if you use logically different networks.

Probably easiest to change your setup computer 2 right?

If so then set the router with computer 2 to have a 192.168.2.x address and 255.255.255.0 mask and set computer 2 appropriately with a default gateway pointing to router address (or use dhcp). Make sure internet works etc then try your vpn connection again. You should find the ppp/pptp connection will setup its one route now. Hopefully that should just work. Check with ping to 192.168.1.100 (computer 1)

dcw@pr

Original Poster:

3,516 posts

273 months

Friday 14th January 2005
quotequote all
I tried changing the router ip address to 192.168.2.1, then i turned off dhcp (because it can only handle 192.168.1.x). after this i could not get the internet to work, altough i could access the router settings on 192.168.2.1- I manually set up the computers with 192.168.2.x addresses.

Can I achieve the same effect by changing the subnet mask to 255.255.254.0? I have no idea what subnet masks are...

BliarOut

72,863 posts

269 months

Saturday 15th January 2005
quotequote all
Masks should be 255.255.255.0 in your configuration. Don't worry what masks are for now, that is correct.

You need two seperate networks for routing to work. One network is 192.168.1.0, the other should be 192.168.2.0

I'll post more when I'm sober.... if I remember

dcw@pr

Original Poster:

3,516 posts

273 months

Saturday 15th January 2005
quotequote all
BliarOut said:


I'll post more when I'm sober.... if I remember


Ditto........

malman

2,258 posts

289 months

Saturday 15th January 2005
quotequote all
dcw@pr said:
I tried changing the router ip address to 192.168.2.1, then i turned off dhcp (because it can only handle 192.168.1.x). after this i could not get the internet to work, altough i could access the router settings on 192.168.2.1- I manually set up the computers with 192.168.2.x addresses.

Can I achieve the same effect by changing the subnet mask to 255.255.254.0? I have no idea what subnet masks are...


What is the new router? Make and model


In this case your router IP address should be 192.168.2.1 mask 255.255.255.0

Manually set an ip address on the pc to 192.168.2.x (x = anything between 2 and 254) For example i'll use 5

IP = 192.168.2.5
Subnet Mask = 255.255.255.0
Default Gateway = 192.168.2.1

DNS = this was set by dhcp before but now needs to be manual. Some routers will do DNS forwarding in which case this should be the address of the router 192.168.2.1 same as default gateway. If the router doesn't do this then you will need to put in one from your ISP.

once you have these setup open command prompt and try these

ping 192.168.2.1 -> should reply its your router prove local network settings

ping 66.102.11.104 -> should reply and prove internet connection as this is one of googles IP's

ping www.google.co.uk -> should reply if dns is working correctly

without dns internet explorer won't lookup pages properly but you may still have a working internet connection as proved by the above pings to IP's

Once that lot is working fire up the VPN and try

ping 192.168.1.100 -> should now reply computer 1 remote vpn host

see how you get on with that and post any problems with pings etc

Hope that sorts it

dcw@pr

Original Poster:

3,516 posts

273 months

Saturday 15th January 2005
quotequote all
Ah I see, I didn't have the DNS set up correctly. I have now changed my network to 192.168.2.x, and it is all working fine. I can't try out the VPN at the moment, but I will let you know what happens when I do.

Cheers eveyone for the help so far

dcw@pr

Original Poster:

3,516 posts

273 months

Monday 17th January 2005
quotequote all
OK, I feel that we are getting somewhere, but still there's more to do...

Now that Computer 2's network is on 192.168.2.x I can ping the router for computer 1, and access its setup pages through IE, at 192.168.1.1 However, I still cannot ping his computer directly - 192.168.1.100, or any other address that I have tried (.120 & .121). I cannot see his computers in My Network Places. And when I try to sync ACT, it still says it cannt resolve the host computer etc...

Any ideas?

BliarOut

72,863 posts

269 months

Monday 17th January 2005
quotequote all
If it's on XP SP2, there will be a firewall turned on by default. If the router is firewalled etc, you can turn it off on the LAN interface.

Check also for Norton Internet Security, Zone alarm etc. All of these will stop it responding to pings/network requests etc.

malman

2,258 posts

289 months

Monday 17th January 2005
quotequote all
dcw@pr said:
OK, I feel that we are getting

I can ping the router for computer 1, and access its setup pages through IE, at 192.168.1.1

Any ideas?


This proves your vpn is working as you can access resources on his network.

Now you need to check for firewall software on his PC as mentioned above xp2 firewall/ norton /zonealarm.

Once you can ping his machine you wiil then probably need to look at user accounts/shares etc to get your ACT stuff syncing up.



dcw@pr

Original Poster:

3,516 posts

273 months

Monday 17th January 2005
quotequote all
OK...

Got it all to work Syncing and everything! But that was only with all firewall on routers and computers turned off. Through a process of elimination we found out (as pointed out above) that it was the windows firewall on computer 1 which was causing the problem.

the thing is, we can't see which settings to change to allow it to work with the firewall on?