Re: HELP!!!



Da Computer Guy <silicongangsta@xxxxxxxxx> wrote:
I have a WatchGuard III 700 firewall. I have a Microsoft 2003 SBS
server with RRAS configured for VPN connections. I am having
difficulties connecting a XP VPN client to the 2003 server. I can see
in the firewall log file that port 1723 is being passed through to the
2003 server but it is denying GRE (47). Below is an excerpt from the
log file:

12/14/06 15:12 firewalld[129]: deny in eth0:1 57 gre 20 115 X.X.X.X
X.X.X.X (default).

Each time i tried to establish a VPN connection i receive an error 721
connection could not be established.

I'm not quite sure where I need to allow the GRE (47) in the services
arean of the WatchGuard. Ihave port 47 allowed in the firewall rule for
VPN. I did read you need to setup port 47 an "IP" protocol but when I
do this it doesn't allow me to enter a NAT for the 2003 server.

You need to allow GRE on your firewall, which is IP *protocol* 47 (just
like TCP is IP protocol 6 and UDP is IP protocol 17, see [1] for more
information), not *port* 47. I'm not familiar with Watchguard, though,
so I can't tell you where/how exactly to do that.

[1] http://www.iana.org/assignments/protocol-numbers

cu
59cobalt
--
"If a software developer ever believes a rootkit is a necessary part of
their architecture they should go back and re-architect their solution."
--Mark Russinovich
.



Relevant Pages

  • Re: "Opening ports"
    ... When filtering log on port 5656, ... Create Protocol: ... Understanding the ISA 2004 Access Rule Processing ... Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa)
  • Re: SBS2003, Terminal server and Mobile 6
    ... RRAS as Firewall) and SBS 2K3 Premium: ... in order for a custom protocol to be considered a "Server" ... In the ''Policy Elements'' branch of ISA server mmc, ... Next...Enter the destination port number for the custom protocol being ...
    (microsoft.public.windows.server.sbs)
  • Re: not what Im after
    ... Users A, B, and C have to be listening to a port to get a message over that ... proxy server between then, then the proxy server actually "owns" the IP ... Will you be using an established protocol or are you writing your own? ... "Advanced .NET Remoting" by Ingo Rammer. ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Remote access from Internet
    ... An initial proposal was to implement the entire user interface as a Java applet and use a simple back-end protocol to move data. ... The user who desires access connects to relay server with a browser and logs in. ... then you probably need to block all ports *except* for one that you actively manage - ideally by something strong like SSH. ... As a side note on ssh security, there is no need to put ssh on port 22. ...
    (comp.arch.embedded)
  • RE: Port Forwarding
    ... RRAS as Firewall) and SBS 2K3 Premium: ... in order for a custom protocol to be considered a "Server" ... In the ''Policy Elements'' branch of ISA server mmc, ... For example, for Terminal Server, the port number would be 3389. ...
    (microsoft.public.windows.server.sbs)