Re: Can Windows Firewall be Configured to Allow Protocol 47 (GRE)?

From: David Beder [MSFT] (dbeder_at_online.microsoft.com)
Date: 10/21/05

  • Next message: Miha Pihler [MVP]: "Re: how to lock down the SAM database?"
    Date: Fri, 21 Oct 2005 00:34:09 -0700
    
    

    The firewall has a built-in exception for GRE when in the presence of an
    associated PPTP connection.
    If these packets were being dropped they'd show up in the log, but it
    doesn't sound like that's the case.

    -- 
    David
    Microsoft Windows Networking
    This posting is provided "AS IS" with no warranties, and confers no rights.
    "Joe" <Joe@discussions.microsoft.com> wrote in message 
    news:23928A0A-7BFB-4EA2-86D1-A3DE682CAF19@microsoft.com...
    >I have a windows 2003 server (web edition)
    > Using the Add Connection wizard I am allowing incoming VPN connections
    > The VPN connection works as expected when firewall is off
    > When I turn on the firewall, the client hangs on "verifying username and
    > password..."
    > From what I understand this means that the TCP port 1723 packets are 
    > getting
    > through but the GRE packets are not. By turning on firewall logging I can 
    > see
    > the port 1723 connections open and close so I know the port 1723 
    > exceptions
    > are working.
    > This did work with the firewall on for several days.
    > How can I add an exception to the Windows Firewall for GRE?
    > 
    

  • Next message: Miha Pihler [MVP]: "Re: how to lock down the SAM database?"

    Relevant Pages

    • Re: strange network traffic
      ... Maybe not so wise to not have a firewall and trust a third party lurker to ... Subject: strange network traffic ... > -> connection established, following packets have neither SYN nor ...
      (Security-Basics)
    • Re: port 80 is open
      ... you said above would be true if a software firewall is used since that is ... the PC so the ISP's router would see the hardware firewall but not the PC ... ISP would know that I am active since it would see packets coming from me ... If you have a connection to your ISP at all (you have a piece ...
      (comp.security.firewalls)
    • Re: Freeswan IPsec routing problem... ;^(
      ... > I forgot to mention that my ADSL connection is based on Dinamyc IPs, ... the default gateway is the place that a machine directs all packets it doesn't ... an address *behind* the other firewall. ... the tunnel leave via ipsec0 and will not be NAT'd then. ...
      (comp.os.linux.security)
    • Re: port 80 is open
      ... The firewall drops all packets initiated ... > internet the ISP router does not send the unreachable message. ... and then close the connection as your IP is seen as not connected. ...
      (comp.security.firewalls)
    • Re: VPN Problem Ereignis 20209
      ... Pruefe doch mal deine Firewall, ob die Generic Routing Encapsulation (GRE) ... packets blockt. ... A connection between the VPN server and the VPN client has been ...
      (microsoft.public.de.german.windows.server.networking)