MS firewall interfering with vpn
Windows Server Forum Index Windows Server
Server discussion on Windows platform.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web winserverhelp.com
MS firewall interfering with vpn

 
Post new topic   Reply to topic    Windows Server Forum Index -> Small Business Server 2003
Author Message
paulie
Guest





Posted: Tue Jan 18, 2005 5:49 am    Post subject: MS firewall interfering with vpn Reply with quote

Hi,

I brought my XP Pro laptop into my home office on which one desktop computer
shares its cable internet connection via a four port switch. By default
Windows firewalls the LAN Connection on that desktop, which goes to the cable
modem. With the firewall enabled, I can make a VPN connection to my server,
however, the laptop insists on working offline. If I simply disable the
firewall on that connection, then the VPN connects well and I am able to work
online, browser shared drives, and even print to office printers.

Is there any way that I can alter the firewall settings to allow the
connection? I feel better with a firewalled network but if it blocks my VPN,
I will have to disable it and rely 100% on my antivirus.

Any ideas?

thanks everyone,

paulie
Back to top
Mariette Knap [SBS MVP]
Guest





Posted: Tue Jan 18, 2005 6:17 am    Post subject: Re: MS firewall interfering with vpn Reply with quote

In news:94FBF58E-FE6A-4FAF-83E9-3A54E5159446@microsoft.com,
paulie <paulie@discussions.microsoft.com> wrote:

Quote:
I brought my XP Pro laptop into my home office on which one desktop
computer shares its cable internet connection via a four port switch.
By default Windows firewalls the LAN Connection on that desktop,
which goes to the cable modem. With the firewall enabled, I can make
a VPN connection to my server, however, the laptop insists on working
offline. If I simply disable the firewall on that connection, then
the VPN connects well and I am able to work online, browser shared
drives, and even print to office printers.

Is there any way that I can alter the firewall settings to allow the
connection? I feel better with a firewalled network but if it blocks
my VPN, I will have to disable it and rely 100% on my antivirus.

I am wondering if the settings for the Windows Firewall defined in a GPO on
your SBS server are properly pushed to your laptop. Can you tell me what you
see in the Windows Firewall on your laptop if it is connected at home? Are
there any exceptions listed?

Under normal circumstances the Windows Firewall should allow VPN traffic.

--
Mariėtte Knap - MVP
http://www.smallbizserver.net
Take part in SBS forum:
http://www.smallbizserver.net/Default.aspx?tabid=154
Back to top
paulie
Guest





Posted: Tue Jan 18, 2005 8:29 am    Post subject: RE: MS firewall interfering with vpn Reply with quote

The settings on the laptop are fine. I know that because i can connect via a
dial up connection from a hotel. The problem occurs when I use the shared
internet connection on my home nework, which only employs a switch. With the
firewall on on the desktop that shares the connection to my laptop, I can
connect, but I cannot see shared drives or use printers. With the firewall
off on the desktop that shares the connection to my laptop, everything works
just fine. The firewall on the desktop connection is the issue clearly, right?

thanks for you very quick response.

cheers.

"paulie" wrote:

Quote:
Hi,

I brought my XP Pro laptop into my home office on which one desktop computer
shares its cable internet connection via a four port switch. By default
Windows firewalls the LAN Connection on that desktop, which goes to the cable
modem. With the firewall enabled, I can make a VPN connection to my server,
however, the laptop insists on working offline. If I simply disable the
firewall on that connection, then the VPN connects well and I am able to work
online, browser shared drives, and even print to office printers.

Is there any way that I can alter the firewall settings to allow the
connection? I feel better with a firewalled network but if it blocks my VPN,
I will have to disable it and rely 100% on my antivirus.

Any ideas?

thanks everyone,

paulie
Back to top
Merv Porter [SBS-MVP]
Guest





Posted: Tue Jan 18, 2005 8:42 am    Post subject: Re: MS firewall interfering with vpn Reply with quote

Is the "File and Printer Sharing" checked in the Firewall settings on the
desktop running ICS?

Understanding Windows Firewall
http://www.microsoft.com/windowsxp/using/security/internet/sp2_wfexceptions.mspx

--
Merv Porter [SBS MVP]
===================================

"paulie" <paulie@discussions.microsoft.com> wrote in message
news:36274BF4-FF4B-41DC-B61B-91DD714AD6E0@microsoft.com...
Quote:
The settings on the laptop are fine. I know that because i can connect via
a
dial up connection from a hotel. The problem occurs when I use the shared
internet connection on my home nework, which only employs a switch. With
the
firewall on on the desktop that shares the connection to my laptop, I can
connect, but I cannot see shared drives or use printers. With the
firewall
off on the desktop that shares the connection to my laptop, everything
works
just fine. The firewall on the desktop connection is the issue clearly,
right?

thanks for you very quick response.

cheers.

"paulie" wrote:

Hi,

I brought my XP Pro laptop into my home office on which one desktop
computer
shares its cable internet connection via a four port switch. By default
Windows firewalls the LAN Connection on that desktop, which goes to the
cable
modem. With the firewall enabled, I can make a VPN connection to my
server,
however, the laptop insists on working offline. If I simply disable the
firewall on that connection, then the VPN connects well and I am able to
work
online, browser shared drives, and even print to office printers.

Is there any way that I can alter the firewall settings to allow the
connection? I feel better with a firewalled network but if it blocks my
VPN,
I will have to disable it and rely 100% on my antivirus.

Any ideas?

thanks everyone,

paulie
Back to top
Lanwench [MVP - Exchange]
Guest





Posted: Tue Jan 18, 2005 8:45 am    Post subject: Re: MS firewall interfering with vpn Reply with quote

paulie wrote:
Quote:
I will check the IP range. By the way, I have a router but am uable
to use it since the NAT firewall in that router interferes with my
VPN connection in the same way that the Windows XP firewall
interferes with my router. Quite frustrating.

VPN can work behind NAT firewalls just fine.
And re your Windows firewall - it doesn't block any outbound traffic, so I
wonder what else is going on....
Quote:

"Merv Porter [SBS-MVP]" wrote:

Is the IP range of the home office and that of the remote office,
the same? (say, 192.168.0.1 on both)

Opinion... I think you'd be much better off spending $40 on a router
so everyone on the home LAN can have direct Internet access, rather
than using ICS on a desktop to share it out.

--
Merv Porter [SBS MVP]
===================================

"paulie" <paulie@discussions.microsoft.com> wrote in message
news:8AA4C861-49B1-4BDC-9519-4F0C9644BE2A@microsoft.com...
Yes it is checked.

"Merv Porter [SBS-MVP]" wrote:

Is the "File and Printer Sharing" checked in the Firewall settings
on the desktop running ICS?

Understanding Windows Firewall


http://www.microsoft.com/windowsxp/using/security/internet/sp2_wfexceptions.mspx

--
Merv Porter [SBS MVP]
===================================

"paulie" <paulie@discussions.microsoft.com> wrote in message
news:36274BF4-FF4B-41DC-B61B-91DD714AD6E0@microsoft.com...
The settings on the laptop are fine. I know that because i can
connect via a dial up connection from a hotel. The problem
occurs when I use the shared internet connection on my home
nework, which only employs a switch. With the firewall on on the
desktop that shares the connection to my laptop, I can connect,
but I cannot see shared drives or use printers. With the
firewall off on the desktop that shares the connection to my
laptop, everything works just fine. The firewall on the desktop
connection is the issue clearly, right?

thanks for you very quick response.

cheers.

"paulie" wrote:

Hi,

I brought my XP Pro laptop into my home office on which one
desktop computer shares its cable internet connection via a four
port switch. By default Windows firewalls the LAN Connection on
that desktop, which goes to the cable modem. With the firewall
enabled, I can make a VPN connection to my server, however, the
laptop insists on working offline. If I simply disable the
firewall on that connection, then the VPN connects well and I am
able to work online, browser shared drives, and even print to
office printers.

Is there any way that I can alter the firewall settings to allow
the connection? I feel better with a firewalled network but if
it blocks my VPN, I will have to disable it and rely 100% on my
antivirus.

Any ideas?

thanks everyone,

paulie
Back to top
paulie
Guest





Posted: Tue Jan 18, 2005 8:45 am    Post subject: Re: MS firewall interfering with vpn Reply with quote

Yes it is checked.

"Merv Porter [SBS-MVP]" wrote:

Quote:
Is the "File and Printer Sharing" checked in the Firewall settings on the
desktop running ICS?

Understanding Windows Firewall
http://www.microsoft.com/windowsxp/using/security/internet/sp2_wfexceptions.mspx

--
Merv Porter [SBS MVP]
===================================

"paulie" <paulie@discussions.microsoft.com> wrote in message
news:36274BF4-FF4B-41DC-B61B-91DD714AD6E0@microsoft.com...
The settings on the laptop are fine. I know that because i can connect via
a
dial up connection from a hotel. The problem occurs when I use the shared
internet connection on my home nework, which only employs a switch. With
the
firewall on on the desktop that shares the connection to my laptop, I can
connect, but I cannot see shared drives or use printers. With the
firewall
off on the desktop that shares the connection to my laptop, everything
works
just fine. The firewall on the desktop connection is the issue clearly,
right?

thanks for you very quick response.

cheers.

"paulie" wrote:

Hi,

I brought my XP Pro laptop into my home office on which one desktop
computer
shares its cable internet connection via a four port switch. By default
Windows firewalls the LAN Connection on that desktop, which goes to the
cable
modem. With the firewall enabled, I can make a VPN connection to my
server,
however, the laptop insists on working offline. If I simply disable the
firewall on that connection, then the VPN connects well and I am able to
work
online, browser shared drives, and even print to office printers.

Is there any way that I can alter the firewall settings to allow the
connection? I feel better with a firewalled network but if it blocks my
VPN,
I will have to disable it and rely 100% on my antivirus.

Any ideas?

thanks everyone,

paulie


Back to top
Merv Porter [SBS-MVP]
Guest





Posted: Tue Jan 18, 2005 8:45 am    Post subject: Re: MS firewall interfering with vpn Reply with quote

Is the IP range of the home office and that of the remote office, the same?
(say, 192.168.0.1 on both)

Opinion... I think you'd be much better off spending $40 on a router so
everyone on the home LAN can have direct Internet access, rather than using
ICS on a desktop to share it out.

--
Merv Porter [SBS MVP]
===================================

"paulie" <paulie@discussions.microsoft.com> wrote in message
news:8AA4C861-49B1-4BDC-9519-4F0C9644BE2A@microsoft.com...
Quote:
Yes it is checked.

"Merv Porter [SBS-MVP]" wrote:

Is the "File and Printer Sharing" checked in the Firewall settings on
the
desktop running ICS?

Understanding Windows Firewall

http://www.microsoft.com/windowsxp/using/security/internet/sp2_wfexceptions.mspx

--
Merv Porter [SBS MVP]
===================================

"paulie" <paulie@discussions.microsoft.com> wrote in message
news:36274BF4-FF4B-41DC-B61B-91DD714AD6E0@microsoft.com...
The settings on the laptop are fine. I know that because i can connect
via
a
dial up connection from a hotel. The problem occurs when I use the
shared
internet connection on my home nework, which only employs a switch.
With
the
firewall on on the desktop that shares the connection to my laptop, I
can
connect, but I cannot see shared drives or use printers. With the
firewall
off on the desktop that shares the connection to my laptop, everything
works
just fine. The firewall on the desktop connection is the issue
clearly,
right?

thanks for you very quick response.

cheers.

"paulie" wrote:

Hi,

I brought my XP Pro laptop into my home office on which one desktop
computer
shares its cable internet connection via a four port switch. By
default
Windows firewalls the LAN Connection on that desktop, which goes to
the
cable
modem. With the firewall enabled, I can make a VPN connection to my
server,
however, the laptop insists on working offline. If I simply disable
the
firewall on that connection, then the VPN connects well and I am
able to
work
online, browser shared drives, and even print to office printers.

Is there any way that I can alter the firewall settings to allow the
connection? I feel better with a firewalled network but if it blocks
my
VPN,
I will have to disable it and rely 100% on my antivirus.

Any ideas?

thanks everyone,

paulie


Back to top
paulie
Guest





Posted: Tue Jan 18, 2005 8:45 am    Post subject: Re: MS firewall interfering with vpn Reply with quote

I will check the IP range. By the way, I have a router but am uable to use
it since the NAT firewall in that router interferes with my VPN connection in
the same way that the Windows XP firewall interferes with my router. Quite
frustrating.

"Merv Porter [SBS-MVP]" wrote:

Quote:
Is the IP range of the home office and that of the remote office, the same?
(say, 192.168.0.1 on both)

Opinion... I think you'd be much better off spending $40 on a router so
everyone on the home LAN can have direct Internet access, rather than using
ICS on a desktop to share it out.

--
Merv Porter [SBS MVP]
===================================

"paulie" <paulie@discussions.microsoft.com> wrote in message
news:8AA4C861-49B1-4BDC-9519-4F0C9644BE2A@microsoft.com...
Yes it is checked.

"Merv Porter [SBS-MVP]" wrote:

Is the "File and Printer Sharing" checked in the Firewall settings on
the
desktop running ICS?

Understanding Windows Firewall

http://www.microsoft.com/windowsxp/using/security/internet/sp2_wfexceptions.mspx

--
Merv Porter [SBS MVP]
===================================

"paulie" <paulie@discussions.microsoft.com> wrote in message
news:36274BF4-FF4B-41DC-B61B-91DD714AD6E0@microsoft.com...
The settings on the laptop are fine. I know that because i can connect
via
a
dial up connection from a hotel. The problem occurs when I use the
shared
internet connection on my home nework, which only employs a switch.
With
the
firewall on on the desktop that shares the connection to my laptop, I
can
connect, but I cannot see shared drives or use printers. With the
firewall
off on the desktop that shares the connection to my laptop, everything
works
just fine. The firewall on the desktop connection is the issue
clearly,
right?

thanks for you very quick response.

cheers.

"paulie" wrote:

Hi,

I brought my XP Pro laptop into my home office on which one desktop
computer
shares its cable internet connection via a four port switch. By
default
Windows firewalls the LAN Connection on that desktop, which goes to
the
cable
modem. With the firewall enabled, I can make a VPN connection to my
server,
however, the laptop insists on working offline. If I simply disable
the
firewall on that connection, then the VPN connects well and I am
able to
work
online, browser shared drives, and even print to office printers.

Is there any way that I can alter the firewall settings to allow the
connection? I feel better with a firewalled network but if it blocks
my
VPN,
I will have to disable it and rely 100% on my antivirus.

Any ideas?

thanks everyone,

paulie





Back to top
Merv Porter [SBS-MVP]
Guest





Posted: Tue Jan 18, 2005 5:50 pm    Post subject: Re: MS firewall interfering with vpn Reply with quote

Which router do you have?

--
Merv Porter [SBS MVP]
===================================
"paulie" <paulie@discussions.microsoft.com> wrote in message
news:C29249A4-C976-4E58-9FF8-C3A94439C995@microsoft.com...
Quote:
I will check the IP range. By the way, I have a router but am uable to
use
it since the NAT firewall in that router interferes with my VPN connection
in
the same way that the Windows XP firewall interferes with my router.
Quite
frustrating.

"Merv Porter [SBS-MVP]" wrote:

Is the IP range of the home office and that of the remote office, the
same?
(say, 192.168.0.1 on both)

Opinion... I think you'd be much better off spending $40 on a router so
everyone on the home LAN can have direct Internet access, rather than
using
ICS on a desktop to share it out.

--
Merv Porter [SBS MVP]
===================================

"paulie" <paulie@discussions.microsoft.com> wrote in message
news:8AA4C861-49B1-4BDC-9519-4F0C9644BE2A@microsoft.com...
Yes it is checked.

"Merv Porter [SBS-MVP]" wrote:

Is the "File and Printer Sharing" checked in the Firewall settings
on
the
desktop running ICS?

Understanding Windows Firewall


http://www.microsoft.com/windowsxp/using/security/internet/sp2_wfexceptions.mspx

--
Merv Porter [SBS MVP]
===================================

"paulie" <paulie@discussions.microsoft.com> wrote in message
news:36274BF4-FF4B-41DC-B61B-91DD714AD6E0@microsoft.com...
The settings on the laptop are fine. I know that because i can
connect
via
a
dial up connection from a hotel. The problem occurs when I use
the
shared
internet connection on my home nework, which only employs a
switch.
With
the
firewall on on the desktop that shares the connection to my
laptop, I
can
connect, but I cannot see shared drives or use printers. With the
firewall
off on the desktop that shares the connection to my laptop,
everything
works
just fine. The firewall on the desktop connection is the issue
clearly,
right?

thanks for you very quick response.

cheers.

"paulie" wrote:

Hi,

I brought my XP Pro laptop into my home office on which one
desktop
computer
shares its cable internet connection via a four port switch. By
default
Windows firewalls the LAN Connection on that desktop, which goes
to
the
cable
modem. With the firewall enabled, I can make a VPN connection
to my
server,
however, the laptop insists on working offline. If I simply
disable
the
firewall on that connection, then the VPN connects well and I am
able to
work
online, browser shared drives, and even print to office
printers.

Is there any way that I can alter the firewall settings to allow
the
connection? I feel better with a firewalled network but if it
blocks
my
VPN,
I will have to disable it and rely 100% on my antivirus.

Any ideas?

thanks everyone,

paulie





Back to top
paulie
Guest





Posted: Tue Jan 18, 2005 8:01 pm    Post subject: Re: MS firewall interfering with vpn Reply with quote

It is a linksys BEFW11S4 v. 2

"Merv Porter [SBS-MVP]" wrote:

Quote:
Which router do you have?

--
Merv Porter [SBS MVP]
===================================
"paulie" <paulie@discussions.microsoft.com> wrote in message
news:C29249A4-C976-4E58-9FF8-C3A94439C995@microsoft.com...
I will check the IP range. By the way, I have a router but am uable to
use
it since the NAT firewall in that router interferes with my VPN connection
in
the same way that the Windows XP firewall interferes with my router.
Quite
frustrating.

"Merv Porter [SBS-MVP]" wrote:

Is the IP range of the home office and that of the remote office, the
same?
(say, 192.168.0.1 on both)

Opinion... I think you'd be much better off spending $40 on a router so
everyone on the home LAN can have direct Internet access, rather than
using
ICS on a desktop to share it out.

--
Merv Porter [SBS MVP]
===================================

"paulie" <paulie@discussions.microsoft.com> wrote in message
news:8AA4C861-49B1-4BDC-9519-4F0C9644BE2A@microsoft.com...
Yes it is checked.

"Merv Porter [SBS-MVP]" wrote:

Is the "File and Printer Sharing" checked in the Firewall settings
on
the
desktop running ICS?

Understanding Windows Firewall


http://www.microsoft.com/windowsxp/using/security/internet/sp2_wfexceptions.mspx

--
Merv Porter [SBS MVP]
===================================

"paulie" <paulie@discussions.microsoft.com> wrote in message
news:36274BF4-FF4B-41DC-B61B-91DD714AD6E0@microsoft.com...
The settings on the laptop are fine. I know that because i can
connect
via
a
dial up connection from a hotel. The problem occurs when I use
the
shared
internet connection on my home nework, which only employs a
switch.
With
the
firewall on on the desktop that shares the connection to my
laptop, I
can
connect, but I cannot see shared drives or use printers. With the
firewall
off on the desktop that shares the connection to my laptop,
everything
works
just fine. The firewall on the desktop connection is the issue
clearly,
right?

thanks for you very quick response.

cheers.

"paulie" wrote:

Hi,

I brought my XP Pro laptop into my home office on which one
desktop
computer
shares its cable internet connection via a four port switch. By
default
Windows firewalls the LAN Connection on that desktop, which goes
to
the
cable
modem. With the firewall enabled, I can make a VPN connection
to my
server,
however, the laptop insists on working offline. If I simply
disable
the
firewall on that connection, then the VPN connects well and I am
able to
work
online, browser shared drives, and even print to office
printers.

Is there any way that I can alter the firewall settings to allow
the
connection? I feel better with a firewalled network but if it
blocks
my
VPN,
I will have to disable it and rely 100% on my antivirus.

Any ideas?

thanks everyone,

paulie








Back to top
Joe
Guest





Posted: Wed Jan 19, 2005 1:55 am    Post subject: Re: MS firewall interfering with vpn Reply with quote

In message <C29249A4-C976-4E58-9FF8-C3A94439C995@microsoft.com>, paulie
<paulie@discussions.microsoft.com> writes
Quote:
I will check the IP range. By the way, I have a router but am uable to use
it since the NAT firewall in that router interferes with my VPN connection in
the same way that the Windows XP firewall interferes with my router. Quite
frustrating.

It's not the NAT that's doing it. I use a PPTP VPN client through two

levels of NAT at my end, one in the router and another in a firewall PC.
Neither stage needs to be configured to allow this.
--
Joe
Back to top
 
Post new topic   Reply to topic    Windows Server Forum Index -> Small Business Server 2003 All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




New Topics Powered by phpBB