VPN behind NAT

Forum for all technical support and trouble shooting of the WinGate VPN.

Moderator: Qbik Staff

VPN behind NAT

Postby Kempston » Jan 25 04 12:58 pm

Subj says it's all. I`m trying to Connect to computers behind NAT, and so far, VPN seems the only solution (i'm aware about).
Fist i've tried to Setup Microsoft VPN, and was constantly getting error 721 on VPN clients while trying to establish VPN connection. Alot of people told me, that it`s coused by inproperly configured NAT server, uncapable to translate GRE packets. Well, bad router might be a good reason not to establish VPN connection for Microsoft but it`s not good enought for me, so i started looking for other VPN solutions. So far the only "working" solution i'm aware is WinGate VPN.
I`ve installed server on pc with real ip and client on pc using NAT. Unlike Microsoft, WinGate Client have immideatly established VPN connection, but unfortunatly that didn`t bring expected effect.

1. When establishing tunnel beetween two computers with real ip - everything works fine.

2. When establishing tunnel from pc behind NAT to pc with real ip - i can sometimes ping private interfaces of public machine, but never can ping interfaces of NAT machine.

3. When establishing tunnel from pc behind NAT to pc with private ip (i.e. from 192.168.230.130 to 192.168.0.1) nothing is pingable AT ALL.

4. Getting up dialup internet connection on 192.168.0.1 machine. When establishing tunnel from pc behind NAT to pc with private ip (i.e. from 192.168.230.130 to 192.168.0.1) - everything works fine.

5. Getting up dialup internet connection on 192.168.0.1 machine. When establishing same tunnel as case 4 (from pc behind NAT to pc with private ip) but instead of 192.168.0.1 specify it`s public ip (213.130.7.6) - nothing is pingable AT ALL.

Real mess isn`t it ? Looks to me like it's a routing issue. I've tried to play with route delete/add/change, but it didn`t get any positive effect.

Basicly i only need to get configuration 2 working - others were tested just for debugging issues.

I've read few posts on this forum and have noticed that some people are having similiar issues. Unfortunatly even on forum i wasn't able to find any solution, so i was wonering if i should wait for stable release of wingate VPN or maybe someone here have new version of hands.sys for me ?
Kempston
 
Posts: 2
Joined: Jan 25 04 11:50 am

Postby MattP » Jan 28 04 5:53 pm

Have you installed WinGate server or just the WinGate VPN? Are you using the WinGate VPN on each end of your connection? If you are then you shouldn't have any problems connecting the two subnets.

If your WinGate server is the host and also the gateway for your LAN then you simply export the VPN configuration file and import it into the VPN joiner (your remote client) and connect. Now you should be able to browse the LAN.

Can you tell us a bit more about your setup?

Thanks,
MattP
Qbik Staff
 
Posts: 991
Joined: Sep 08 03 4:30 pm

Postby Kempston » Jan 28 04 7:31 pm

Well, in all mentioned cases i was using WinGate VPN Server on one pc and WinGate VPN Server on another. I wouldn't expect to see anything working without that, and as i said before in all those cases i get VPN connection established fine, and when i say VPN connection, i mean WinGate VPN connection, not anything else.

Here is Configuration of my network used in tests

1. My PC - two interfaces, one (dialup modem) looks into internet (it's ip will be mentioned below ip as filetest.mine.nu), another - into local network (192.168.0.1). PC has enabled NAT on it

2. 2nd PC - two interfaces, one is physical (192.168.0.10), andother is virtual (VMware) 192.168.230.128, this PC is using 192.168.0.1 as default gateway

3. Virtual NAT router (VMware launched on PC 2) is on ip 192.168.230.2.

4. Virtual Machine (VMware launched on PC 2) - one interface 192.168.230.130, this PC is using 192.168.230.2 as default gateway.

Thnx to mentioned 2 NAT servers, on PC4 i can ping PC1 and internet.
On default PC1 can NOT see PC4, but with help of WinGate VPN i can get PC4 pingable from PC1, but only when dialup connection to internet is established on PC1, even if i`m using 192.168.0.1 when pointing VPN client to VPN server. And when i use filetest.mine.nu instead of 192.168.0.1 as adress of VPN server, after establishing VPN connection PC1 and PC4 cannot see each other AT ALL.
Kempston
 
Posts: 2
Joined: Jan 25 04 11:50 am


Return to WinGate VPN

Who is online

Users browsing this forum: No registered users and 15 guests

cron