Jump to content

Recommended Posts

Posted

Hi,

 

I'm trying to setup VPN on Windows 2016 to allow users to connect remotely (via VPN).

 

I have installed RRAS role and configured it for L2TP/IPSec as per guidance online and a rule has been setup on the firewall to forward the traffic to the server (SNAT).

 

On testing, it works internally (internal client Win10 and Win2012 R2), but we can't connect in remotely (from home).

 

The firewall rule is identical to another rule we have to pass through L2TP/IPSec to another server (Mac), so by that logic the rule should be OK.

 

Also, we have an inline Smoothwall proxy between the firewall and the rest of the network (the VPN server).

 

Does anyone have any ideas what the issue could be?

 

Kind Regards,

 

Bruce.

Posted (edited)

Do you need a NAT rule by any chance? Does your external IP address of the Smoothwall have a public IP and the Internal server has a private IP (RFC 1918) you will need one.

 

NAT rules are often overlooked, I know I have forgotten to do them on the odd occasion when I've needed to. There should be existing NAT rules I'd of thought. Follow the same principle, I don't have a Smoothwall though.

 

edit: OK so re-reading your post you have indicated that you have setup SNAT on the firewall, my mistake.

 

How are you accessing the VPN externally. Is it via FQDN or IP address. Does the FQDN resolve externally?

 

Have you spoken to Smoothwall support at all?

Edited by Davit2005
Posted
Do you need a NAT rule by any chance?

 

Not on the Windows 2016 server I wouldn't have thought? When I installed RRAS I didn't tick NAT.

 

Does your external IP address of the Smoothwall have a public IP and the Internal server has a private IP (RFC 1918) you will need one.

 

The SM only has private address(es) [RFC1918] as we have public IP addresses on the Firewall [Watchguard]

 

NAT rules are often overlooked, I know I have forgotten to do them on the odd occasion when I've needed to. There should be existing NAT rules I'd of thought. Follow the same principle, I don't have a Smoothwall though.

 

edit: OK so re-reading your post you have indicated that you have setup SNAT on the firewall, my mistake.

 

How are you accessing the VPN externally. Is it via FQDN or IP address. Does the FQDN resolve externally?

 

I'm just using the IP public at the moment.

 

But when testing internally we used its internal IP.

 

Have you spoken to Smoothwall support at all?

 

Not yet, but I don't know if SM is the issue. Certainly, outbound SM just passes through any non-web (80/443) traffic to the firewall, so I am hoping that inbound it will do the same.

 

I am considering SSTP (whatever it's call VLAN over SSL) instead as it just uses 80/442, but want to try getting L2TP/IPSec working first...

 

Thanks,

 

Bruce.

Posted

The reason I use RRAS instead of the Smoothwall VPN solution is twofold:

1) This is what Always On VPN uses in the background

2) Even if that wasn’t true, the appropriate client is built into Windows so no further software installations are required

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...