Announcement

Collapse
No announcement yet.

Firewall Port for SBS 2008 for VPN

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Firewall Port for SBS 2008 for VPN

    I opened ports: 25, 80, 444, 4125, 443, 1723, 3389 on the router and forword them to the server (SBS 200

    I enabled the VPN connection on the server, but still can't connect to it by VPN.

    When I am running the wizard on the SBS I am getting error that the SBS can't open ports on the router.

    Any idea why the VPN doesn't work.

    I can RDP the server and the OWA is working fine, I can use the Remote desktop but only the VPN doesn't work.

    I enabled the uPNP on the router too.

    Did I miss any ports on the firewall?

  • #2
    Re: Firewall Port for SBS 2008 for VPN

    I would turn off UPnP, it's a glaring security hole and although I can why some people like it, particularly for home use, there's no way I'd allow a UPnP enabled device at the edge of my network.

    What kind of VPN are you trying? I assume PPTP given that you've opened port 1723. Does the router support VPN forwarding/passthrough and have it enabled? GRE packets are also required for PPTP VPNs and there is no way to forward this traffic unless your router supports VPN passthrough.
    BSc, MCSA: Server 2008, MCSE, MCSA: Messaging, MCTS
    sigpic
    Cruachan's Blog

    Comment


    • #3
      Re: Firewall Port for SBS 2008 for VPN

      The router is ZyXEL P-660HW-T1 v2

      I disabled the UPnP on the router.

      How do I know if the router support VPN forwarding/passthrough?

      and Where to enable it?

      Comment


      • #4
        Re: Firewall Port for SBS 2008 for VPN

        User Guide.
        BSc, MCSA: Server 2008, MCSE, MCSA: Messaging, MCTS
        sigpic
        Cruachan's Blog

        Comment


        • #5
          Re: Firewall Port for SBS 2008 for VPN

          are GRE packets using only port UDP 500?

          I added that too but still can't VPN the server.

          anyone?

          Comment


          • #6
            Re: Firewall Port for SBS 2008 for VPN

            What error do you get when you try to VPN? Have you tried a VPN from inside the network to make sure the server si configured correctly?

            GRE is a protocol rather than something coming through specific ports, so it's not really a case of opening ports for it, hence the VPN passthrough option on most routers. More details here.
            BSc, MCSA: Server 2008, MCSE, MCSA: Messaging, MCTS
            sigpic
            Cruachan's Blog

            Comment


            • #7
              Re: Firewall Port for SBS 2008 for VPN

              OK I managed to fix it.
              I talked with Zyxel and on the firewall i had to open the PPTP_TUNNEL too.

              Don't need to forward it, just open it on the firewall to the server and it working fine now.

              Thanks all for your help and fast respond.

              Regards,

              Kobi

              Comment


              • #8
                Re: Firewall Port for SBS 2008 for VPN

                No probs, glad you got it working.
                BSc, MCSA: Server 2008, MCSE, MCSA: Messaging, MCTS
                sigpic
                Cruachan's Blog

                Comment


                • #9
                  Re: Firewall Port for SBS 2008 for VPN

                  Note: the port for RWW in SBS 2008 is no longer 4125, but 987. See http://www.nogeekleftbehind.com/2009/08/28/sbs-ports/ from my friend Tim Barrett to see a full explanation on ports needed.
                  TIA

                  Steven Teiger [SBS-MVP(2003-2009)]
                  http://www.wintra.co.il/
                  sigpic
                  Iím honoured to have been selected for the SMB 150 list for 2013. This is the third time in succession (no logo available for 2011) that I have been honoured with this award.

                  We donít stop playing because we grow old, we grow old because we stop playing.

                  Comment

                  Working...
                  X