Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


tatbaird

142 posts

Master Geek


#208920 5-Mar-2017 13:23
Send private message

Hi,

 

 

 

We have demoted an SBS server and built a new 2016 VM as the new DC. The SBS box (physical) still has the RRAS role installed and it is working fine for VPN clients. We are looking to blow away the SBS box of course and repurpose it as a backup server. To that end we want the new server to handle VPNs, Anyway I have installed the RRAS role on the new VM and it seems to be running. It will not accept connections though. Internal DNS has been changed to reflect the new server and connecting to the PPTP VPN internally works straight away as you would expect. There have been no changes made to the Mikrotik routerfirewall, as I said if I re-enable the service on the old server it works OK. Windows firewall is off. Any NAT rule on the firewall just points to the site network. Flat, no VLANs, 1 subnet. There is no specific entry on the Mikrotik that I can see, but maybe I have missed something. It can't be external DNS because there is nothing different there.

 

 

 

Cheers


Create new topic
gbwelly
1243 posts

Uber Geek


  #1730410 5-Mar-2017 15:19
Send private message

"Any NAT rule on the firewall just points to the site network"

 

Surely the gre and tcp ports would need to be mapped on the nat device to the specific ip address of the new pptp server?

 

Or is the VM on the same IP address as the old pptp server? If so check the local firewall on the VM as if it's on the domain profile for example it will accept connections when you are testing on the local LAN, but not from the internet.

 

 

 

 










tatbaird

142 posts

Master Geek


  #1730427 5-Mar-2017 15:52
Send private message

Thanks, I can't see anywhere on the Mikrotik to change that. Under service ports pptp is blank and no gre entry at all. There are entries for 1723 in the NAT translation table tho


chevrolux
4962 posts

Uber Geek
Inactive user


  #1730433 5-Mar-2017 16:01
Send private message

On the Mikrotik you will want a dstnat rule forwarding tcp 1723, and another rule forwarding GRE to your server IP too.
Unless the new server has the same IP as the old server they won't be heading to the right place at the moment which seems consistent with what you are saying that connecting to the old server works.



tatbaird

142 posts

Master Geek


  #1730473 5-Mar-2017 17:24
Send private message

Yes, thanks for the input lads. I found about 20 static NAT rules all pointing to the old IP. Pretty noob omission in the end.

 

 

 

Thanks


toyonut
1508 posts

Uber Geek


  #1732845 8-Mar-2017 09:08
Send private message

If you are not using 443 (https) inbound already, you could also take advantage of a more modern VPN and set up SSLVpn instead of pptp. It is more secure and doesn't require as many firewall ports opened up. It is also usable from some networks where they heavily block outbound ports except for http and https.





Try Vultr using this link and get us both some credit:

 

http://www.vultr.com/?ref=7033587-3B


Create new topic





News and reviews »

Gen Threat Report Reveals Rise in Crypto, Sextortion and Tech Support Scams
Posted 7-Aug-2025 13:09


Logitech G and McLaren Racing Sign New, Expanded Multi-Year Partnership
Posted 7-Aug-2025 13:00


A Third of New Zealanders Fall for Online Scams Says Trend Micro
Posted 7-Aug-2025 12:43


OPPO Releases Its Most Stylish and Compact Smartwatch Yet, the Watch X2 Mini.
Posted 7-Aug-2025 12:37


Epson Launches New High-End EH-LS9000B Home Theatre Laser Projector
Posted 7-Aug-2025 12:34


Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.