Geekzone: technology news, blogs, forums
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.

132 posts

Master Geek
+1 received by user: 8

# 208920 5-Mar-2017 13:23
Send private message





We have demoted an SBS server and built a new 2016 VM as the new DC. The SBS box (physical) still has the RRAS role installed and it is working fine for VPN clients. We are looking to blow away the SBS box of course and repurpose it as a backup server. To that end we want the new server to handle VPNs, Anyway I have installed the RRAS role on the new VM and it seems to be running. It will not accept connections though. Internal DNS has been changed to reflect the new server and connecting to the PPTP VPN internally works straight away as you would expect. There have been no changes made to the Mikrotik routerfirewall, as I said if I re-enable the service on the old server it works OK. Windows firewall is off. Any NAT rule on the firewall just points to the site network. Flat, no VLANs, 1 subnet. There is no specific entry on the Mikrotik that I can see, but maybe I have missed something. It can't be external DNS because there is nothing different there.





Create new topic
783 posts

Ultimate Geek
+1 received by user: 343


  # 1730410 5-Mar-2017 15:19
Send private message

"Any NAT rule on the firewall just points to the site network"


Surely the gre and tcp ports would need to be mapped on the nat device to the specific ip address of the new pptp server?


Or is the VM on the same IP address as the old pptp server? If so check the local firewall on the VM as if it's on the domain profile for example it will accept connections when you are testing on the local LAN, but not from the internet.





132 posts

Master Geek
+1 received by user: 8

  # 1730427 5-Mar-2017 15:52
Send private message

Thanks, I can't see anywhere on the Mikrotik to change that. Under service ports pptp is blank and no gre entry at all. There are entries for 1723 in the NAT translation table tho


3982 posts

Uber Geek
+1 received by user: 1687


  # 1730433 5-Mar-2017 16:01
Send private message

On the Mikrotik you will want a dstnat rule forwarding tcp 1723, and another rule forwarding GRE to your server IP too.
Unless the new server has the same IP as the old server they won't be heading to the right place at the moment which seems consistent with what you are saying that connecting to the old server works.

132 posts

Master Geek
+1 received by user: 8

  # 1730473 5-Mar-2017 17:24
Send private message

Yes, thanks for the input lads. I found about 20 static NAT rules all pointing to the old IP. Pretty noob omission in the end.





1508 posts

Uber Geek
+1 received by user: 213

  # 1732845 8-Mar-2017 09:08
Send private message

If you are not using 443 (https) inbound already, you could also take advantage of a more modern VPN and set up SSLVpn instead of pptp. It is more secure and doesn't require as many firewall ports opened up. It is also usable from some networks where they heavily block outbound ports except for http and https.

Try Vultr using this link and get us both some credit:

Create new topic

Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:

Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:

Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:

News »

Video game market in New Zealand passes half billion dollar mark
Posted 24-May-2019 16:15

WLG-X festival to celebrate creativity and innovation
Posted 22-May-2019 17:53

HPE to acquire supercomputing leader Cray
Posted 20-May-2019 11:07

Techweek starting around NZ today
Posted 20-May-2019 09:52

Porirua City Council first to adopt new council software solution Datascape
Posted 15-May-2019 12:00

New survey provides insight into schools' technology challenges and plans
Posted 15-May-2019 09:30

Apple Music now available on Alexa devices in Australia and New Zealand
Posted 15-May-2019 09:11

Make a stand against cyberbullying this Pink Shirt Day
Posted 14-May-2019 20:23

Samsung first TV manufacturer to launch the Apple TV App and Airplay 2
Posted 14-May-2019 20:11

Vodafone New Zealand sold
Posted 14-May-2019 07:25

Kordia boosts cloud performance with locally-hosted Microsoft Azure ExpressRoute
Posted 8-May-2019 10:25

Microsoft Azure ExpressRoute in New Zealand opens up faster, more secure internet for Kiwi businesses
Posted 8-May-2019 09:39

Vocus Communications to deliver Microsoft Azure Cloud Solutions through Azure ExpressRoute
Posted 8-May-2019 09:25

Independent NZ feature film #statusPending to premiere during WLG-X
Posted 6-May-2019 22:13

The ultimate dog photoshoot with Nokia 9 PureView #ForgottenDogsofInstagram
Posted 6-May-2019 09:41

Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.