Re: VPN almost working - have TCP/IP, but no file shares



In article <MPG.1d8a27da6b9b78569896c0@xxxxxxxxxxxxxxxxx>,
chris@xxxxxxxxxxx says...
> I've got a Linksys BEFVP41 VPN box at home, and am running SafeNet
> SoftRemote on my laptop. The home network behind the VPN has a couple
> of printers, a Tivo running TivoWeb, and a Linux file server running
> Samba. The Linux box is also the WINS server for the home network.
>
> I've finally gotten TCP/IP connectivity to work beautifully - sitting at
> a coffee shop I'm able to ping everything, scan & print to the HP
> multifunction printer, use VNC to connect to the Linux desktop and see
> what the Tivo recorded last night (more "Mythbusters", hooray! :-)
>
> What I CAN'T do, though, is access any of the file shares on the Linux
> box - NET VIEW says there are no entries in the list, NET VIEW
> \\SERVERXYZ comes up with error 53 "network path was not found". This
> works fine at home, it's just failing on the VPN.
>
> On the laptop, I've tried disabling ZoneAlarm (didn't work) and added
> the server to the LMHOSTS file (also didn't work, but I didn't reboot
> ... HOSTS doesn't require it, didn't know if LMHOSTS did or not).
>
> On the laptop within SoftRemote I've tried requiring the virtual
> adapter. Not only did that not work, it also caused all other TCP/IP
> traffic to the home VPN to fail - seems it was giving me my requested
> local address but with a mask of 255.255.255.255 so I could only talk to
> myself.
>
> On the Linksys general filters page, the "Block WAN Request", "Multicast
> Pass Through", "IPSec Pass Through" and "PPTP Pass Through" settings are
> all enabled. Ports 137-139 are UDP filtered (disabling the filtering
> doesn't seem to help). On the specific VPN settings, NetBIOS broadcast
> is enabled.

It's all in the timing ... I tried all the right things, just not at the
same time. ;-)

The solution (for anyone else who might be having this problem) was:

1) Added LMHOSTS file on the remote laptop that points back to the file
server.

2) Corrected permissions in Zone Alarm. Apparently, even when ZA is set
to trust the network (which I wouldn't recommend in a coffee shop!) it
was still blocking the NETBIOS traffic. I was able to defeat this by
defining an expert rule allowing all traffic to the 192.168.1.0 subnet
from any source. Even with the network set back to internet zone,
sharing is working with this rule in effect.

Network shares are working by IP or by name. One thing that ISN'T
working is browsing (i.e. "NET VIEW" says "list of servers for this
workgroup isn't currently available") so I suspect I've still got WINS
or master browser issues to resolve. But "NET VIEW \\servername" does
work, and I can live with that until I resolve the other issues.

-- Chris
________*________ Chris Barnabo, chris@xxxxxxxxxxx
____________ \_______________/ http://www.spagnet.com
\__________/ / /
__\ \_______/ /__ "The heck with the Prime Directive,
\_______________/(- let's destroy something!"
.



Relevant Pages

  • Re: [Full-disclosure] Remote Desktop Command Fixation Attacks
    ... This set of steps is redundant in many places, and it's also enormously expensive, since you're using no less than three different expensive bits of networking hardware (AP, PIX, VPN Concentrator), in addition to a bunch of x86 server hardware, windows server licenses, and at least one ISA license. ... Your computers necessarily don't have full access to your network infrastructure when they aren't logged on, so GPOs, software updates, etc can't be applied at the times you want them to be applied. ... Turning on, enabling, and implementing every possible security setting and device you think of is not defence in depth, and will probably only have two effects - your users won't use your wireless network, and you'll burn so much cash you won't have any left to spend on *useful* security measures. ...
    (Full-Disclosure)
  • Re: VPN with SBS 2003 (not R2) and DSL.
    ... Reading property value for VPN returned OK ... Reading VPN Server Name returned OK ... identical network cards. ... it seems doubtful that SBS will work properly with two NICs ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN Connection Problems
    ... Note that we are able to successfully VPN into the office. ... to browse the network, RDP to the server or even ping the server. ... > This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN clients unable to connect to other resources.
    ... on the SBS 2003 server just not sure where to go for help on it. ... Next time I'm at my home PC, I'll VPN in and see what IP info I'm getting ... client PC on your LAN, you should be able to do so from a remote VPN client, ... get the network path was not found. ...
    (microsoft.public.windows.server.sbs)
  • Re: RRAS as VPN Server Configuration Questions...
    ... Ethernet adapter VPN: ... Name resulotion on VPN Connection issues on DC, ISA, DNS and WINS server as ... Issue in a VPN client ... ... How to Setup Windows, Network, VPN & Remote Access on ...
    (microsoft.public.win2000.ras_routing)