image: import a file screenshot
When moving to a new PC you can import existing Outlook messages using the tools provided in the client application
R E L A T E D   C O N T E N T
ADVERTISEMENT

Hands on: Troubleshooting remote access

How to solve problems with VPNs, and a round-up of power line networking tools

Alan Stevens, Personal Computer World 24 Jul 2007
ADVERTISEMENT

Remote Lan access can be tricky to get right, so I thought I’d share one problem I came across recently which could cause a lot of head scratching, especially if you’re not familiar with networks and addressing schemes.

It involved a company wanting to enable staff to work from home, using a very simple virtual private network (VPN) solution. To this end the company had purchased and installed a Draytek ADSL router with a built-in VPN server.

Like others, the Draytek router supports a variety of tunnelling protocols, but to keep things as simple as possible the company had opted for a basic PPTP (Point to Point Tunnelling Protocol) implementation. Not the most secure, admittedly, but easy to set up and it was working well with several users configured on the router, connecting from home using the client software in Windows XP.

Another benefit was the ease with which new users could be added, with the network administrator simply creating a new account on the router then talking the user through the configuration work required to connect on their home PC or laptop.

One new user, however, couldn’t get it to work, so I was asked to investigate. She confirmed that she had internet access and had configured a VPN connection in Windows XP, using the same parameters as everyone else. On the face of it, all seemed to be working correctly. Windows XP was reporting a successful connection when she selected the icon on her desktop, but she couldn’t see her files on the company server. Neither was she able to work on her email held in an Imap folder on the office mail server.

Naturally, we went through all the settings again, but found everything as it should be. We made sure the VPN server was up and working and that a suitable account had been configured on the router to enable her to connect remotely. Again, everything was in order and, when we checked the active connections, the router reported her as successfully attached using a PPTP tunnel.

I started to suspect it was the way the home network was configured, and that’s when we discovered the true cause of the problem.

Like a lot of small companies, the office network involved was protected using Network Address Translation (Nat) on the router with a single local subnet in the 192.168.0.0 range. VPN users were set up to be assigned an IP address between 192.168.0.50 and 192.168.0.100 using the host DHCP server, also provided by the router. Unfortunately, the router on the home network was also Nat protected and configured to use the same 192.168.0.0 subnet internally.

This didn’t stop the tunnel being successfully established. However, because the subnets were the same at each end, the Windows PC on the home network was unable to distinguish between packets that needed to be sent down the tunnel to the remote Lan and those addressed to other devices on the local network.

There were several ways in which we could have solved this, including switching to a more complex IPSec VPN or tweaking routing tables. However, to minimise the amount of work involved, we felt it better to change either the subnet on the office network or the user’s home router.

Changing the office network would also have involved a fair amount of work because of the servers and several network printers with fixed addresses. So, at the risk of encountering the problem again, we opted to change the user’s home router to use the 192.168.1.0 subnet and assign addresses in that range to her PC and any others she might connect to the Lan.

The only slight hiccup was that she couldn’t remember the router password. It turned out to be the default for the model involved, so it didn’t hold us up for long. And, of course, once we’d made the change and confirmed that she had VPN access I made sure we also changed the administrator password to something less obvious.


All Online
Tags: Networks

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S
M A R K E T P L A C E
Get your free demo of Numara Track-It! 8 - the leading help desk solution for IT related issues.
Make presentations, review documents & share your entire desktop. 30-day free trial! (cc required).
Discover how remote support can fuel your IT business in ways you've never thought of before.
Apply ITIL best practices at your service desk while eliminating integration cost. Learn more here.
WAN based, automated, daily vulnerability assessments. Click here to try and request our whitepapers.
Have your product or service listed here >   
Sponsored links
F E A T U R E D   J O B S
London, Waterloo, United Kingdom | Christian Aid
Senior Web Designer, £37,526 - £42,257 per annum, London, Waterloo The Senior Web Designer is a crucial post in the Publishing Team and provides creative design and graphic resource for all Christian Aid's websites, with ... more >
Buckinghamshire, United Kingdom | Grass Roots
Tester, Aylesbury, Buckinghamshire, Excellent Salary + Benefits Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the Grass Roots Group, which ... more >
South West, Darlington, United Kingdom | University College Falmouth
  Web Sharepoint Development Manager, £23,692-£26,665 (£29,138) per annum (Grade 5) The creation of a new University for the Arts in the South West has taken a major step forward with the merger of University ... more >
Leeds, United Kingdom | UKCRN
Application Developer (Role 2), Leeds Join us, and you'll work within a project team to design, develop, test and deliver web applications using ASP.NET 1.x , 2.0 and/or 3.x  (VB.NET and /or C#), HTML and ... more >
More job opportunities