<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>PPTP/L2TP ports to forward in Virtual Private Networking</title>
<link>http://www.dslreports.com/forum/r20970761</link>
<description></description>
<language>en</language>
<pubDate>Wed, 11 Nov 2009 12:13:55 EDT</pubDate>
<lastBuildDate>Wed, 11 Nov 2009 12:13:55 EDT</lastBuildDate>

<item>
<title>Re: PPTP/L2TP ports to forward</title>
<link>http://www.dslreports.com/forum/remark,21029489</link>
<description><![CDATA[<A HREF="/useremail/u/843138"><b>Matt</b></A> : <div class="bquote"><small>said by  tiger9 <A HREF="/useremail/u/1241546"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Really?  I thought I could just forward IP/50 [ESP] on to the server.  Thanks, though.<br><br>EDIT - Isn't IPSec ESP compatible with NAT?   I know that IPSec AH [51] isn't, but my sources say that ESP is OK with it.<br> </div>Microsoft doesn't recommend IPSec NAT-T (UDP 4500) for a VPN server behind NAT: &raquo;<A HREF="http://support.microsoft.com/kb/885348" >support.microsoft.com/kb/885348</A><br><br>You're likely to experience problems with clients behind NAT with IPSec/L2TP if you can't enable it though.<br><small>--<br><A HREF="http://linuxhaters.blogspot.com/">Linux Haters Unite!</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21029489</guid>
<pubDate>Fri, 29 Aug 2008 22:16:14 EDT</pubDate>
</item>

<item>
<title>Re: PPTP/L2TP ports to forward</title>
<link>http://www.dslreports.com/forum/remark,20973202</link>
<description><![CDATA[<A HREF="/useremail/u/1241546"><b>tiger9</b></A> : Really?  I thought I could just forward IP/50 [ESP] on to the server.  Thanks, though.<br><br>EDIT - Isn't IPSec ESP compatible with NAT?   I know that IPSec AH [51] isn't, but my sources say that ESP is OK with it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20973202</guid>
<pubDate>Tue, 19 Aug 2008 09:42:20 EDT</pubDate>
</item>

<item>
<title>Re: PPTP/L2TP ports to forward</title>
<link>http://www.dslreports.com/forum/remark,20972643</link>
<description><![CDATA[<A HREF="/useremail/u/731304"><b>rjs1003</b></A> : Your PPTP port/protocol combination is correct.<br><br>For L2TP/IPSec... well, if you didn't have NAT involved you'd be correct, but the mode of IPSec used by L2TP/IPSec connections doesn't work naturally through NAT, so Microsoft use NAT-Traversal (NAT-T) which puts the ESP packet inside another UDP packet, and usually transmits this on port 4500.<br>So in other words, for L2TP/IPSec you probably just want UDP ports 500 and 4500.<br><br>Just to emphasize what I'm saying:<br>if you run L2TP/IPSec on the NAT box (firewall/gateway/router) you'd want to open UDP 500 + ESP.<br>If the VPN server is _behind_ the NAT box you want UDP 500 + UDP 4500.<br><br>Bob]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20972643</guid>
<pubDate>Tue, 19 Aug 2008 04:33:19 EDT</pubDate>
</item>

<item>
<title>PPTP/L2TP ports to forward</title>
<link>http://www.dslreports.com/forum/remark,20970761</link>
<description><![CDATA[<A HREF="/useremail/u/1241546"><b>tiger9</b></A> : I have a VPN server sitting behind a NAT [S2K3].  It's running L2TP/IPSec and PPTP.  I'd just like to double check that to enable users to connect to the VPN, I have to port forward :<br>   TCP/1723 + IP/47 [GRE] for PPTP<br>   UDP/500 [IKE] + IP/50 [ESP] for L2TP<br><br>Thanks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20970761</guid>
<pubDate>Mon, 18 Aug 2008 19:18:45 EDT</pubDate>
</item>

</channel>
</rss>
