Koozali.org: home of the SME Server

VPN and NAT, is it possible

Jaakko Tamminen

VPN and NAT, is it possible
« on: July 12, 2001, 06:41:36 PM »
Hello

I have static IP, but actually my ISP has a NAT, so the public IP is not the one I must use in my router.

Is there a way to make VPN work with this kind of NAT, so 2 other companies could connect with their dynamic IP?

J. Tamminen
Finland

Justin

Re: VPN and NAT, is it possible
« Reply #1 on: July 12, 2001, 07:38:12 PM »
> I have static IP, but actually my ISP has a NAT,
> so the
> public IP is not the one I must use in my router.

So your static IP on your external interface for the e-smith server is being NAT'd before hitting the Internet. Are you sure it isn't just an application proxy by your ISP?

> Is there a way to make VPN work with this kind of NAT, so 2
> other companies could connect with their dynamic IP?

If they are doing NAT at the ISP level your going to have to do some serious sweet talking. They will need to do some configuration on their Internet gateway.

If the other two users are using the same ISP as you, it may be exponentially easier to do.

Justin.

Jaakko Tamminen

Re: VPN and NAT, is it possible
« Reply #2 on: July 12, 2001, 08:54:34 PM »
My ISP is a non-negotiable, holds a monopoly in this area, and is expensive.. what can I do...

The other 2 computers.. one of them is under the same ISP, the other one is abroad (estonia).

So I'm stuk with this NAT transalation.

Currently I'm using beeweeb to share the "main" site hard disk, but beeweeb is unsecure.. They are saying that next year some crypto will be done.

J. Tamminen
Finland


Justin wrote:
>
>  
> > I have static IP, but actually my ISP has a NAT,
> > so the
> > public IP is not the one I must use in my router.
>
> So your static IP on your external interface for the e-smith
> server is being NAT'd before hitting the Internet. Are you
> sure it isn't just an application proxy by your ISP?
>
> > Is there a way to make VPN work with this kind of NAT, so 2
> > other companies could connect with their dynamic IP?
>
> If they are doing NAT at the ISP level your going to have to
> do some serious sweet talking. They will need to do some
> configuration on their Internet gateway.
>
> If the other two users are using the same ISP as you, it may
> be exponentially easier to do.
>
> Justin.

Ken Yuinipok

Re: VPN and NAT, is it possible
« Reply #3 on: July 15, 2001, 11:20:38 PM »
Jaakko,

Your ISP must provide you with a real IP address if you want to do VPN, unless the other PPTP client computer is using the same ISP.  Does that make sense?

Ken