<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Ports affecting the VPN connectivity</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/06/13/ports-affecting-the-vpn-connectivity.aspx</link><description>If you are running firewall infront of your RRAS server (i.e. between internet and RRAS) , then following are the relevant ports which needs to be opened on the firewall for VPN connectivity to be successful: 
 a) PPTP tunnel based VPN uses TCP Port</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Securing the server running RRAS role after doing upgrade or fresh install of Windows server 2008</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/06/13/ports-affecting-the-vpn-connectivity.aspx#2997013</link><pubDate>Fri, 14 Mar 2008 08:44:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2997013</guid><dc:creator>Routing and Remote Access Blog</dc:creator><description>&lt;p&gt;Hello, As you know in Windows server 2008 (WS08) we have removed “Basic Firewall” functionality in RRAS&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2997013" width="1" height="1"&gt;</description></item><item><title>re: Ports affecting the VPN connectivity</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/06/13/ports-affecting-the-vpn-connectivity.aspx#1237022</link><pubDate>Thu, 14 Jun 2007 00:06:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1237022</guid><dc:creator>Stefaan Pouseele</dc:creator><description>&lt;p&gt;For L2TP/IPsec based VPN's, a firewall will only see IPsec traffic. In other words, the L2TP traffic (UDP Port 1701) is hidden. Thus, only UDP 500 (IKE), UDP 4500 (NAT-T) and IP protocol 50 (ESP) is needed. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1237022" width="1" height="1"&gt;</description></item><item><title>re: Ports affecting the VPN connectivity</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/06/13/ports-affecting-the-vpn-connectivity.aspx#1236936</link><pubDate>Wed, 13 Jun 2007 23:47:14 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1236936</guid><dc:creator>Sooner Al [MVP]</dc:creator><description>&lt;p&gt;Users can run the test detailed in the PPTP Ping and VPN Traffic sections in this Cable Guy article to troubleshoot PPTP VPN connection problems.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/technet/community/columns/cableguy/cg0105.mspx"&gt;http://www.microsoft.com/technet/community/columns/cableguy/cg0105.mspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;These tools, ie. pptpsrv and pptpclnt, also run on Vista machines for home users setting up a PPTP VPN server on a Vista PC at home and/or use a remote Vista client.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://theillustratednetwork.mvps.org/Vista/PPTP/PPTPVPN.html"&gt;http://theillustratednetwork.mvps.org/Vista/PPTP/PPTPVPN.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Many consumer grade routers have issues passing GRE Protocol 47 traffic.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1236936" width="1" height="1"&gt;</description></item><item><title>re: Ports affecting the VPN connectivity</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/06/13/ports-affecting-the-vpn-connectivity.aspx#1235305</link><pubDate>Wed, 13 Jun 2007 20:26:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1235305</guid><dc:creator>anon</dc:creator><description>&lt;p&gt;What about IPsec NAT-T on 4500/udp? We currently rely on this functionality for Windows 2000 clients connecting to a Windows 2003 Server. If this functionality is changing because of TCP encapsulation solutions like SSTP, then it would be great to know.&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1235305" width="1" height="1"&gt;</description></item></channel></rss>