PPTP VPN Classful Routing

B

BH

The situation is that I created a PPTP VPN connection to a datacenter
environment using class A IP addresses. After creating this connection,
I wanted to maintain Internet access, so I unchecked the advanced TCP/IP
flag to use the remote default gateway. However, since Windows does not
ask for a network and mask for the VPN connection it defaults to
classful routing.

So, as an example, I connect to VPN concentrator 10.1.0.1 and I only
want traffic to the 10.1.0.1/24 network to go through VPN. Everything
else I want to use my current default gateway. Windows, however, has
another idea in mind and simply adds a route to 10.0.0.0/8 through the
VPN. So what I want is all traffic to 10.1.0.0-10.1.255.255 to go
through the VPN, but Windows gives me 10.0.0.0-10.255.255.255.

I know I can manually modify the routes by removing the ones created for
the VPN and injecting new ones, but this is annoying. I am hoping that
someone has a more graceful solution in mind I could try.

Thank you,

BH
 
K

Ken Zhao [MSFT]

Hello,

Thank you for using newsgroup!

Based on your requirement, you may need a solution for it. Please note that
the newsgroups provide assistance to resolve break/fix issues. We are happy
to provide general information in regard to this query.

We also recommend Microsoft Advisory Services. CSS Advisory Services is a
remotely delivered, hourly fee-based, consultative support option that
provides proactive support beyond your break-fix product maintenance needs
like product migration, code review, or new program development. More
information on this service here:
US and Canada:

http://support.microsoft.com/default.aspx?pr=AdvisoryService

Outside of the US/Canada:

http://support.microsoft.com/common/international.aspx

I hope this information is helpful in getting started and we invite you to
post again with any specific break/fix issues.

Thanks & Regards,

Ken Zhao

Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.


Newsgroup Web Interface Upgrade
Please complete a one-time registration process on your first visit to the
Partner Portal beginning July 11, 2005 at 9 A.M. PST by entering the secure
code mspp2005 when prompted. This secure code will be valid for 6 months
after which you will need to update your registration by entering the new
secure code. We will post announcements in the newsgroups prior to
expiration. Once you have entered the secure code mspp2005 , you will be
able to update your profile and access the the partner newsgroups. Please
update your Favorites link to the newsgroups web page, your current link
will redirect until November 1, 2005.
Please post any comment, questions or concerns to the
microsoft.private.directaccess.partnerfeedback newsgroup. For more
information, please go to:
https://partner.microsoft.com/global/technicalsupport/registeredsupport/4001
4662


--------------------
| Date: Wed, 10 Aug 2005 16:16:26 -0500
| From: BH <[email protected]>
| Reply-To: (e-mail address removed)
| User-Agent: Mozilla Thunderbird 1.0 (Windows/20041206)
| X-Accept-Language: en-us, en
| MIME-Version: 1.0
| Subject: PPTP VPN Classful Routing
| Content-Type: text/plain; charset=ISO-8859-1; format=flowed
| Content-Transfer-Encoding: 7bit
| Message-ID: <#[email protected]>
| Newsgroups: microsoft.public.windowsxp.work_remotely
| NNTP-Posting-Host: 63.96.4.10
| Lines: 1
| Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP15.phx.gbl
| Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.windowsxp.work_remotely:12753
| X-Tomcat-NG: microsoft.public.windowsxp.work_remotely
|
| The situation is that I created a PPTP VPN connection to a datacenter
| environment using class A IP addresses. After creating this connection,
| I wanted to maintain Internet access, so I unchecked the advanced TCP/IP
| flag to use the remote default gateway. However, since Windows does not
| ask for a network and mask for the VPN connection it defaults to
| classful routing.
|
| So, as an example, I connect to VPN concentrator 10.1.0.1 and I only
| want traffic to the 10.1.0.1/24 network to go through VPN. Everything
| else I want to use my current default gateway. Windows, however, has
| another idea in mind and simply adds a route to 10.0.0.0/8 through the
| VPN. So what I want is all traffic to 10.1.0.0-10.1.255.255 to go
| through the VPN, but Windows gives me 10.0.0.0-10.255.255.255.
|
| I know I can manually modify the routes by removing the ones created for
| the VPN and injecting new ones, but this is annoying. I am hoping that
| someone has a more graceful solution in mind I could try.
|
| Thank you,
|
| BH
|
 
O

OJ

I 've been all through this. It's to do with IPCP and RAS subnet masks.
If you look at your vpn clients subnet mask while connected it is
255.255.255.255. this is by defaul and cannot be changed. (when using
default gateway on remote network)

If you choose not to use the default gatewy on remote network, then you can
only router to the 254 hosts on teh same classefull subnet as you, even if
the correct IP settings are on the ISA Server.
It's shit, but this is by design..

google for IPCP DHCP RAS and you will find answers.

OJ
 
B

BH

OJ said:
I 've been all through this. It's to do with IPCP and RAS subnet masks.
If you look at your vpn clients subnet mask while connected it is
255.255.255.255. this is by defaul and cannot be changed. (when using
default gateway on remote network)

If you choose not to use the default gatewy on remote network, then you can
only router to the 254 hosts on teh same classefull subnet as you, even if
the correct IP settings are on the ISA Server.
It's shit, but this is by design..

google for IPCP DHCP RAS and you will find answers.

OJ

What a PITA, I guess I will have to look at some other options. Thank
you for the help.

BH
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top