VPN plus NAT on Windows 2008 Server R2: Need two virtual NIC

Ask questions about dedicated servers here and we and other users will do our best to answer them. Please also refer to the self-help section for tutorials and answers to the most commonly asked questions.
Post Reply
Numenius
New to forums
New to forums
Posts: 6
https://www.youtube.com/channel/UC40BgXanDqOYoVCYFDSTfHA
Joined: Sat Jul 28, 2012 9:35 pm

VPN plus NAT on Windows 2008 Server R2: Need two virtual NIC

Post by Numenius »

Hello, NFO! I'm still loving your great service. I searched through the KB and FAQ but didn't see an answer to my question, so I hope it wasn't covered already somewhere.

I'd like to use RRAS on Win2k8 R2 to set up VPN with NAT. I already did the VPN part last evening and it works: I can connect from home and access a shared folder on the server and receive a VPN IP assignment from within the IP range I configured. The NAT part, however, has a hitch. I am wondering if I need a second instance of the Xen Net Driver to simulate the second NIC card usually present on a physical NAT setup?

When I configured RRAS through the wizard, I selected VPN plus NAT. VPN wizard proceeded as expected. No NAT part followed, however. So I went to RRAS snap-in module, selected my server/IPv4/General, right click, selected "new routing protocol," and I received the message "No new router interfaces are available for addition." Likewise right click on the same, selecting "New interface", results in the same message.

Network and Sharing center likewise shows the regularly functioning internet connection from NFO Network 5 to the internet. It also now shows the new RAS Interface, as Private Network, but next to it, it has "access type: No internet access" and "Connection:" is blank, rather than "Xen Network Adapter." So is something wrong here?

I tried going to the Xen Network Adapter / Adapter Settings / IPv4 / Properties / Advanced and added a second IP address in the 10.x.x.x range, but this didn't give me any more options for adding a new routing protocol, which is the step I think I'm missing to enable NAT. I've also heard it's harder and not Microsoft "recommended scenario" to multihome the public internet IP and the internal NAT service on the same NIC, though it seems it can be done but is more complicated.

So, questions:
Is the right solution to install a second instance of the Xen Net Driver to simulate a two-NIC machine? If so, how? If not, what is the right way to proceed? Or perhaps I making some other noob mistake here? :wink:

Background, if it helps:

Why both VPN and NAT? I'd like to use the VPN to coordinate file sharing between several computers (home, portable, and work office), and I'm hoping adding NAT to the VPN would allow me to tunnel to internet access through NFO when logged on from work, because our work network is a ramshackle mess, has terrible response times for new DNS lookups (10s for new addresses, often fails on first try), making browsing awful, really slow during peak usage hours, weird local caching issues, and some blocked ports which occasionally it would be nice to bypass (like to check on the gameserver) because they are trying to preserve limited bandwidth. The IT guy there knows less than I do, I think, about networking. It's often faster to browse on my phone in 3G than on the ethernet-connected desktop at work! I realize tunneling won't solve the problem of limited bandwidth during peak usage, but I'm betting with tunneling through VPN+NAT, I will get a real benefit due to the other issues.
Numenius
New to forums
New to forums
Posts: 6
Joined: Sat Jul 28, 2012 9:35 pm

Re: VPN plus NAT on Windows 2008 Server R2: Need two virtual

Post by Numenius »

I spoke with Tech Support again tonight and they suggested upgrading to the two IP option, so I tried that.

The upgrade completed, I followed the instructions on the confirmation page to add a second IP to the Xen adapter IPv4 properties, and rebooted the machine for good measure. Then I disabled RRAS and reconfigured from scratch.

It still doesn't work. Here's exactly what happens.

I go to Start Menu/Administrative Tools/Routing and Remote Access. I right click the server name, and select "Configure and Enable." I get the wizard start page. Click Next. Then I select the third option, "Virtual Private Network and NAT." I receive the error message as before:

"Les than two network interfaces were detected on this machine. For standard VPN server configuration at least two network interfaces need to be installed. Please use the custom configuration path instead."

Going to custom configuration, I tick the box for "VPN" and the box for "NAT." It reports those options as selected in the confirmation screen. I click next. It chugs for a bit, says it completed, and is starting server. It brings me back to the RRAS control panel main screen. I right click the server name, and all the VPN options are there, but nothing for NAT.

Does anyone know what might be making it fail here?
Majorproject
New to forums
New to forums
Posts: 1
Joined: Thu Oct 25, 2012 2:21 pm

Re: VPN plus NAT on Windows 2008 Server R2: Need two virtual NIC

Post by Majorproject »

Was this ever resolved?
Running into the same issue.
Post Reply