Route VPN Clients Through NAT

Daniel Petri


Most of us use the MMC to administer Windows 2000 RRAS. But what happens when you need to route an incoming VPN client back to the net and you’re using NAT with private, non-routable addresses? Users of the company’s VPN used complain about losing internet access while using VPN. The usual way to avoid this is to have the user go to the advanced TCP/IP properties of the VPN connection and uncheck the box that says Use default gateway on remote network.

Unfortunately, not all users can follow instructions, or are willing to do so. Adding the internal interface to NAT puts an end to that issue (but does raise security concerns, so that has to be taken into consideration) and that’s where the NETSHELL command can help.
If you take a look of the interfaces available under the IP routing section of the RRAS console on a Windows 2000 server, you’ll generally see the NIC’s listed, the loopback interface, and a card called the internal interface. That internal connection is the virtual interface that VPN clients connect to, and you’ll notice that you can’t add it to the NAT protocol via the GUI. Time for the command line.
Open the command prompt, type NETSH to open the NETSHELL program. Now type

routing ip nat add interface internal private

Done. You’ll now notice that the internal interface is listed under the NAT protocol. At this point, VPN clients can now route to the net as well as your LAN. You can configure all RRAS functions using the netsh command, but personally I only use it for this purpose.
With Windows Server 2003, Microsoft has added the ability to add the internal interface to the NAT protocol via the GUI.


More in Networking

Network Security

Static vs Dynamic IP Address - What's the Difference?

Mar 29, 2022 | Jason Wynn

What is DNS?

Mar 11, 2022 | Siji Roy

What is 5G and How is it Better Than 4G LTE?

Feb 24, 2022 | Jason Wynn

Datacenter networking servers

What is a DHCP Server?

Dec 7, 2021 | Jason Wynn

How to Access and Triage Network Connectivity in the Microsoft 365 Admin Center

May 19, 2021 | Michael Reinders

Paul Thurrott's Short Takes: February 22

Feb 22, 2019 | Paul Thurrott

Most popular on petri

Article saved!

Access saved content from your profile page. View Saved