Configuring VPN Packet Filters

Packet filters provide a useful security mechanism for blocking unwanted traffic on particular machines. It’s a good idea to use packet filters to keep non-VPN traffic out of your VPN servers. The rules for doing this are fairly straightforward, as you will see in the following sections.

PPTP Packet Filters

You need at least two filters to adequately screen out non-PPTP traffic:

  • The first filter allows traffic with a protocol ID of 47—the Generic Routing Encapsulation (GRE) protocol—to pass to the destination address of the PPTP interface.
  • The second filter allows inbound traffic bound for TCP port 1723 (the PPTP port) to come to the PPTP interface.

You can add a third filter if the PPTP server also works as a ...

Get MCTS Windows Server® 2008 R2 Complete: Study Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.