Re: Exchange issue with browsing accross IP Sec tunnel

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



No windows does not cause this what are your ISP connections to each site?
Often times the provider is not supplying enough bandwidth. This can cause
this problem or they are having a problem with their circuit


"Mike" <Mike@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:41338674-11B5-464A-AB89-E191CC9CBCA6@xxxxxxxxxxxxxxxx
Mitch,
we can only use above 200mtu pings onto one of the networks the other ones
wont pass and our sonicwalls seem fine. Not sure where to go from here.
Is
there a setting in Windows possibly causing this?

"mitch Roberson" wrote:

Mike

I was just talking with our network team and they reminded me of
something.
We have occasionally seen a problem with IPSEC tunnels where the tunnel
looks like it is up but it is not. the negotiation did not fully complete
when it is debugged you will see the errors. this is one possibility

the other is delay on the tunnel when you do a continous ping with a
packet
size of 1400 what are the delay times in Milliseconds?
"Mike" <Mike@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:DD251576-4BA0-4F47-9177-EE5883E23349@xxxxxxxxxxxxxxxx
I support a remote site lets call it site B. At site B we use sonicwall
IP
Sec tunnels to connect 25 or so pcs and 3 servers (2 of which are 2000
DC's),
to site A. The client machines and servers use this tunnel from a Site
B
(192.168.44.0) to connect Site A (192.168.1.0) which contains
additional
DC's
and our primary and only exchange server.

Up until about a month ago everything worked fine between the sites and
we
could replicate DNS etc client pcs could browse files on both sides
using
unc
names or unc ip mappings. Then it basically stopped working, our
tunnel
is
up and connected and we can pint by name and IP address but are unable
to
go
beyond that.

The critical issue is that our exchange server (Site A) is not at site
B
and
now outlook clients cannot connect to exchange internally at Site B
thus
no
email. DNS replication is also failing as they sites cannot connect
using
AD
synch either, so now AD is also not able to replicate changes from site
to
site.
Site B geographically is 2000 miles from Site A so we are trying to get
this
done remotely. We do have remote access in using IP mapping.

At this point we have spent countless hours on phone getting no good
response from MS support as we are also a MS partner. Additionally we
have
replaced the soncicwall appliance at site B, added host files on all
pcs
and
several other steps with no good result. We have basically hit the
wall
and
have no idea what would be causing this issue. If anyone has any
suggestion
or has experienced this before it would greatly help us if any
suggestions
could be made. I actually think it could be something very simple but
we
are
so far in we may not just see it.

We are stumped on this so any suggestions would be great!

Thanks
Mike






.



Relevant Pages

  • VPN server over windows XP
    ... I am trying to setup a windows xp machine as a vpn server that accepts ... multiple ipsec tunnels from other windows xp machines. ... The first problem I faced is that windows xp does not support ipsec tunnel ...
    (Linux-Kernel)
  • Re: Juniper Netscreen-SA 1000/neotetis SSL web -terminal and linux klients
    ... >>No, not Windows only. ... >>base OS is Linux... ... I think the client that's used is installed ... Services on the other side through that tunnel. ...
    (comp.os.linux.networking)
  • Re: RRAS 2003 can create Tunnels?
    ... Now my i want to connect my site to a remote site passing through two ... The gave me an IP 10.0.0.1,and they want me to create a tunnel with ... why would you want to waste a Windows machine to do such a thing ... Let a Windows server be a Windows server to ...
    (microsoft.public.windows.server.networking)
  • Re: Establish external trust over a NAT device
    ... successfully shared a PPTP client connection which allows the whole side ... would be really interested in how to set this up using a Windows RRAS server ... to set up an IPSec tunnel between networks, ... be possible if the NAT device also replaces the NETBios owner IP ...
    (microsoft.public.win2000.active_directory)
  • Re: Cant map drives over multi-homed network (VPN)
    ... it was the damn Windows XP SP-2 firewall! ... >>I've also tried to enter the IP addresses of the remote servers ... The ping should indicate that the tunnel is passing ... > Change the local drive letter to an unused drive letter on the local ...
    (microsoft.public.win2000.networking)