Re: Internet Web browsing and VPN acess why not at the same time?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Jianwa пишет:
We have a VPN and ISA 2004 server that provides access to VPN clients.
VPN clients can connect to the corporate network and get access to all
internal servers (and services).

When the VPN client connect they can╢t browse the internet. They only have
access to intranet website(s), but no Internet.

Name resolution seems to work fine, through corporate DNS.
VPN users can't ping Internet addresses.
When VPN clients disconnect they have again full access to the Internet.

VPN server is using a static IP address pool.

Now we need SOME users to have Internet Access AND Intranet (vpn) access at
the same time.

Any idea about what's wrong or how to get both ?

Thanks in advance.


When VPN user connects to your network his routing table changes (by
default, your VPN server became default gateway for your clients). So
all internet traffic comes through your ISA server, and to give
Internet access you should enable HTTP traffic from "VPN clients"
network to external.

Another method - use CMAK (Connection manager administration kit) to
create connection profile, where you can define routes to your internal
network via VPN serve.




--
With best regards
Nickolay Domukhovsky, MCSA

.



Relevant Pages

  • Re: Sometimes it works sometimes it doesnt (VPN data issues)
    ... NIC1 "Internet" is set to ... (the IP of the external firewall) and the DNS is set to ... A connection between the VPN server and the VPN client xxx.xxx.xxx.xxx ...
    (microsoft.public.windows.server.networking)
  • RE: Sharing VPN client connection
    ... as a VPN server, configure the internal clients to connect the remote ... office by VPN connection and then access to the Internet from the Remote ... Enable internal clients to access the Internet. ... On the server, go to My Network Places, click New Connection Wizard. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN Problem, need your help.....
    ... Are you actually connecting one card to the NAT ... get this server to a single NIC scenario ... > VPN server. ... > Internet for all the systems on the network. ...
    (comp.security.firewalls)
  • Re: The OTHER problem with Netgear WGT624 (and probably others)
    ... |>|>Isolated network zone, enforced by router and firewall rules. ... My preferred solution is to put the server behind ... |>| authenticated VPN and blocks all outbound connections. ... |>How does VPN help an office connect to the internet? ...
    (alt.internet.wireless)
  • Re: Browsing share on AD slow over VPN
    ... VPN Clients - No NAT translation from internal IP to VPN client IP address): ... share if I put IP address of server rather than its host name. ... internet, they use their own gateway instead of the remote network gateway. ...
    (microsoft.public.windows.server.active_directory)