Re: ISA 2004 - MSSQL / Listening VNC Publishing - Denied Connection

From: José Carlos (iwjcs_at_uol.com.br)
Date: 03/26/05


Date: Sat, 26 Mar 2005 13:00:26 -0300

Andy,

Thanks for your response, let's me explain better,

I work in a ASP Company.
I'm preparing the following solution case using our LAN:

- Site-to-remote site (WAN to WAN) VPN Client only to a specific Corba
solution synchronization; This it's ok, it's running!
- Provide firewall to our LAN that uses common application like IE, Outlook,
MSN, etc. This it's ok, it's running!
- Point-to-Point, remote assistance and supports, to our Support Team that
are working in our LAN and use VNC in listening mode;
- Remote database connection (MSSQL) to a site-to-site synchronization using
firewall blocking rules;

I don't need to publish VNC and MSSQL to the VPN. The Server was configured
as VPN client
I need to publish our Internal LAN that uses VNC (listening mode, protocol
TCP port 55xx) and MSSQL (protocol TCP port 1433) to Internet, using our
Public IP address.

This solution case is installed in a Win2003 Server with ISA 2004 Standard
and again, VPN it's running ok!
The same solution, but without VPN, it's running in ISA 2000 without
problems.
My problem is concerned in VNC and MSSQL publishing.

I've already tried the simple and very usefull instructions but without
success in:

"Publishing a SQL Server Computer with ISA Server 2004",
http://www.microsoft.com/technet/prodtechnol/isa/2004/deploy/publishingsql.m
spx#EAAA
similar tutorial:
"Publishing FTP Sites with an Alternate Port using ISA Server 2004
Firewalls", http://www.isaserver.org/tutorials/2004pubftpaltport.html

When I try to connect to MSSQL through the remote IP, I receive the
following logging message:

Destination IP:
            200.x.y.z - it's correct IP Address from our server
Destination Port:
            1433
Protocol:
            Microsoft SQL (TCP)
Action:
            Denied Connection
Rule:
            Default rule
Client IP:
            200.a.b.c - it's correct remote IP Address
Source Network:
            External - I think it's ok
Destination Network:
            Local Host - I think this it's wrong; I suppose this must be
"Internal"

The same logging message occurs with the VNC, but with a curiosity, the
Protocol appears like "Unidentified IP Traffic", but it's registered as
"VNC5xxx".
I've tried to re-register another MSSQL Server Protocol with other name than
default "Microsoft SQL (TCP)" and the new name appears right in the logging,
so I thing that's nothing wrong with the "VNC5xxx" registry.

Excuse-me by the extensivity and the multi-posts.

Any idea?

Thanks in Advance,

José Carlos.

"ABH" <andyspamfee@hotmail.com> escreveu na mensagem
news:#AePj3fMFHA.2252@TK2MSFTNGP15.phx.gbl...
> "José Carlos" <iwjcs@uol.com.br> wrote in message
> news:uxzlSyOMFHA.3760@TK2MSFTNGP12.phx.gbl...
> > Dear all,
> > I've setup the remote VPN client successfull.
> >
>
> If you've set up VPN client connectivity and want to use VNC on internal
> machines, the logical way would be to connect over VPN and then use the
> internal IP to connect using VNC.
>
> Surely you don't actually want to publish VNC on a public IP adddress ?
>
>
> --
> Andy
>
>



Relevant Pages

  • Re: How expand domain subnet?
    ... the server subnet masks and the IDENTICAL DHCP scopes. ... So if a server goes down, ... Although it is unusual to have a segment of TCP/IP LAN without internal ... but if the VPN client is on a 192.168.x.x LAN it uses up ...
    (microsoft.public.windows.server.networking)
  • Re: VPN issue
    ... This could be in the security configuration of the visitors LAN. ... > The VPN client connected to its IPsec server, asked for my password, went ... > server can't be found. ...
    (microsoft.public.win2000.networking)
  • Re: Win 2003 VPN: Cannot reach LAN
    ... Looking at your routing table of VPN client, it seems like you are getting the default gateway address correctly. ... Also try the same for some LAN machine IP address ... Have you enabled forwarding on VPN server? ... Can you do "ipconfig /all" and "route print" on VPN server and send the output? ...
    (microsoft.public.win2000.ras_routing)
  • Re: Remote access to home Macs?
    ... but while nice and responsive across the LAN it's a bit useless for the WAN I've found. ... Set up port-forwarind on your NAT router - forward port 22 to the IP of the machine you want to look at. ... Run OSXvnc server on display 1. ... Then open your VNC viewer and tell it to look at localhost:5901 ...
    (uk.comp.sys.mac)
  • Re: computer missing from network
    ... LAN broadcasts. ... The VPN client is not on the LAN so the machines on the LAN ... server he can print to his printer. ...
    (microsoft.public.windows.server.networking)