Re: VPN Client can't access internal network -- Help?!?!

From: Eric (estam_at_scsiweb.com)
Date: 04/06/04


Date: 6 Apr 2004 12:22:00 -0700

Hello All,

The current configuration consists of 3 machines:
1. ISA Server original
2. ISA Server new
3. PC (w2k) on the web

To the best of my knowledge machine #1 and #2 are the same. They both
have:
ISA 2000 + sp1
RRAS
W2k + sp3 + windows updates

Obviously, they are not the same machine, so there are hardware
differences, but they both have 2 NIC cards (1 for Internet + 1 for
Internalnet)

The PC has a network connection for VPN defined for machine #1. Then
I copied it and changed the IP address to point to #2.

Both connections go active and I can "logon" to both connections.

When I am connected to #2, I can ping the ISA server using the VPN
address and the internal network address, but nowhere else on the
Internal network. I can ping from #2 to the internal network. When I
tracert from the PC through #2, tracert shows the ISA server (the VPN
address), and then the normal request timeout message.

All the above are successfull on #1.

There must be something simple that I am missing... but I can't see
it.

The internal network has 2 ranges. The first is primarily used by the
machines in the network. The second is used by ancillary machines and
the VPN. The PDC is multihomed. The ISA/LAT is the same for both
machines and has both ranges defined as internal.

Please keep the questions coming... Hopefully, this will turn out to
be an easy problem.

Eric

"Sharoon Shetty K [MSFT]" <sharoons@online.microsoft.com> wrote in message news:<#GyeRG9GEHA.2408@TK2MSFTNGP12.phx.gbl>...
> Can you check the tracert output ?
>
> --
>
> Thanks
> Sharoon
> sharoons@online.microsoft.com
>
> This posting is provided "AS IS" with no warranties, and confers no rights.
>
> "Eric" <estam@scsiweb.com> wrote in message
> news:c84aa573.0404020816.168878bf@posting.google.com...
> > Hello,
> >
> > I am trying to swap out my ISA computer to a new
> > bigger/faster/stronger machine. I need to be able to test my new
> > machine without disrupting the current configuration.
> >
> > Problem:
> >
> > VPN client CAN connect to ISA/RRAS machine. CAN ping ISA/RRAS
> > machine. Can NOT access(VNC)/ping any machine on the internal
> > network.
> >
> >
> > Environment:
> >
> > NT Domain
> > W2K Server (stand alone)
> > ISA 2000 (Firewall mode)
> > RRAS
> > 2 NIC cards (Internet & Internal)
> >
> > I have a test machine here... I have 2 VPN Clients configured (1 for
> > each server) The original client works perfectly. The second one
> > fails. I can see no significant differences in the Route table.
> >
> > What did I miss?
> >
> > Eric



Relevant Pages

  • Re: 2 servers with same name on same LAN ?????
    ... Document your IP scheme and topology along with the machines that are ... Use a proxy like ISA Server that keeps logs of what happens and can ... It can also control access to the Internet ...
    (microsoft.public.win2000.networking)
  • Re: Active directory authentication
    ... >trying to complete a client logon to an Active Directory ... >to join machines to the domain from behind ISA Server. ... >> Can I authenticate thru ISA Server? ...
    (microsoft.public.isa)
  • Re: Virtualization of ISA2006
    ... an adapter shared by a number of machines to the internet? ... Microsoft Internet Security & Acceleration Server: Partners ... Microsoft ISA Server Partners: Partner Hardware Solutions ...
    (microsoft.public.isa.configuration)
  • RE: Group Policy for XPSP@
    ... manual for installing the remote administration when using ISA Server. ... > I just installed the network version of AVG Virus on the SBS Server. ... > connect to any XPSP2 machines to install the virus program and configure it. ... The instructions they provided apply to ISA server 2004. ...
    (microsoft.public.windows.server.sbs)
  • ISA Server 2004 and VMWare
    ... Can ISA Server 2004 properly firewall virtual machines and their class C ...
    (microsoft.public.isa)

Loading