Re: Outgoing VPN Error 619
- From: "Jim Harrison \(ISA SE\)" <jmharr@xxxxxxxxxxxxxxxxxxxx>
- Date: Tue, 22 Apr 2008 09:12:36 -0700
I only beat you when you ask me to; it's part of our "special
relationship"... :-p
The remote subnet being identical to the LAT subnet is most certainly a
problem, but is not relevant to the question of spoofing, misconfiguration
alerts or initial connection failure.
- Spoofing alerts are received when traffic is received from a source IP
which deviates from the address ranges associated with that network. If you
assign VPN clients the same address range as that assigned to your LAT, ISA
will (rightly) cry foul.
- misconfiguration alerts arise from assigning IP addresses to multiple
networks (among other things); "stealing" from the LAT for the VPN network
without actually changing the LAT network (includes actually changing that
network ) creates an overlap
- if you're seeing no problems with your configuration, it's because either
you've disabled the alerts or are not paying them any attention (or not
using ISA 2004 or 2006)
--
Jim Harrison (ISA SE)
This posting implies no warranty and confers no rights.
http://catb.org/~esr/faqs/smart-questions.html
"Phillip Windell" <philwindell@xxxxxxxxxxx> wrote in message
news:ebCjCHJpIHA.4292@xxxxxxxxxxxxxxxxxxxxxxx
"Jim Harrison (ISA SE)" <jmharr@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:78600091-3E54-48E4-B3A5-494F0501CC6F@xxxxxxxxxxxxxxxx
Inbound VPN problem:
You cannot use the same subnet as the LAT.
You MUST use a separate subnet.
There is no option.
Can I ask you to clairify something,...without taking a beating for it,
anyway?
The "same subnet" you mention above,...Are you describing the orignal subnet
the VPN client lives in? Like when a home user is on 192.168.0.x and so is
the business, therefore the user cannot VPN in. Or are you refering to the
VPN client receiving an IP# when they connect that is the same subnet as the
ISA's internal nic. Like when using the same DHCP Scope for both the LAN
and the VPN Clients, that I think was mentioned earlier in the thread.
I am doing the latter and am having no problems.
--
Phillip Windell
www.wandtv.com
The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
.
- Follow-Ups:
- Re: Outgoing VPN Error 619
- From: Phillip Windell
- Re: Outgoing VPN Error 619
- References:
- Outgoing VPN Error 619
- From: Damon
- Re: Outgoing VPN Error 619
- From: Phillip Windell
- Re: Outgoing VPN Error 619
- From: Jim Harrison \(ISA SE\)
- Re: Outgoing VPN Error 619
- From: Phillip Windell
- Re: Outgoing VPN Error 619
- From: Damon
- Re: Outgoing VPN Error 619
- From: Jim Harrison \(ISA SE\)
- Re: Outgoing VPN Error 619
- From: Damon
- Re: Outgoing VPN Error 619
- From: Damon
- Re: Outgoing VPN Error 619
- From: Jim Harrison \(ISA SE\)
- Re: Outgoing VPN Error 619
- From: Phillip Windell
- Outgoing VPN Error 619
- Prev by Date: Re: Outgoing VPN Error 619
- Next by Date: Re: Outgoing VPN Error 619
- Previous by thread: Re: Outgoing VPN Error 619
- Next by thread: Re: Outgoing VPN Error 619
- Index(es):
Relevant Pages
|
Loading