ISA 2006 - D-Link DFL-210 site-to-site VPN loses packets

Tech-Archive recommends: Fix windows errors by optimizing your registry



I have the following setup:

Main site: ISA Server 2006 SP1 on Windows Server 2003 R2 SP2. Two AD domain
controllers (on other machines).

Remote site: D-Link DFL-210 (F/W: 2.20). No servers, just two Vista SP1
laptops and a network printer.

I have set up an IPSec site-to-site VPN-tunnel using a PSK and mostly it
works alright. I can ping systems in both directions and I can access
intranet websites.

I can also log in to the Windows domain from the laptops at the remote site.
But access to resources (files, CRM-system, SQL-server and so on) is slower
then I had expected and sometimes the users lose the access rights to some of
the systems.

In the ISA log I get a lot of FWX_E_TCP_NOT_SYN_PACKET_DROPPED errors for
packets sent from laptops at the remote site to servers at the main site.
NetMon also shows a lot of "ICMP: Time Exceeded Message" messages from the
servers to the laptop.

In ISA 2006 the network object for the remote site includes the IP-range for
that subnet and also the external interface address for the DFL-210. There
are two network rules set up that routes traffic from "Remote net" to
"Internal" and from "Internal" to "Remote net" (the latter is for me to be
able to remotely access the systems at the remote site).

Obviously something is wrong since ISA finds a lot of packets that it can't
match to an open session, but I can't figure out what the problem is. Anyone
got an idea?
.



Relevant Pages

  • Re: SKYPE through ISA 2004
    ... Isa Management, monitoring, logging tab then 'start query' Be good to know ... the laptops don't theoretically have access to your internal network ... the domain, and I have enough connectivity to make a connection, ... node actually is inside the network. ...
    (microsoft.public.windows.server.sbs)
  • Re: SKYPE through ISA 2004
    ... Think we are gonna have to create some rules in ISA for these laptops.. ... the domain, and I have enough connectivity to make a connection, ... node actually is inside the network. ...
    (microsoft.public.windows.server.sbs)
  • Re: SKYPE through ISA 2004
    ... Think we are gonna have to create some rules in ISA for these laptops.. ... the domain, and I have enough connectivity to make a connection, ... node actually is inside the network. ...
    (microsoft.public.windows.server.sbs)
  • ISA server issues with remote site
    ... Our main office is connected to a remote site between 2 pix 501 routers. ... Pix at the main office is on the same subnet as to SBS 2003R2 & ISA server. ... ISA allows a ping using the SBS protected network access rule. ...
    (microsoft.public.windows.server.sbs)
  • Re: HELP! Cant connect the remote server due to spoofing..
    ... In the networks setting of ISA console, you must add 202.x.x.x as a network ... > The issue here is the connection has been denied. ... > have user A in the LAN to connect to this remote site but need ...
    (microsoft.public.isa)