ISA 2004 BUG: L2TP connection to ISA on dial-up

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Robert Lacroix (me_at_robertlacroix.com)
Date: 11/12/04


Date: Fri, 12 Nov 2004 03:29:51 +0100

I have problems establishing an L2TP connection to ISA 2004 that is
connected via dial-up (automatic dial-up to External). The client gets
"Error 678: The remote computer did not respond." Certificates are deployed
properly and the connection works to the LAN ip address of the ISA, but
doesn't work to the ip on the dial-up interface (I enabled VPN access from
all networks for testing).
I tried that with the same client. When connecting to the LAN ip it is
directly connected to the LAN, when connecting to the dial-up interface of
the ISA it is directly connected to the internet with no firewall inbetween.
My ISP doesn't block L2TP and I don't block IP fragments on ISA. I don't see
any blocked packets in ISA's log file. I also tried with fwengmon /a 0.0.0.0
255.255.255.255 with no difference.
I checked that behaviour with different servers and different clients and I
have the same problem on all, so I assume it's a bug in ISA 2004. Can
anybody confirm to have this configuration working ? Anything else I can
test ?

Thanks, Robert



Relevant Pages

  • RE: VPN timeouts
    ... I do not use ISA & was wondering if there is a configurable option on the ... You remote clients VPN connection will timeout while trying to connect SBS ... between remote client and SBS server which caused by lack of network ...
    (microsoft.public.windows.server.sbs)
  • RE: RWW not accessible over web
    ... You can install the ISA firewall client on the laptop. ... |> option will configure ISA to provide network security and packet ... Before you run the Configure E-mail and Internet Connection Wizard, ...
    (microsoft.public.windows.server.sbs)
  • Re: Unable to make VPN connection to ISA 2006 Standard
    ... After todays work I conclude this has to be an ISA problem. ... server and used the same ADSL connection, router, client etc and was able to ... make an incoming connection direct to RRAS on this machine with absolutely no ...
    (microsoft.public.isa.vpn)
  • Re: Clarification of BytesSent vs BytesSentDelta in ISA 2004 Firewall log
    ... In ISA Server Management, I can get matching results between the Bytes ... I choose a client IP with relatively little traffic ... Remember that the data in the logs is per connection, ... >>> BytesSent and BytesSentDelta in the Firewall Service log of ISA 2004. ...
    (microsoft.public.isaserver)
  • Re: Unable to make VPN connection to ISA 2006 Standard
    ... server and used the same ADSL connection, router, client etc and was able to ... make an incoming connection direct to RRAS on this machine with absolutely no ... When I reinstalled ISA it also worked and I even got site to site ...
    (microsoft.public.isa.vpn)