RE: PPTP VPN on ISA SERVER 2004

From: Mohammed A. Raslan (mhdraslan_at_gmail.com.delme)
Date: 01/11/05


Date: Mon, 10 Jan 2005 21:31:02 -0800

Forwarding tcp 1723 on your external Firewall interface to the ISA Server is
not enough, you must also forward IP protocol 47 (GRE)

i suggest that you forward all traffic to the External interface of the ISA
server if this is just a DSL modem not a real firewall

"Mouse" wrote:

> Hi,
> I have ISA Server 2004 configured ad Edge Firewall.
> I follow instructions that I found in this article: "Enabling The ISA
> Server 2004 VPN Server".
> http://www.isaserver.org/articles/2004vpnserver.html
>
> My configuration is this one:
> ISA Server 2004 std Ed. installed on Win2k server SP4.
>
> I have 2 network cards (1 LAN 172.16.x.x - 1 WAN 192.168.1.6).
>
> WAN card is connected to a firewall ZyWall that has a public IP over
> internet.
> On this firewall I put a rule to forward PPTP port (1723) to WAN IP of
> ISA Server.
> LAN card is connected to the rest of the LAN (internal network).
>
> When I try to connect a client with the VPN client to the public IP of
> the firewall the client says "unable to connect.. remote server does
> not respond ecc".
>
> In ISA logs I found this line:
> PPTP (protocol)
> Initiated Connection (Action)
> Allow VPN client traffic to ISA Server (Rule)
> 217.56.23.132 (IP from wich I'm trying to connect to ISAServer)
> External (From)
> Local Host (to)
>
> Some ideas?
> "Sorry for my english"
> Thanks
> Fabio
>



Relevant Pages

  • Re: CEICW fails - several errors
    ... The firewall isn't used when ISA is installed. ... On the WAN NIC of your server the DNS has to point to the LAN IP. ... I immediately checked and ISA Server ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA2004 client firewall slow webpage loading
    ... have you configured this new client as web proxy client? ... configure ISA server as your Proxy ... stop the Microsoft Firewall service. ...
    (microsoft.public.windows.server.sbs)
  • Re: CEICW fails - several errors
    ... On the WAN NIC of your server the DNS has to point to the LAN IP. ... Ethernet adapter Internet Connection: ... I immediately checked and ISA Server ... Management said that Web Proxy, Firewall and ...
    (microsoft.public.windows.server.sbs)
  • ISA Spoofing Issue Using Second Firewall with One to One NAT
    ... Two tier firewall implementation segmenting the Internet, ... ISA Server configured with packet filters ... facing firewall's one to one NAT are seen as a spoof by ISA. ...
    (NT-Bugtraq)
  • RE: [fw-wiz] Strange setup
    ... I have done similar designs with a Cisco PIX and ISA server. ... configure the firewall to only a allow traffic on ports 80 and 443 from ... the ISA server is on the internal network and a static NAT ... > Internet hosts). ...
    (Firewall-Wizards)