Re: Http access across a site 2 site VPN

Tech-Archive recommends: Fix windows errors by optimizing your registry



Thanks, when I log the traffic, I get "failed connection attempt" for the
access rule that represents access to the vpn between the sites. Any
suggestions on where I might go from here?
--
Fred Berestoff


"Fred Berestoff" wrote:

Hi Thanks for the response.

during the site to site wizard isa asks if you want to create the
corresponding network rules and access rules, and I went ahead and created
them as part of the wizard. Specifically I allowed for all outbound traffic
from internal and the vpn link network object (kodiak to anchorage) to
internal and the vpn link network object (kodiak to anchorage for all users
for any time. there is also a network route rule that was created routing
traffic from internal to the vpn.

Question: at one time I had this set up in a side by side design, where the
isa was only for internet access, as a result I had defined the internal
domain and address for ALL internal networks in the internal address and
domains tab. (where you tell isa to bypass those addresses and domains). I
have since removed this information and modified to reflect the current
setup, but could there somehow be some sort of legacy rule set up somewhere?
It would explain why I can pass icmp and other traffic across the vpn but not
http or https.

thanks again,

--
Fred Berestoff


"Phillip Windell" wrote:

What did you do for Access Rules?
no rules = no access
The Remote Network is not part of Internal. It is part of the Network Object
you created when you configured for the VPN. The Access Rules are for between
Internal and the Remote Network Object.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft, or
anyone else associated with me, including my cats.
-----------------------------------------------------

"Fred Berestoff" <FredBerestoff@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:D5D89330-9D89-4121-9229-91DF99BA96EC@xxxxxxxxxxxxxxxx
I have a Site to site VPN between an isa server enterprise 2006 server and a
cisco pix. This VPN used to be a pix to pix vpn but I have been able to
substitute an isa server on one end of the link. Ever since I did this, I
cannot access any "internal" websites that are on the other side of the vpn.
I can see the traffic in the logs, and it shows the http traffic as getting
routed into the correct vpn link, but it just times out with a 504 proxy
timeout error. I can Remote Desktop to computers on the other side of the
VPN, and pass other traffic like icmp traffic: (other than the websites http
and https all other traffic seems to pass normally) any help with this would
be appreciated,

thanks,
--
Fred Berestoff



.



Relevant Pages

  • Re: Http access across a site 2 site VPN
    ... "Fred Berestoff" wrote: ... access rule that represents access to the vpn between the sites. ... internal and the vpn link network object (kodiak to anchorage for all users ... isa was only for internet access, as a result I had defined the internal ...
    (microsoft.public.isa)
  • RE: Missing web services configuration pane
    ... Please contact the ISP to confirm what the exact connection type is. ... If it's a VPN type, you should have the VPN server side address. ... 825763 How to configure Internet access in Windows Small Business Server ... 241252 VPN Tunnels - PPTP Protocol Packet Description and Use ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN Issue
    ... 317025 You Cannot Connect to the Internet After You Connect to a VPN Server ... | first done with a standard usb broadband modem on XP Professional. ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN Error code 800 HELP!
    ... Can you visit Internet and OWA on SBS server? ... Just one PC get error code 800 connecting VPN connecting to SBS? ...
    (microsoft.public.windows.server.sbs)
  • Re: CAN WE LOGIN TO A WINDOWS 2003 ACTIVE DIRECTORY DOMAIN OVER TH
    ... I have only heard about VPN and never tried it. ... drive and access it through the internet after you established VPN connection? ... We can do VPN in windows xp to windows xp machine right and it does not have ... Logging onto a server is not nearly as serious as logging ...
    (microsoft.public.windows.server.active_directory)