Re: Clients VPN through ISA 2004

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Tristan Kington [MSFT] (tristank_at_online.microsoft.com)
Date: 10/26/04


Date: Tue, 26 Oct 2004 23:21:40 +1000

VPN connections happen at a lower level than regular Winsock connections, so
the Firewall Client should be disabled while you try it.

Basically, VPN works at the SecureNAT client layer (IP layer - clients that
use ISA Server in line with their default gateway to the internet).

If you make your D.G. the internal IP of the ISA Server, you might have more
luck.

"Chris Roberts" <chris.roberts@robertsc.fsnet.co.uk> wrote in message
news:clldgp$m5$1@news7.svr.pol.co.uk...
> Thanks Tristan,
>
> I've tried creating a rule for any user, from internal to External, but no
> joy.
>
> I've tried monitoring the connection using the logging tab, with an open
> filter, but no traffic appears. I can see traffic from MSN and HTTP from
> the test client but nothing assosiated with VPN or the server that the VPN
> it's trying to connect to. I have a feeling that something is stopping the
> VPN protocol from getting to the ISA Server.
>
> I'm using the Firewall Client on the client machine, and am not sure
> whether or not that is something to do with it. I know it origionaly
> blocked all traffic from Outlook 2003 until I found a setting in
> Configuration\General\Configure Firewall Client Settings. I don't know if
> there is something similar for VPN.
>
> I don't suppose anyone has any ideas of what could be stopping this?
>
> Many thanks in advance
>
> Chris
>
> "Tristan Kington [MSFT]" <tristank@online.microsoft.com> wrote in message
> news:eXqY8rzuEHA.4084@TK2MSFTNGP10.phx.gbl...
>> It definitely works for me at home, but I don't use authentication in my
>> ruleset there.
>>
>> I believe that if you create a rule that allows the VPN protocol (eg,
>> PPTP) you're using to the destination, unauthenticated (eg, applies to
>> All Users or a client set, not a domain user), that it'll probably work.
>>
>> You can work out why something's failing using ISA's monitoring
>> interface, Logging tab. Hit start, and watch while a client makes a
>> connection.
>>
>> --
>> http://blogs.msdn.com/tristank/
>> --
>> This post is provided AS-IS, and confers no warranty.
>>
>>
>> "Chris Roberts" <chris.roberts@robertsc.fsnet.co.uk> wrote in message
>> news:clkukk$gu1$1@newsg1.svr.pol.co.uk...
>>> Does any one know how I can configure ISA 2004 to let clients on my
>>> local
>>> network VPN out through the ISA server to other servers that do not use
>>> ISA.
>>> I've attempted to describe the schema bellow
>>>
>>>
>>> Clients attempting to VPN (Local Network) > ISA 2004 > Internet > VPN
>>> Server
>>>
>>> Many thanks
>>>
>>> Chris
>>> chris.roberts@optima-ws.com
>>>
>>>
>>
>>
>
>



Relevant Pages

  • Re: Possible DHCP issue with VPN clients
    ... You might want to check both the binding order of the NICs (www and VPN ... connections) and also the default gateway metrics on both. ... all of a sudden this client can't connect. ...
    (microsoft.public.win2000.active_directory)
  • [NEWS] Cisco VPN 5000 Client Multiple Vulnerabilities
    ... Multiple vulnerabilities exist in the Cisco Virtual Private Network (VPN) ... 5000 Client software. ... These vulnerabilities are documented as Cisco bug ID ... CSCdx17109 - MAC OS VPN 5000 Client password vulnerability ...
    (Securiteam)
  • Re: Hi GG Tried this and still getting same error ...
    ... On the SBS that your VPN client is connected to, you could add the ip range ... If VPN connections are required both ways, ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange 2007 and Event 9646
    ... Are you at Windows 2003 SP1? ... VPN users (IPsec client, not SSL-based). ... closing TCP connections, but this isn't a real solution. ...
    (microsoft.public.exchange.admin)
  • Re: VPN clients unable to connect to other resources.
    ... gateway matches the IP of the remote client, and DNS and WINS point to the ... remote (although it takes close to a minute to connect, ... This is just regular Windows VPN, ... VPN server, remote routing and access running on the SBS 2003 server ...
    (microsoft.public.windows.server.sbs)