Re: can you identify if this is a dns issue..

From: Ace Fekay [MVP] (PleaseSubstituteMyActualFirstName&LastNameHere_at_hotmail.com)
Date: 08/04/04


Date: Wed, 4 Aug 2004 18:06:13 -0400

In news:OrtTszleEHA.2532@TK2MSFTNGP09.phx.gbl,
Calvin C. <CChang@mjlm.com> made a post then I commented below
> Thanks Ace and Lee,
> Yes, we're using Cisco VPN client and Cisco router (2600 gateway)
> No personal firewall, ICF, Proxy or ISA. Not sure about IP access
> rules on router or allowing routing from VPN client but I guess not.
> (It's our vendor to configure the router and VPN, but cannot figure
> out the problem either)
>
> I've sent my VPN config to Cisco tech, and he said it's fine so I try
> to find a clue from MS side.
>
> THanks again.

I still think it's something on their end, but I'm not trying to pass the
buck. I'm just saying that based on your description. You said that you can
ping by IP, but you cannot connect by IP, FQDN or computer name. Smply
stating that connecting by IP is the base method and easiest method to test
connectivity that does not utilize DNS. IF you cannot connect by IP, but can
ping it, then its telling me there's something blocking the connection,
meaning something is blocking the ports required to make a connection,
mapped drive, or whatever you;re trying to do, something such as a firewall
rule, an IP access list or even ICF. DNS from your description, does not
seem to be a factor here.

Maybe it's NAT. If mutliple internal NAT subnets are routing between each
other on a Windows NAT/RAS server, then I've seen issues with H.323 support,
since that squashes the PDUs required for LDAP communication, but this
applies to AD communication. In that case, we would kill H.323 support. But
since you are using a Cisco connection, and you state that you are not using
a Windows RAS server for VPN connectivity, then it seems to point back to
the Cisco VPN service.

Do you have multiple internal NAT subnets? If using private IP addressing,
what is offering NAT, the Cisco router or Windows?

-- 
Regards,
Ace
Please direct all replies ONLY to the Microsoft public newsgroups
so all can benefit.
This posting is provided "AS-IS" with no warranties or guarantees
and confers no rights.
Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft Windows MVP - Windows Server - Directory Services
Security Is Like An Onion, It Has Layers
HAM AND EGGS: A day's work for a chicken;
A lifetime commitment for a pig.
-- 
=================================


Relevant Pages

  • Re: RDP thru Cisco VPN client and thru 501 Failure
    ... been configured to establish a site-to-site VPN to the ... that our connection is thru his 506E, I am not sure of that. ... standard M$ connection (not requiring Cisco client) to our 501. ... Do  you have access to theofficePIX 501 and can you post the PIX 501 ...
    (comp.dcom.sys.cisco)
  • Re: Cisco VPN Client outbound through an ISA server
    ... VPN tunnel from client to Cisco VPN server needs to be in "Transparent ... UDP 500 send receive allows S-NAT based cisco client to connect to the Cisco ... > Secure VPN Connection terminated locally by the Client. ...
    (microsoft.public.isa.enterprise)
  • Re: Proxy for VPN-Clients
    ... Cisco to find a solution to this. ... Phillip Windell ... The users don't connect via Microsoft VPN - the use ... > Cisco VPN Client to connect to a Cisco Pix - so there is no connection ...
    (microsoft.public.isa)
  • Re: VPN/Remote Desktop/Internet problem
    ... If the remote clients are connecting to the PIX using the Cisco VPN ... The remotes may be authenticating their VPN connection against AD though. ...
    (microsoft.public.windows.server.networking)
  • Re: network gateway with a foreign IP address
    ... the Internet to a connection that's behind your Cisco router. ... presume that the 70.x.x.120 address belongs to the Cisco. ... All of the interesting configuration should be done on the Cisco router ... At least ask what diagnostic Jack will use to determine where the problem is when his connection is down. ...
    (Fedora)