Re: site to site routing through VPN

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

anonymous_at_discussions.microsoft.com
Date: 05/13/04


Date: Thu, 13 May 2004 06:58:25 -0700

Thanks for the response Bill.

I added the routes through the routing and remote access
admin, static routes. The default gateway is the servers
in both cases. Could you elaborate on how to look into
these issues here. I'm not sure what you mean or where to
look:

"Are they linked to the demand-dial
>interfaces?"
do you mean the interface I created? If so I added the
route when I installed the interface and the route uses
the interface as it's gateway.

> Check that the VPN actually binds to both dd
interfaces.
How do I check this?

> Check that the subnet routes are added to the
routing table at both
>ends, using the VPN endpoint as the interface.
Could you elaborate here? Not sure what you mean.

I also wanted to add... there is not a trust between the
two domains yet. Would this cause me to not be able to
ping? Second the 2k3 server is not multi homed, is there
perhaps an issue with this? I think I may have read
something about issues with not being multi homed and
rras. Any ideas?

Cheers! and thanks for the response.

>-----Original Message-----
> Ping from server to server is easy - they are joined
by a point-to-point
>link! To get from client to client requires the routing
to be working.
>
> How did you add the routes? Are they linked to the
demand-dial
>interfaces?
>
> Check that the VPN actually binds to both dd
interfaces.
> Check that the subnet routes are added to the
routing table at both
>ends, using the VPN endpoint as the interface.
> Check that the clients at both ends use the VPN
router as their default
>gateway.
>
>"Scott Taylor" <anonymous@discussions.microsoft.com>
wrote in message
>news:c40d01c4386d$4ffdcb80$a501280a@phx.gbl...
>> Hello All!
>> I've got a server to server VPN set-up for routing
>> between two sites. Site 1 is NT 4 domain. Site 2 is 2k3
>> sbs. they are seperate domains. site 1 domain a; site 2
>> domain b.
>>
>> I can get the servers connected via vpn. using defined
>> interfaces. I've added the routes for the networks in
>> each routing table. I can ping from router in site 1 to
>> all systems in site 2 and viseversa. But I can't ping
>> from any workstation in either site across the servers
to
>> the other site, workstation in site 1 can't ping router
>> or workstations or servers in site 2 and viseversa.
>>
>> Thus I can't connect to apps or check email either.
>> anyone got any ideas?
>>
>> Cheers and ty in advance!
>>
>
>
>.
>



Relevant Pages

  • iptables and static routing..
    ... using iptables command. ... Note that if I turn the interface to the network down, ... but also sets unwanted/undesirable routing paths in the routing table. ... should not set the default routes in the first place. ...
    (Fedora)
  • Re: /etc/sysconfig/network-scripts/route-ethN Question
    ... Another way is to dispense with the routing syntax and setup the variables in the file: ... Red Hat's startup scripts will pattern match base on the variables and file name, setting the routes accordingly per adapter. ... This setup the routes on the virtual interface to my VMs. ...
    (RedHat)
  • Re: Q: multi-homed server with multiple default routers
    ... Instead only the destination address and routing table are used ... >> to determine the interface and hardware destination. ... to add a permanent route other than adding a default router. ... It is also a method to add one or more permanent routes that are not ...
    (comp.unix.solaris)
  • Re: 2620, 1721 and T1 - routing issue
    ... Ethernet1/0 (connected to a switch at colo then to servers there) ... The Ethernet1/0 to the servers is working fine and servers are visible ... communicating but as you all say the routing is in bad shape. ... Host Gateway Last Use Total Uses Interface ...
    (comp.dcom.sys.cisco)
  • Re: [fw-wiz] Multiple routes out
    ... Your natting will detrmine your routing. ... routes for the other nets ... anything coming in to the ASA on InsideNet1 needs to be given ... Anything coming in on InsideNet2 needs to be given to OutsideNet2 interface ...
    (Firewall-Wizards)