Re: VPN Routing

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



 

Case Study ? VPN client can ping the VPN server only

 

Situation: one of our clients setup a VPN on windows server. The VPN client can ping the VPN server without problem. However, they can?t access other network resources and ping receives ?time out? message.

 

Investigation: 1. The Windows server is behind a router with PPTP pass-through.

2. The server comes with two NICs and both are enabled.

3. The ipconfig /all display both NICs? IPs are in the same IP range, 10.0.0.0/8.

 

Analysis: Any windows multihomed servers should not use the same IP range if it comes with two or more NICs.  In general, if you have a router or firewall protecting your LAN, you can create a VPN using just one NIC; if you don?t have a router or firewall protecting your LAN, you should enable RRAS on a Windows server with two NICs using the different IP ranges. In some cases, you may want to have more secure LAN even the LAN is behind a router or firewall, you can setup a Windows server as VPN using two NICs. But, they must be in the different subnets. For example, one NIC is 192.168.0.2/255.255.255.0 and another is 10.0.0.2/255.0.0.0.


Don't send e-mail or reply to me except you need consulting services. Posting on MS newsgroup will benefit all readers and you may get more help.

Bob Lin, MS-MVP, MCSE & CNE
How to Setup Windows, Network, Remote Access on http://www.HowToNetworking.com
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
This posting is provided "AS IS" with no warranties.

I recommend Brinkster for web hosting!

I've set up a VPN on a W2K3 server my local network using RRAS.  The VPN
server is not a DC.   The VPN server has two NICs - Internet & Intranet.
I'm using IAS to authenticate.

The entire network is connected to the Internet through a Linksys router
(BEFSR41) with NAT on.  The router maps ports 1701 and 1723 to the
"Internet" nic on the VPN server.

My remote clients can connect to the VPN server, authenticate and their
computers get registered.  The remote clients are able to pull in IP
addresses and configuration info via DHCP.  However, they cannot reach any
of the resources on the network.  At the most basic level, they cannot ping
anything on the network by IP address.

To reduce the size of this message, I've attached a text file with the
relevant configuration information and the results of a tracert from a
remote client.

Any help would be appreciated.

Thanks.




Relevant Pages

  • Re: ConnectComputer Problem
    ... I'm a little confused by your network configuration. ... Switch2 --- SBS Server ... switch has internet access all the time, the second switch has the client ... NICs ...
    (microsoft.public.windows.server.sbs)
  • Re: Still cant connect to RWW or OWA remotely
    ... laptop plugged into port on DSL router. ... service, e-mail, and RWW is available to all users on the network. ... The server is a SBS2003 SP1 Standard box without ISA, ... of the two NICs by clicking the Advanced tabs, it won't open that box, ...
    (microsoft.public.windows.server.sbs)
  • Re: Cannot browse the network after migration
    ... the cause is the multiply NICs are all enable NetBT. ... >>> browse the network. ... >>> 189101 Understanding NetBIOS Resource Record Flags ... >>> NetBIOS setting from the DHCP server. ...
    (microsoft.public.windows.server.migration)
  • RE: How Does ISA 2004 Performs Routing
    ... Since I'm still not very clear about the network topology, ... The output of "IPconfig /all" command on ISA and an internal computer. ... >referring to routing between the 2 NICs but was referring to how the ISA ... >server itself routed to the next proxy server in the proxy chain. ...
    (microsoft.public.isa)
  • Re: Still cant connect to RWW or OWA remotely
    ... The server is a SBS2003 SP1 Standard box without ISA, ... the two NICs by clicking the Advanced tabs, it won't open that box, and ... program or service is running that might use the network address translation ... Is the Modem also your Router? ...
    (microsoft.public.windows.server.sbs)