Re: Routes



Hi Phillip,

I have been told that I have been set up to fail! The IT departmant of the
company involved are trying to get me to fail so they don't loose face.

I think that the best way forward is to forget what constraints they have
set and to give them a finished solution that will work!

Ok, Firstly I will get rid of NIC2 in both servers and work with a single in
both. and connect the Sonicwall to the LAN Switch.

I will allow full network access to the VPN clients.

The Default Gateway on the network shall remain 10.24.16.1.

The Sonicwall shall remain 10.240.16.6 and the servers will stay
10.24.16.10/10.24.16.12/10.24.16.14. The Pcs addresses are via DHCP and are
there to run terminal Sessions to 10.24.16.10 and 10.24.16.12. The Pc's also
run citrix sessions to there head office which allows them access to
Word/Excel, the internet and mail and routes there printing back up to there
local printers

The Backup domain controller is 10.24.16.14 and this runs the printers and
DHCP server.

John


"Phillip Windell" wrote:

"Buzz" <Buzz@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:D32C25E1-A93E-4D87-979F-B4CE06EF2E16@xxxxxxxxxxxxxxxx
You could probably make it easier for yourself if you could set up the
VPN to the Sonicwall, then connect by Remote Desktop or TS client to the
servers over the VPN connection.

That is exactly what i want to do! but the only way I can get a Ts client
to attach to the server is to have the Sonicwalls IP in the Default gateway
in Nic2.

This is what you said:
---------------
I have a quick question about static routes. I have been asked to supply a
VPN solution to access 2 servers for support purposes using a Sonicwall
device which is not to impact any of the system as at present and to
terminate at the servers and no further into the LAN.
---------------

You said,..."No futher into the LAN"

I said,.....
-------------------
You can't. When you successfully connect the VPN and it works properly the
whole LAN is available. That has always been the "weak point" of all the
Hardware VPN Appliances.
-------------------

So this is the situation,...unless you throw out the Sonicwall and use a better
product like ISA Server for the job,...it **will** go further into the LAN than
just the one machine you want to target.

So that leaves two questions:

1. Do you still want to do it anyway even though the access will be to the
entire LAN?

2. If the answer to #1 is yes,...then what is the LAN Topology designed like so
that the routing can be set up propterly.


--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft, or
anyone else associated with me, including my cats.
-----------------------------------------------------



.



Relevant Pages

  • Re: Routes
    ... out through the Sonicwall, but the server will lose its normal Internet ... The Application Servers are solely used to run an application and serve ... The basic problem is that you are trying to use VPN to do a job that it ... reason it gets access to all the machines on the LAN. ...
    (microsoft.public.windows.server.networking)
  • Re: Routes
    ... I will allow full network access to the VPN clients. ... The Sonicwall shall remain 10.240.16.6 and the servers will stay ... terminate at the servers and no further into the LAN. ...
    (microsoft.public.windows.server.networking)
  • Re: Routes
    ... out through the Sonicwall, but the server will lose its normal Internet ... The LAN and Sonicwall NICs should be in different subnet, ... Networking, Internet, Routing, VPN Troubleshooting on ... VPN solution to access 2 servers for support purposes using a Sonicwall ...
    (microsoft.public.windows.server.networking)
  • Internal NIC weird after reconfig of RRAS server. Desperate!!
    ... let's VPN traffic through to the external nics of the VPN servers. ... IAS) on the internal LAN, and the checkpoint lets this through from the ... When I restarted the RRAS ...
    (microsoft.public.win2000.ras_routing)
  • Re: Connecting different Servers over Internet
    ... VPN from home. ... data on the different servers and such; ... >> the lan). ... we are working with one ISP and doing a wireless ...
    (microsoft.public.win2000.advanced_server)

Loading