Re: SBS 2003/VPN - Error 721



Hi,

Error 721 points to the GRE protocol 47 not being forwarded from the router
to your external nic IP. Also known as PPTP pass through. You shouldn't need
to do anything manual in ISA, just run CEICW. Which router do you have?

I get error 721, why is that?:
http://www.smallbizserver.net/SBS2000/RemoteAccess/Igeterror721whyisthat/tabid/94/Default.aspx

--
Regards,

Marina Roos
Microsoft SBS-MVP
One of the Magical M&M's
www.smallbizserver.net
Take part in SBS forum:
http://www.smallbizserver.net/Default.aspx?tabid=53

<postings@xxxxxxxxxxxxxxx> schreef in bericht
news:1115980553.224226.39730@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
> Hi
>
> Here is a repost of a VPN Problem I am desperate to solve. I'm
> keeping this concise as possible. Please coudl you take the time to
> look this over?
>
> I have a SBS 2003 server (not running ISA server). I also have another
> server running ISA 2000 which links via external network card to an
> ADSL router, which in turn goes to my ISP and the Internet.
>
> I simply cannot get an XP client to connect via VPN through the
> Internet (by running "Connect to Small Business Server icon" set up
> via a remote connection disk). All I get is error 721.
>
> UNSUCCESSFUL TESTS COMPLETED:
>
> * I can't log onto the VPN via clients external network interface
> (which links to another ADSL router/Internet). Error 721.
>
> * I have plugged the client's external network card directly into the
> external network card of the ISA Server. No change in behavior. Error
> 721
>
> SUCCESSFUL TESTS COMPLETED:
>
> I can log onto the VPN internally (using PDC internal network IP
> address, and internal network card).
>
> >From the client I can Telnet port 1723 via the external network and
> routers.
>
> I have successfully tested GRE using pptpclnt.exe on the client and
> pptsrv.exe on the server via the external network and routers.
>
> MY CONFIGURATION SO FAR:
>
> ISA Server:
>
> * Added an extra static IP address (allocated from ISP) to External
> network card for VPN use.
> * Created Protocol definition for GRE, 47, Inbound.
> * Created Protocol definition for PPTP, 1723 Inbound
> * Published SBS internal network interface IP address to allocated
> external VPN IP address. I'm only allowing GRE and PPTP protocols
> through in this instance.
>
> * ISA Packet Filters on allocated External VPN IP Address:
> - UDP, Direction = Both, Local Port = 500, Remote Port = 500
> - UDP, Direction = Both, Local Port = 1701, Remote Port = 1701
> - PPTP call, 47, Direction = Both
> - ICMP unreachable, ICMP. Inbound, ICP Type =3, ICMP Code = All codes
>
> SBS Server:
>
> * Ran remote access wizard, assigned VPN IP address I allocated for the
> ISA Server box.
> * Added user to "mobile users" security group.
>
> Windows XP (SP2) Client:
>
> * Note Internet is working fine via external network card.
> * VPN was installed via a remote connection disk created on the SBS
> 2003 server.
> * No Internal firewall used when testing.
>
> Please can I have your thoughts on how I can get this thing working?
>
> Many thanks!
>
> Alex
>


.



Relevant Pages

  • Re: VPN Advice...do I need a purchased static ip address on the external interface?
    ... >> Server then that server must have a been assigned a purchased static IP ... >> if I was to try and use Windows 2000 SBS as the server for the VPN, ... >> If I used a router instead then the router would have this purchased IP ... > supports dynamic dns, then users connect to the dynamic dns name and ...
    (comp.dcom.vpn)
  • Re: vpn probl
    ... not to vpn server, so when workstations needed to reply to the ping requests ... they were trying to respond though their gateway that was the adsl router ... static route 172.16.x..x pointing to vpn remote router in rras, ...
    (microsoft.public.windows.server.networking)
  • Re: Problem
    ... telephoned the office where the server was and asked her to re-boot the ... Once I saw the config of the VPN router there, I knew what to do on the ... on the remote site and see if they have the connection manager installed. ...
    (microsoft.public.windows.server.sbs)
  • Re: Please Help Site-To-Site without ISA
    ... You can configure more than one site to site VPN connection on the ... You set up a new demand-dial interface and configure a new site to ... public IP of the VPN server at the second site on the front. ... to router connection. ...
    (microsoft.public.windows.server.networking)
  • Re: vpn probl
    ... fact that you have ISA server at one end and not at the other. ... site to site link in ISA creates a file to configure the "answering" router. ... hub (as all other sites have a VPN link to the hub). ... > static routes redirecting the their needs. ...
    (microsoft.public.windows.server.networking)