RE: IPSec VPN Problems



Hi Steve:
Thanks for posting here.

>From the description, I understand that you have deployed a
router-to-router IPSec VPN tunnel between the main office and remote
office. Everything was working fine at the beginning. Recently the XP
client at the remote office side cannot access the SQL Server on the SBS
Server at the main office side. Your network diagram looks like the
following:

Internal clients-SBS Server-Router---Internet---Router-Remote XP clients

If I have misunderstood, please kindly correct me and provide me the
accurate one.

Before we go any further, could you tell me if the ISA Server 2004 is
installed on the SBS Box? I would like to suggest you first re-run the
CEICW Wizard, the wizard can help us configure the networking settings for
a SBS server. You may refer to this KB article to complete the wizard:

825763 How to configure Internet access in Windows Small Business Server
2003
http://support.microsoft.com/?id=825763

If the problem persists after we re-run the wizard, please help me gather
the following information in order to narrow down this issue:
1. If you directly establish a PPTP connection (using the windows built-in
VPN connection) from the XP Client at the remote office side to the
external IP address of the SBS Server, will you be able to access the SQL
Server?

2. Once the IPSec tunnel was established, try establishing a second PPTP
connection to the SBS Server (go through the IPSec VPN tunnel as you
mentioned), will you be able to access the SQL Server?

3. Once the IPSec tunnel was established, from the remote XP client, can
you ping the external IP address of the SBS Server?

4. How does the SQL application work? Which way does the application use to
connect to the SQL Server on the main office side, IP address or computer
name?

5. Please type ipconfig/all on both the remote XP client and the SBS
Server, and post the output to me in the reply.

6. Is there any third-party software installed on the SBS Server or XP
client? If so, please temporarily disable them and see if the problem can
be resolved. If possible, please also disable the Windows Firewall on the
remote client.

Thank you for your time and cooperation. Please feel free to let me know if
you have any questions or concerns.

Have a nice day! :)

Best Regards
Edward Tian(MSFT)
Microsoft CSS Online Newsgroup Support

Get Secure! - www.microsoft.com/security
======================================================
This newsgroup only focuses on SBS technical issues. If you have issues
regarding other Microsoft products, you'd better post in the corresponding
newsgroups so that they can be resolved in an efficient and timely manner.
You can locate the newsgroup here:
http://www.microsoft.com/communities/newsgroups/en-us/default.aspx

When opening a new thread via the web interface, we recommend you check the
"Notify me of replies" box to receive e-mail notifications when there are
any updates in your thread. When responding to posts via your newsreader,
please "Reply to Group" so that others may learn and benefit from your
issue.

Microsoft engineers can only focus on one issue per thread. Although we
provide other information for your reference, we recommend you post
different incidents in different threads to keep the thread clean. In doing
so, it will ensure your issues are resolved in a timely manner.

For urgent issues, you may want to contact Microsoft CSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

Any input or comments in this thread are highly appreciated.
======================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
| Thread-Topic: IPSec VPN Problems
| thread-index: AcXj2DsFkSc2t8oDRe2BbxbelYfKnw==
| X-WBNR-Posting-Host: 207.191.78.42
| From: "=?Utf-8?B?U3RldmUgSGFwcA==?=" <SteveHapp@xxxxxxxxxxxxxxxxxxxxxxxxx>
| Subject: IPSec VPN Problems
| Date: Mon, 7 Nov 2005 12:17:09 -0800
| Lines: 26
| Message-ID: <5E8319D7-EFFA-4C16-9AE8-135D9EFEB342@xxxxxxxxxxxxx>
| MIME-Version: 1.0
| Content-Type: text/plain;
| charset="Utf-8"
| Content-Transfer-Encoding: 7bit
| X-Newsreader: Microsoft CDO for Windows 2000
| Content-Class: urn:content-classes:message
| Importance: normal
| Priority: normal
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
| Newsgroups: microsoft.public.windows.server.sbs
| NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.2.250
| Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGXA03.phx.gbl
| Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.windows.server.sbs:168370
| X-Tomcat-NG: microsoft.public.windows.server.sbs
|
| Hello:
|
| Is anyone suddenly experiencing problems with their router to router VPN?

| It was working fine at the beginning of last week, but suddenly I can't
pull
| up backend SQL data from the SQL server over the VPN.
|
| I have a W2003 SBS server running SQL Server and Exchange behind a
| Watchguard Firebox Edge x15 at our main office.
| I have a remote office with no server and 4 XP Pro PCs behind a
Watchguard
| Firebox Edge x5.
| I have an IPSec VPN running from router to router.
|
| The remote office PCs use a front end SQL application accessing the
backend
| data on the SQL server in the main office.
|
| A "soft" PPTP VPN setup on the remote XP boxes to the external IP of the
| main office Watchguard (passed through to the W2003 server) works.
| A "soft" PPTP VPN setup on the remote XP boxes to the INTERNAL IP of the
| W2003 server (meaning this VPN is going through the IPSec VPN) works.
|
| After hours with Watchguard technicians, they have determined it is a
| Windows problem.
|
| Any help or suggestions would be appreciated!
|
| Steve
|

.



Relevant Pages

  • RE: VPN (RRAS) ON SBS 2003 SP1
    ... SBS Server via VPN cannot access other internal servers/clients, ... "Remote Access Wizard": ... mark) on both the SBS Server and the remote client, ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote office logon script - Long Delay
    ... in the logs and replication is occuring regularly and without error. ... I do not have WINS configured for the remote site, ... GC/AD server with DNS and DHCP for it's area. ... Intersite Messagind service on the SBS server to "Startup: ...
    (microsoft.public.windows.server.sbs)
  • RE: Access Denied when running RSoP
    ... The local COM+ snap-in will not be able to connect to remote servers to ... regarding SBS server in the future, please feel free to post back to this ... Microsoft CSS Online Newsgroup Support ... >> even to a Windows 2003 Terminal Server, but not to the SBS Server (again ...
    (microsoft.public.windows.server.sbs)
  • Re: Rmote Access problem
    ... The client could not connect to the remote computer. ... Remote connections ... Re-running CEICW on SBS server: ...
    (microsoft.public.windows.server.sbs)
  • SecurityFocus Microsoft Newsletter #152
    ... MICROSOFT VULNERABILITY SUMMARY ... Real Networks Helix Universal Server Remote Buffer Overflow ... ... NEW PRODUCTS FOR MICROSOFT PLATFORMS ...
    (Focus-Microsoft)