RE: Remote Connection to SBS-2000

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Charles,

Thanks again for the reply ...

The LAT Table including the following:

10.0.0.0 ------> 10.255.255.255
172.16.0.0 ---> 172.31.255.255
192.168.0.0 --> 192.168.255.255
169.254.0.0 --> 169.254.255.255

May be I should also add the IP range assigned for the VPN Remote Users,
which is:

192.168.223.200 ---> 192.168.223.220

The strange thing is that I have limited the number of RAS Routing Ports to:

WAN MiniPort (PPTP) ................. 21
WAN MiniPort (L2TP) ................. 0

But whenever I restart, it resets itself back to the default of 128 Port for
each !!!

Appreciate your help and support ...

Reda

""Charles Yang [MSFT]"" wrote:

> Hi,
>
> Thanks for updates.
>
> It seems you have changed your SBS 2000 local area IP address. Just as I
> know, we need also to make sure that the ISA have been applied the setting
> for it. It seems the port 3389 is not open correctly for the remote
> desktop, but just as I know ISA 2000 have no configuration on the local
> network, so could you check if the LAT on the ISA server is correctly
> configured for the new IP range, if not all the traffic relate to RDP will
> blocked as the ISA server might consider the traffic comes from the
> internet, it will block the traffic then.
>
> You do not need to reinstall ISA 2000 now. We may need to check if your ISA
> is configured correctly.
>
> Thanks again for your efforts. Please post back the results. We may also
> need to gather the ISA log, you can check the log files on the following
> location:
>
> C:\Program Files\Microsoft ISA Server\ISALogs
>
> Please feel free to let me know, if you have any further concerns. I will
> be here waiting for your updates.
>
>
>
> Best regards,
>
> Charles Yang (MSFT)
>
> Microsoft CSS Online Newsgroup Support
>
> Get Secure! - www.microsoft.com/security
>
> ======================================================
> This newsgroup only focuses on SBS technical issues. If you have issues
> regarding other Microsoft products, you'd better post in the corresponding
> newsgroups so that they can be resolved in an efficient and timely manner.
> You can locate the newsgroup here:
> http://www.microsoft.com/communities/newsgroups/en-us/default.aspx
>
> When opening a new thread via the web interface, we recommend you check the
> "Notify me of replies" box to receive e-mail notifications when there are
> any updates in your thread. When responding to posts via your newsreader,
> please "Reply to Group" so that others may learn and benefit from your
> issue.
>
> Microsoft engineers can only focus on one issue per thread. Although we
> provide other information for your reference, we recommend you post
> different incidents in different threads to keep the thread clean. In doing
> so, it will ensure your issues are resolved in a timely manner.
>
> For urgent issues, you may want to contact Microsoft CSS directly. Please
> check http://support.microsoft.com for regional support phone numbers.
>
> Any input or comments in this thread are highly appreciated.
> ======================================================
> This posting is provided "AS IS" with no warranties, and confers no rights.
>
>
> =====================================================
> When responding to posts, please "Reply to Group" via your newsreader so
> that others may learn and benefit from your issue.
> =====================================================
>
> This posting is provided "AS IS" with no warranties, and confers no rights.
>
> --------------------
> | Thread-Topic: Remote Connection to SBS-2000
> | thread-index: AcXuak/jn7n8BTUWQLKCsrv+sMR26Q==
> | X-WBNR-Posting-Host: 69.234.184.85
> | From: "=?Utf-8?B?UmVkYSBIYW5uYQ==?=" <RedaHanna@xxxxxxxxxxxxxxxxxxxxxxxxx>
> | References: <EA173014-E327-496E-81B8-C8D2451CF639@xxxxxxxxxxxxx>
> <GNWwUqA7FHA.2132@xxxxxxxxxxxxxxxxxxxxx>
> <F5ACD566-5C77-4C1D-B681-E41A7ED5FFC0@xxxxxxxxxxxxx>
> <euBklgj7FHA.568@xxxxxxxxxxxxxxxxxxxxx>
> | Subject: RE: Remote Connection to SBS-2000
> | Date: Sun, 20 Nov 2005 23:08:02 -0800
> | Lines: 311
> | Message-ID: <C3947B10-6DE1-4B7B-B9B0-9D9976DAEDAC@xxxxxxxxxxxxx>
> | MIME-Version: 1.0
> | Content-Type: text/plain;
> | charset="Utf-8"
> | Content-Transfer-Encoding: 7bit
> | X-Newsreader: Microsoft CDO for Windows 2000
> | Content-Class: urn:content-classes:message
> | Importance: normal
> | Priority: normal
> | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
> | Newsgroups: microsoft.public.windows.server.sbs
> | NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.2.250
> | Path: TK2MSFTNGXA02.phx.gbl!TK2MSFTNGXA03.phx.gbl
> | Xref: TK2MSFTNGXA02.phx.gbl microsoft.public.windows.server.sbs:224135
> | X-Tomcat-NG: microsoft.public.windows.server.sbs
> |
> | Charles,
> |
> | When I reboot the SBS-2000 and do not login locally and try to login
> using
> | RDP after creating a VPN connection, it doen't work ...
> |
> | Also, I have tried to telnet <Server IP> 3389 after VPN the Server, but I
> | get the error:
> | Connecting to 192.168.222.7 ... Could not open connection to the host, on
> | port 3389: Connect failed
> |
> | So, I need to physically go tomorrow morning to that site, login locally
> to
> | the SBS-2000, and run Internet Connection Wizard to refresh the ISA
> settings
> | and then I will be able to RDP the SBS-2000 both from the LAN or after
> | VPN'ing the Server ...
> |
> | Just for your information, our LAN was initially set to 192.168.1.xxx /
> | 255.255.255.0 and about 2 months ago, I have changed it to
> 192.168.222.xxx /
> | 255.255.255.0 ... Is there any hidden setting within the ISA Server that
> I
> | need to change too ???
> |
> | Do you think I should uninstall the ISA 2000 Server that is on the
> SBS-2000
> | and then reinstall it again ???
> |
> | Thanks for your help and support and looking forward to your response ...
> |
> | Reda
> |
> |
> | ""Charles Yang [MSFT]"" wrote:
> |
> | > Hi,
> | >
> | > It seems the RDP is worked now.
> | >
> | > Considering the situation you described, it seems the services is not
> | > initialized fully when you try to RDP to SBS 2000.
> | >
> | > So could you tell us if you have reboot the SBS 2000 and then do not
> logon
> | > SBS 2000 locally, can you telnet to SBS 2000 from remote sites, is it
> | > possible for you to RDP to SBS 2000?
> | >
> | > Also do you have router installed on your SBS 2000? As I know, ISA
> setting
> | > will not be changed after you reboot SBS 2000, it seems the ISA setting
> is
> | > not applied correctly.
> | >
> | > If possible, please also do the tests above and paste the information
> so
> | > that we can identify the root issue, please also check the event view
> to
> | > see if there are any error message related to ISA.
> | >
> | > Thanks again for your efforts.
> | >
> | >
> | >
> | > Best regards,
> | >
> | > Charles Yang (MSFT)
> | >
> | > Microsoft CSS Online Newsgroup Support
> | >
> | > Get Secure! - www.microsoft.com/security
> | >
> | > ======================================================
> | > This newsgroup only focuses on SBS technical issues. If you have issues
> | > regarding other Microsoft products, you'd better post in the
> corresponding
> | > newsgroups so that they can be resolved in an efficient and timely
> manner.
> | > You can locate the newsgroup here:
> | > http://www.microsoft.com/communities/newsgroups/en-us/default.aspx
> | >
> | > When opening a new thread via the web interface, we recommend you check
> the
> | > "Notify me of replies" box to receive e-mail notifications when there
> are
> | > any updates in your thread. When responding to posts via your
> newsreader,
> | > please "Reply to Group" so that others may learn and benefit from your
> | > issue.
> | >
> | > Microsoft engineers can only focus on one issue per thread. Although we
> | > provide other information for your reference, we recommend you post
> | > different incidents in different threads to keep the thread clean. In
> doing
> | > so, it will ensure your issues are resolved in a timely manner.
> | >
> | > For urgent issues, you may want to contact Microsoft CSS directly.
> Please
> | > check http://support.microsoft.com for regional support phone numbers.
> | >
> | > Any input or comments in this thread are highly appreciated.
> | > ======================================================
> | > This posting is provided "AS IS" with no warranties, and confers no
> rights.
> | >
> | >
> | > =====================================================
> | > When responding to posts, please "Reply to Group" via your newsreader
> so
> | > that others may learn and benefit from your issue.
> | > =====================================================
> | >
> | > This posting is provided "AS IS" with no warranties, and confers no
> rights.
> | >
> | > --------------------
> | > | Thread-Topic: Remote Connection to SBS-2000
> | > | thread-index: AcXtXI6BN2f6nmEGT8Spp3E2wWt/uQ==
> | > | X-WBNR-Posting-Host: 69.104.68.25
> | > | From: "=?Utf-8?B?UmVkYSBIYW5uYQ==?="
> <RedaHanna@xxxxxxxxxxxxxxxxxxxxxxxxx>
> | > | References: <EA173014-E327-496E-81B8-C8D2451CF639@xxxxxxxxxxxxx>
> | > <GNWwUqA7FHA.2132@xxxxxxxxxxxxxxxxxxxxx>
> | > | Subject: RE: Remote Connection to SBS-2000
> | > | Date: Sat, 19 Nov 2005 14:57:03 -0800
> | > | Lines: 161
> | > | Message-ID: <F5ACD566-5C77-4C1D-B681-E41A7ED5FFC0@xxxxxxxxxxxxx>
> | > | MIME-Version: 1.0
> | > | Content-Type: text/plain;
> | > | charset="Utf-8"
> | > | Content-Transfer-Encoding: 7bit
> | > | X-Newsreader: Microsoft CDO for Windows 2000
> | > | Content-Class: urn:content-classes:message
> | > | Importance: normal
> | > | Priority: normal
> | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
> | > | Newsgroups: microsoft.public.windows.server.sbs
> | > | NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.2.250
> | > | Path: TK2MSFTNGXA02.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGXA03.phx.gbl
> | > | Xref: TK2MSFTNGXA02.phx.gbl microsoft.public.windows.server.sbs:223868
> | > | X-Tomcat-NG: microsoft.public.windows.server.sbs
> | > |
> | > | Charles,
> | > |
> | > | Thanks for the detailed troubleshooting procedure ...
> | > |
> | > | I have Telnet Port 3389 and it gave me the blank screen, then it is
> OK ...
> | > |
> | > | After a reboot and successful login on the SBS-2000, I can RDP the
> | > SBS-2000
> | > |
> | > | But, if I reboot and didn't login locally to the SBS-2000, I cannot
> RDP
> | > it ...
> | > |
> | > | I am not sure if it is related to the initialization of the Terminal
> | > | Services or has something to do with the ISA ...
> | > |
> | > | I also noticed that after I login to the SBS-2000 and run the
> Internet
> | > | Connection Wizard and reaply the ISA settings, I can RDP the SBS-2000
> ...
> | > |
> | > |
> | > | ""Charles Yang [MSFT]"" wrote:
> | > |
> | > | > HI Reda,
> | > | >
> | > | > Welcome to SBS newsgroup.
> | > | >
> | > | > Issue description:
> | > | > ==============
> | > | >
> | > | > I understand that you encountered problem when you RDP via VPN
> | > connections.
> | > | >
> | > | > Analyzing and suggestions:
> | > | > ===============
> | > | >
> | > | > Generally speaking, as you can access the SBS 2000 server within
> Lan
> | > via
> | > | > RDP session, it should be something block the RDP traffic. In order
> to
> | > | > narrow down the issue, please help perform the steps below:
> | > | >
> | > | > 1. To verify this, let us the telnet 3389 port to see if it is
> works.
> | > To
> | > | > do that, please follow the steps below:
> | > | >
> | > | > A. Open a Command Prompt window on the client.
> | > | > B. Type the following command:
> | > | >
> | > | > telnet <internal ip address of the SBS 2000 server> 3389
> | > | >
> | > | > Can you see the blank screen? If not, the traffic to remote 3389 is
> | > blocked.
> | > | >
> | > | > Please test it after VPN connection is established.
> | > | >
> | > | > 2. Please also check if you RDP to other internal client computer
> via
.



Relevant Pages

  • Re: Nagging Autorization issue for Companyweb after ISA04 install
    ... Check the companyweb CNAME entry in the DNS Server. ... Does the situation occur when you access companyweb from the ISA ... > 'Microsoft Firewall' service. ... > This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: Error 403 Forbidden
    ... the ISA log should be collect after 4 hours or more after ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... When responding to posts, please "Reply to Group" via your newsreader so ...
    (microsoft.public.windows.server.sbs)
  • Re: RWW - Cant login
    ... MVPs do not work for Microsoft ... Must be a difference between Standard and Premium and ISA. ... In the Microsoft Internet Security and Acceleration Server 2004 console, ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: IIS web config
    ... The 1 IP 1 Port listener is by design on ISA Server. ... 'Microsoft Firewall' service. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • RE: Add network connection fails
    ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... | place" in the network neighbourhood on a client. ... configure ISA server as your Proxy ...
    (microsoft.public.windows.server.sbs)