Re: VPN/Remote Access

Tech-Archive recommends: Speed Up your PC by fixing your registry



Joe:

I also forgot to mention, we are using two NICs on the server, internal and
external.

This firewall has its own vpn which (theoretically) will connect with the
provided client software from out on the internet. Do you think that would
work? Would that give users login access to the server since we'd be on the
"external" NIC?

I'd hate to try that, I'd much rather use the SBS VPN, but I gotta get this
thing working pronto.

--
sestratton
tallahassee, fl


"Joe" wrote:

Sestratton wrote:
We're running SBS 2003.

Initially we had installed ISA server, but we could never get it to work
with a screwy program (written by the local courthouse programmer) we have to
use for access to the local courthouse. We HAVE to have that access, so I
eventually had to uninstall the ISA and go with a hardware firewall.

We have always been able to access OWA from outside the office, but the VPN
and remote access have never worked. I have run and re-run the wizards to no
avail.

We've never really needed it before, so I didn't worry much about it. But
now we are REALLY needing VPN access and I can't get it to work. I'm sure
something is getting blocked at either the hardware firewall or the SBS
server.

When trying to access the VPN now, with the hardware firewall on I get an
Error 800.

Just to see what would happen, I turned off the harware firewall for a
couple minutes and tried again. Then I get an Error 721.

So the hardware firewall is part of the problem, but not the entire problem.

My question is, can you point me toward a troubleshooting methodology to
figure all this out?


There are two protocols which are used for the basic PPTP VPN, and they
need to be passed by the firewall and also directed to the SBS. So the
firewall needs to be configured to do this.

I can't be more specific, but the firewall will have a rule-making
system. The messages you need to redirect are TCP/IP port 1723 and
IP protocol 47, known as GRE. Some firewalls refer to both protocols
together as PPTP. They need to be accepted and passed to the SBS. If
you still have two NICs in the server, the redirection is to the
external one.

Error 800 usually means 'no way at all', and 721 usually means 'I got
the TCP/1723 connection but not GRE'. Try the firewall configuration
and come back with specific error messages if there is still trouble.

There are other possible problems, and users need to be members of the
Mobile Users group, so it's worth trying a VPN connection from one of
the LAN workstations. If that's OK, it's definitely a firewall or
client issue.

.



Relevant Pages

  • Re: CEICW fails at firewall config
    ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
    (microsoft.public.windows.server.sbs)
  • Re: More on Remote Desktop
    ... Chances are good, though, that he's already got VPN capabilities on his ... firewall to do it for $100. ... > server at home...or purchase additional/new hardware... ... >> my firewall makes the PPPoE connection to my ADSL ISP. ...
    (microsoft.public.windowsxp.network_web)
  • Re: More on Remote Desktop
    ... You realize the Remote Desktop data stream is encrypted the same as a PPTP VPN link... ... Unless of course the original poster wants to implement an L2TP/IPSec VPN server at home...or ... > firewall to get between your clients and server on your own LAN. ... > setup so that my firewall makes the PPPoE connection to my ADSL ISP. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Still cant connect to RWW or OWA remotely
    ... Re-running the CEICW, disabling the firewall, then re-running CEICW again, ... "Cannot find server or DNS Error". ... the DSL router 4-port switch. ... of the two NICs by clicking the Advanced tabs, ...
    (microsoft.public.windows.server.sbs)
  • Re: best network setup?
    ... An appliance based firewall is a separate dedicated device designed to do ... You can be sure that any changes to your server will not affect the ... If the SBS server is down for whatever reason all clients can still get ... SBS doesn't rely on two NICs to provide any services other than the ...
    (microsoft.public.windows.server.sbs)