Re: ISA 2004 Blocks VPN Clients

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi Dan,

With SBS 2003, VPN access is configured through the Remote Access Wizard.
Have you run the Remote Access Wizard in the Server Management console?

Also, GRE 47 is not a port, but rather a protocol, and may need to be reset
in the router by resetting the VPN Passthrough option (or similarly worded
feature). On some routers, I 've had to disable VPN Passthrough, reboot
router, re-enable VPN Passthrough, then reset the forwarding for port 1723
to the external NIC.

--
Merv Porter [SBS-MVP]
============================

"DanEM" <DanEM@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:BA9051E4-AD8F-47AC-94A8-C0F5E9C96742@xxxxxxxxxxxxxxxx
SBS 2003 w/ISA 2004 and 2 NICS 192.168.1.2 (external) 192.168.16.2
(internal). Ports 1723 and 47 forwarded to 192.168.1.2 in Linksys WRT54GX2
router.

I have run VPN setup in ISA and CEICW.

This VPN has worked in the past. When it has failed in the past,
restarting
the router, and re-running VPN setup and CEICW has fixed it. But not this
time.

When I try to connect to VPN from remote WinXP computer, ISA firewall on
server denies connection on port 1723. The rule that denies access is
'Allow
VPN Client traffic to ISA Server'. I can find no rule by this name.

Please help.
Dan


.



Relevant Pages

  • Re: VPN Advice...do I need a purchased static ip address on the external interface?
    ... >> Server then that server must have a been assigned a purchased static IP ... >> if I was to try and use Windows 2000 SBS as the server for the VPN, ... >> If I used a router instead then the router would have this purchased IP ... > supports dynamic dns, then users connect to the dynamic dns name and ...
    (comp.dcom.vpn)
  • Re: vpn probl
    ... not to vpn server, so when workstations needed to reply to the ping requests ... they were trying to respond though their gateway that was the adsl router ... static route 172.16.x..x pointing to vpn remote router in rras, ...
    (microsoft.public.windows.server.networking)
  • Re: Problem
    ... telephoned the office where the server was and asked her to re-boot the ... Once I saw the config of the VPN router there, I knew what to do on the ... on the remote site and see if they have the connection manager installed. ...
    (microsoft.public.windows.server.sbs)
  • Re: Please Help Site-To-Site without ISA
    ... You can configure more than one site to site VPN connection on the ... You set up a new demand-dial interface and configure a new site to ... public IP of the VPN server at the second site on the front. ... to router connection. ...
    (microsoft.public.windows.server.networking)
  • Re: vpn probl
    ... fact that you have ISA server at one end and not at the other. ... site to site link in ISA creates a file to configure the "answering" router. ... hub (as all other sites have a VPN link to the hub). ... > static routes redirecting the their needs. ...
    (microsoft.public.windows.server.networking)