RE: VPN with SBS 2003 (not R2) and DSL (Part Two)



Hello Customer,

Thank you for posting here.

According to your description, I would like to do a summary on your
question:

SBS 2003 with 1 NIC (if you install other NIC on SBS, please disable it)
Before the SBS, there is a DSL router
You ran the CEICW and Remote Access Wizard, then use Connect to Small
Business Server on remote client to establish VPN connection to SBS
But the VPN connection will disconnect after 3m 29s later.

If I have misunderstood the problem, please don't hesitate to let me know.

Before we go any further, please let me know the following information so
that we can understand your situation more clearly.

1. Do you install ISA server 2004 on your SBS?

2. Do you have static public IP address on your DSL router?

3. Do you get any event error about VPN on remote client or SBS?

4. You mentioned "3m: 29s later the connection is severed", does this issue
happen exact at 3m 29s later? Does this issue happen every time? What is
the "severed" mean?

5. Please try to change another ISP on remote client side, and change to
use another computer to establish the VPN connection, does this issue can
be reproduced?

6. Test the VPN connection from inside of the SBS network, will the problem
be reproduced?

Note: This test will bypass the DSL router.

Manually create a VPN connection on the internal client through the
following KB article:
How to configure a VPN connection to your corporate network in Windows XP
Professional
http://support.microsoft.com/?id=305550

Note: The VPN server IP is the internal IP address of the SBS Server

7. Run command "ipconfig /all > c:\ipconfig_sbs.txt" and "route print >
c:\route_sbs.txt" on SBS when the VPN connection established, send the
files c:\ipconfig_sbs.txt and c:\route_sbs.txt to me at
v-terliu@xxxxxxxxxxxxx

8. Run command "ipconfig /all > c:\ipconfig_client.txt" and "route print >
c:\route_client.txt" on remote client when the VPN connection established,
send the files c:\ipconfig_client.txt and c:\route_client.txt to me at
v-terliu@xxxxxxxxxxxxx

I appreciate your time and look forward to hearing from you.

Thanks and have a nice day!

Best regards,

Terence Liu(MSFT)

Microsoft CSS Online Newsgroup Support

Get Secure! - www.microsoft.com/security

=====================================================
This newsgroup only focuses on SBS technical issues. If you have issues
regarding other Microsoft products, you'd better post in the corresponding
newsgroups so that they can be resolved in an efficient and timely manner.
You can locate the newsgroup here:
http://www.microsoft.com/communities/newsgroups/en-us/default.aspx

When opening a new thread via the web interface, we recommend you check the
"Notify me of replies" box to receive e-mail notifications when there are
any updates in your thread. When responding to posts via your newsreader,
please "Reply to Group" so that others may learn and benefit from your
issue.

Microsoft engineers can only focus on one issue per thread. Although we
provide other information for your reference, we recommend you post
different incidents in different threads to keep the thread clean. In doing
so, it will ensure your issues are resolved in a timely manner.

For urgent issues, you may want to contact Microsoft CSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

Any input or comments in this thread are highly appreciated.
=====================================================

This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
| From: DrewYK <drew_cushnir@xxxxxxxxxxx>
| Newsgroups: microsoft.public.windows.server.sbs
| Subject: VPN with SBS 2003 (not R2) and DSL (Part Two)
| Date: Wed, 06 Jun 2007 16:48:37 -0700
| Organization: http://groups.google.com
| Lines: 104
| Message-ID: <1181173717.364215.281790@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>
| NNTP-Posting-Host: 66.112.33.171
| Mime-Version: 1.0
| Content-Type: text/plain; charset="iso-8859-1"
| X-Trace: posting.google.com 1181173718 29780 127.0.0.1 (6 Jun 2007
23:48:38 GMT)
| X-Complaints-To: groups-abuse@xxxxxxxxxx
| NNTP-Posting-Date: Wed, 6 Jun 2007 23:48:38 +0000 (UTC)
| User-Agent: G2/1.0
| X-HTTP-UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US;
rv:1.8.1.4) Gecko/20070515 Firefox/2.0.0.4,gzip(gfe),gzip(gfe)
| Complaints-To: groups-abuse@xxxxxxxxxx
| Injection-Info: q19g2000prn.googlegroups.com; posting-host=66.112.33.171;
| posting-account=AqXOmQ0AAADGnNTeSkBQwfHoUTH4zzYO
| Path:
TK2MSFTNGHUB02.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTFEEDS01.phx.gbl!newsfeed.
cw.net!cw.net!news-FFM2.ecrc.de!syros.belnet.be!news.belnet.be!out02a.usenet
server.com!news.usenetserver.com!in02.usenetserver.com!news.usenetserver.com
!postnews.google.com!q19g2000prn.googlegroups.com!not-for-mail
| Xref: TK2MSFTNGHUB02.phx.gbl microsoft.public.windows.server.sbs:42261
| X-Tomcat-NG: microsoft.public.windows.server.sbs
|
| For those who did not read my first attempt at this I have the
| following:
|
| 1 SBS2003 Server, with one NIC (Really two acting as one, see previous
| post for more information on this).
| 1 DSL Modem
| 1 Netgear managed switch - 10/100 with four 1Gb ports
| 1 Netgear unmanaged switch - 16 1Gb ports.
|
| The current layout is:
|
| [Managed switch]
| | \----[Win XP (Earth)]
| |
| [Unmanaged switch]
| | \ \ \---[SBS 3003 (Sol)]
| {inTRAnet} \ \
| | \ \---[File Server]
| [DSL modem] \
| | \---[Archiver]
| {inTERnet}
| |
| [Remote PC (Pluto)]
|
| I guess I am not quite done trying VPN after all.
|
| Some research has revealed the the service provider was not providing
| all the Up we were paying for, as a result of some "discussions" we
| now have an opportunity to try again.
|
| I can modify the network described above so it looks like this:
|
| [Managed switch]
| | \----[Win XP (Earth)]
| |
| [Unmanaged switch]
| | \ \ \---[SBS 3003 (Sol)]
| [Linksys \ \
| WRT54G] \ \---[File Server (Jupiter)]
| | \
| {inTRAnet} \---[Archiver (Saturn)]
| |
| [DSL modem]
| |
| {inTERnet}
| |
| [Remote PC (Pluto)]
|
|
| I located a Linksys router which can be used to route, instead of the
| modem, if that assists in the setup of the network.
|
| (By the way we are not restricted to either the DSL modem or the
| Linksys Router. I have convinced the company that it might be a good
| idea to replace them both and I found one item that would replace both
| of them:
| http://www.cdw.com/shop/products/default.aspx?EDC=531268
| This would give me this layout:
|
| [Managed switch]
| | \----[Win XP (Earth)]
| |
| [Unmanaged switch]
| | \ \ \---[SBS 3003 (Sol)]
| {inTRAnet} \ \
| | \ \---[File Server]
| [Netgear \
| DSL/Router] \---[Archiver]
| |
| {inTERnet}
| |
| [Remote PC (Pluto)]
|
| Any recommendations?)
|
|
| So, here we go again folks... What I would like to know is which way
| is the better way to setup the VPN, Linksys or no Linksys, and how do
| I do it? I ask that the steps you show me are something that someone
| who has yet to do this successfully can follow.
|
| Please keep in mind that after following both wizards on the server
| (Internet Connection Wizard and Remote Access Wizard) and running the
| "Connect to Small Business Server" we are asked for User/Pass/Domain,
| we enter them and are told that we have successfully connected. 3m:
| 29s later the connection is severed. This is still happening, even
| after the increase in up speed (from 320 to 608).
|
| But I do not understand statements like "the NIC IP range on the
| client side cannot be the same as the Intranet side but that the PPP
| IP on the client side will." Partly because we have tried it both
| Broadband and dialup and it makes no difference if the NIC is enabled
| or not, etc., and yes each time the PPP IP has been in the same range
| as the Internet addresses.
|
| I am sure that someone besides myself will benefit from this kind of
| guidance. I see requests for this sort of information in just about
| every SBS forum I have looked in, but most of the time the requests
| for help end in frustration from people either getting solutions that
| did not work for them or because they did not understand the answer.
|
| I have both of these handicaps right now. (Hey, at least I'm honest!
| LOL)
|
|

.



Relevant Pages

  • Re: SBS2K3 and 2003 term server problem since SP1 upgrade
    ... Please also help perform trace from the remote client to TS external NIC, ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: Problems with shares over remote connection
    ... from remote client to SBS, however you have encountered some issue when the ... remote client accesses Shares of SBS. ...
    (microsoft.public.windows.server.sbs)
  • RE: Remote Connection to SBS-2000
    ... But, if I reboot and didn't login locally to the SBS-2000, I cannot RDP it ... ... > Welcome to SBS newsgroup. ... the traffic to remote 3389 is blocked. ... > SBS 2000 and then establish the VPN connection to SBS 2000 then try to RDP ...
    (microsoft.public.windows.server.sbs)
  • RE: Need help setting up VPN access
    ... Thank you for posting to the SBS Newsgroup. ... I understand that you want to setup VPN connection for some remote clients. ... 2> For IP configuration on server and client workstations, ...
    (microsoft.public.windows.server.sbs)
  • RE: Remote Connection to SBS-2000
    ... Welcome to SBS newsgroup. ... the traffic to remote 3389 is blocked. ... SBS 2000 and then establish the VPN connection to SBS 2000 then try to RDP ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)