Re: vpn connection communication



no Marina, I think you're missing the point.

It doesn't matter what we do in AD to make it aware of whatever, and the
difference in behaviour between the PC acting as a LAN client (where it can
access things) and a VPN client (where it can't) is key to the whole
problem.

We have:

VPN client
|
|
Internet -- Remote Site (also VPN)
|
|
SBS
|
|
LAN

SBS knows how to route from LAN to Remote Site and also from RRAS to remote,
so when VPN Client connects the VPN is capable of routing to Remote Site,
however VPN Client itself (probably) does not have that routing information
itself.

The output of 'roue print' while VPN Client is connected would probably
confirm the issue.

"Marina Roos [SBS-MVP]" <marina@xxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:ulf2g7%230HHA.4824@xxxxxxxxxxxxxxxxxxxxxxx
Hi SG,

You are missing the point here. Seanny is using a Demand Dial with RRAS on
the remote DC to ISA 2004 on SBS. As that means there are 2 sites in Sites
and Services, it also means you have to add the subnets of both sites and
assign them to the proper site. Because Seanny is using a static IP pool
for
his vpn clients, that is in another IP range, that range will need to be
added to Sites and Services to the proper site. I suspect he will have
some
events in his logs that will point him to that.

--
Regards,

Marina Roos
Microsoft SBS-MVP
One of the Magical M&M's
www.smallbizserver.net
Take part in SBS forum:
http://www.smallbizserver.net/Default.aspx?tabid=53

"SuperGumby [SBS MVP]" <not@xxxxxxxxxxx> schreef in bericht
news:%233b43m90HHA.4928@xxxxxxxxxxxxxxxxxxxxxxx
in the RRAS connectoid, have you turned off 'use default gateway'?
probably
done to allow direct internet access while VPN'd in.

If so the VPN PC doesn't know how to route to the remote site.

I doubt it has anything to do with 'sites and services'.

"seany" <seany.2ueezi@xxxxxxxxxxxxx> wrote in message
news:seany.2ueezi@xxxxxxxxxxxxxxxx

Hi,

I am having a problem with a branch office deployment scenario. This
is what I have set up:

Main office server
SBS 2003 R2, 2 nics
ISA sp3 Installed
Internal subnet: 198.168.1.x

Branch office server
Win2003 standard R2, 1 nic
Linksys router
Internal subnet: 192.168.5.x

The persistent VPN connection between the two servers was set up in
RRAS (as per a web-article I read) with rules in ISA to allow the
communication. When I'm connected to the main office subnet directly
everything works as expected. I can ping the branch office machines
and map network drives. When connected via VPN I can't.

Is it possible to allow a client who has a VPN connection to the main
office server access resources on the branch office server? Do I have
to add a static route in RRAS between the two VPN IP address pools or
is the problem in ISA?


Any help would be greatly appreciated.

cheers,

Sean


--
seany
------------------------------------------------------------------------
seany's Profile: http://forums.techarena.in/member.php?userid=28514
View this thread: http://forums.techarena.in/showthread.php?t=791134

http://forums.techarena.in







.



Relevant Pages

  • RE: Putting new Active Directory machine at remote office
    ... You have to place the domain controller at the branch office into a separate ... and this will speed up login times and authentication requests. ... here over a IPSEC VPN tunnel. ... I'd like to put a server at the remote site to allow users to login/ ...
    (microsoft.public.windows.server.active_directory)
  • Re: Client-side IPSec VPN
    ... Logged a call with Sonicwall and everything. ... I ended up passing through pptp vpn at the remote site instead. ... > One user needs to access a customer's VPN using SonicWall VPN Client. ...
    (microsoft.public.windows.server.sbs)
  • Re: Asking for Assistabce w/ Cisco VPN Client
    ... I went to the remote site to replace the PCs and realized the people using VPN, Remote Desktop will not be able to ... Is there any way I configure CISCO VPN Client & Remote Desktop so the users at the remote site can print at the remote site data they are viewing that is on the main site. ...
    (microsoft.public.windowsxp.general)
  • RE: OT: How to configure with VPN endpoints outside ISA2K4?
    ... I understand that you want to setup a branch office ... the easiest method is to setup site to site VPN for your ... Connecting a Remote Office to a Small Business Server 2000 Network ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN
    ... Run CEICW on SBS ... You have to rerun the CEICW to make sure your SBS 2003 server have right ... Click Next, click Enable Remote Access, click to select the VPN Access ... Please ensure the VPN client computers' DNS and WINS are your SBS ...
    (microsoft.public.windows.server.sbs)