• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

PPTP IP pool cant talk to Internal Network

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> Network Infrastructure >> PPTP IP pool cant talk to Internal Network Page: [1] 2   next >   >>
Login
Message << Older Topic   Newer Topic >>
PPTP IP pool cant talk to Internal Network - 24.Sep.2009 9:16:31 AM   
Thirst4Knowledge

 

Posts: 15
Joined: 24.Sep.2009
Status: offline
Hi,

I have setup pptp vpn to an ISA server with a one NIC setup , behind a firewal. Ultimatley I want the clients to have access to a specif IP address ONLY (MS Exchange server).

The clients are able to succesfully conect via pptp onto the ISA server but they are not able to ping anything on the internal network

My question is this:

because the IP address pool I have allocated is on a different Private network address where would I need to set-up the routing so that the The pptp private address pool can talk to this specific server...

1)is it via ISA itself or
2)Via another rule on the Firewall to allow traffic to the exchange server via the PPTP public address

Im assuming ISA because there is already a static NAT and an ACL rule to allow GRE 1723 to on our firewall, to speak to our ISA servers private address.


Basically I want the pptp VPN pool of 10.10.10.0 255.255.255.0 to be able to talk my internal LAN 192.168.249.0 255.255.255.0

If the above is possible then:


I want it to be really granular so that pptp users can only communicate with a single IP address on the 192.168.249.0 network which will be my mail server

TIA
T4k

< Message edited by Thirst4Knowledge -- 24.Sep.2009 9:18:00 AM >
Post #: 1
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 12:15:25 PM   
pwindell

 

Posts: 2228
Joined: 12.Apr.2004
From: Taylorville, IL
Status: offline
Ping is irrelevant.  Ping only tests ping,..it does not test anything else.  Allowing ping does not automatically allow anything else,....allowing anything else does not automatically allow Ping.  When Ping works it doesn't mean anything else will,...when the desired traffic does works, ping still will not work,...unless it is allowed separately or in addition to.

Did you create the proper access Rule?  The VPN Clients Network is automatic and you cannot add or remove addresses from it. When a VPN Client connects they become part of that network regaurdless of what IP# they received.  So the Access Rule would be:

From: VPN Clients Network
To: <whatever>
Protocol:<whatever>
Users:<whatever>

_____________________________

Phillip Windell

(in reply to Thirst4Knowledge)
Post #: 2
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 12:39:50 PM   
Thirst4Knowledge

 

Posts: 15
Joined: 24.Sep.2009
Status: offline
Ok forget ping, no other IP protcols can get to the internal network from a pptp client.

I have a rule:

Allow Traffic----(pptp server) From anywhare to 192.168.x.x(pptp sever IP address) Network external

(in reply to pwindell)
Post #: 3
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 12:58:10 PM   
pwindell

 

Posts: 2228
Joined: 12.Apr.2004
From: Taylorville, IL
Status: offline
From: VPN Clients Network
To: Internal Network 
Protocol:<whatever>
Users:<whatever>


The position in the Rule List matters.  Don't have the rule below other Rules that may conflict with it.

_____________________________

Phillip Windell

(in reply to Thirst4Knowledge)
Post #: 4
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 1:46:14 PM   
Thirst4Knowledge

 

Posts: 15
Joined: 24.Sep.2009
Status: offline
Hi I have:

From: VPN Clients Network
To: Internal Network
Protocol:<whatever>
Users:<whatever>

Its placed at the top (below the local host rule which cant be moved)

(in reply to pwindell)
Post #: 5
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 1:51:38 PM   
pwindell

 

Posts: 2228
Joined: 12.Apr.2004
From: Taylorville, IL
Status: offline
I don't know what to make of it then,...but that rule is correct.

_____________________________

Phillip Windell

(in reply to Thirst4Knowledge)
Post #: 6
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 2:16:34 PM   
Thirst4Knowledge

 

Posts: 15
Joined: 24.Sep.2009
Status: offline
Its got to a point here I have lost track of what I have done.

Im even thinking that Im using routing and remote access....

or dose that get setup automaticaly by doing the ISA stuff ?

(in reply to pwindell)
Post #: 7
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 2:25:04 PM   
pwindell

 

Posts: 2228
Joined: 12.Apr.2004
From: Taylorville, IL
Status: offline
It gets setup by ISA when you configure ISA

It gets messed up when you do it from the RRAS MMC outside of  ISA.

But sometimes ISA will over-ride what you do and put RRAS back as it belongs.

There are a few things you can do from the RRAS MMC that ISA doesn't care about, but it is best to stay away from it.

_____________________________

Phillip Windell

(in reply to Thirst4Knowledge)
Post #: 8
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 2:35:06 PM   
Thirst4Knowledge

 

Posts: 15
Joined: 24.Sep.2009
Status: offline
You would think it would be a matter of:

"ISA let Network A talk to network C"

(in reply to pwindell)
Post #: 9
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 2:35:48 PM   
pwindell

 

Posts: 2228
Joined: 12.Apr.2004
From: Taylorville, IL
Status: offline
You could go into the ISA MMC in the VPN Node and Disable VPN Client Access.

Let it sit for a while.

Then come back and Enable it again.

It should unconfigure then reconfigure RRAS when it does this.

_____________________________

Phillip Windell

(in reply to pwindell)
Post #: 10
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 2:42:44 PM   
Thirst4Knowledge

 

Posts: 15
Joined: 24.Sep.2009
Status: offline
THe Networks tab under the VPN clients its saying that "no IP addresses are assigned to this network"

Is this just a default built in thing...

(in reply to Thirst4Knowledge)
Post #: 11
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 2:44:29 PM   
pwindell

 

Posts: 2228
Joined: 12.Apr.2004
From: Taylorville, IL
Status: offline
quote:

You would think it would be a matter of:

"ISA let Network A talk to network C"


No, I wouldn't think that.

The VPN Users Network in ISA is a Dynamic Network that changes and adjusts on the fly when VPN User "dial in".

Then the Access Rules that control the traffic consider the Protocol being used, the content of the payload of the protocol (in some protocols), the Application Filter required (with protocols that use them), what the user account is, and even the time of day.

_____________________________

Phillip Windell

(in reply to Thirst4Knowledge)
Post #: 12
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 2:46:47 PM   
pwindell

 

Posts: 2228
Joined: 12.Apr.2004
From: Taylorville, IL
Status: offline
quote:

THe Networks tab under the VPN clients its saying that "no IP addresses are assigned to this network"

Is this just a default built in thing...


Supposed to be that way. 
The External Network, Localhost, and the VPN Quarentine Network is the same way.

_____________________________

Phillip Windell

(in reply to pwindell)
Post #: 13
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 2:58:49 PM   
Thirst4Knowledge

 

Posts: 15
Joined: 24.Sep.2009
Status: offline
Is it normal to have Access to local only on the laptop using pptp (WAN miniport)

(in reply to pwindell)
Post #: 14
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 3:10:27 PM   
Thirst4Knowledge

 

Posts: 15
Joined: 24.Sep.2009
Status: offline
The ISA server can ping the pptp client 10.10.10.2
But the pptp client cant communicate with the ISA server like RDP for example...

if that helps

(in reply to Thirst4Knowledge)
Post #: 15
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 3:16:30 PM   
Thirst4Knowledge

 

Posts: 15
Joined: 24.Sep.2009
Status: offline
ALso the ISA server is pointing to servers on another network for WINS...

could this be an issue...

I noticed that the pptp connection was getting these wins settings as well

(in reply to Thirst4Knowledge)
Post #: 16
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 3:17:15 PM   
pwindell

 

Posts: 2228
Joined: 12.Apr.2004
From: Taylorville, IL
Status: offline
You have some kind of mess going on with your Access Rules.  I'm tired of blindly shooting in the dark. There is nothing I can do with that. You are the only one who knows (and can see) what you have sitting in front of you.

These articles will explain everything you need to know about access rules.  ISA2004 and 2006 work the same way.

Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

_____________________________

Phillip Windell

(in reply to Thirst4Knowledge)
Post #: 17
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 3:25:33 PM   
Thirst4Knowledge

 

Posts: 15
Joined: 24.Sep.2009
Status: offline
" I'm tired of blindly shooting in the dark"

Trust me that makes 2 of us :/

(in reply to pwindell)
Post #: 18
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 3:29:45 PM   
Thirst4Knowledge

 

Posts: 15
Joined: 24.Sep.2009
Status: offline
Just as a note its confusing when theres one NIC and finding out where internal and external are refferenced.

(in reply to Thirst4Knowledge)
Post #: 19
RE: PPTP IP pool cant talk to Internal Network - 24.Sep.2009 3:33:16 PM   
pwindell

 

Posts: 2228
Joined: 12.Apr.2004
From: Taylorville, IL
Status: offline
The VPN Client must also receive the proper DNS (and maybe WINS) IP# for the LAN or they will not resolve names on the LAN properly to be able to communicate, nor will they autheticate to resources if they don't know what and where the DC is.  They need all the same things that the other workstations on the LAN need.

This of course means the the Access Rule(s) they use must allow the DNS protocol in addition to whatever other protocols they need.

_____________________________

Phillip Windell

(in reply to Thirst4Knowledge)
Post #: 20

Page:   [1] 2   next >   >> << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> Network Infrastructure >> PPTP IP pool cant talk to Internal Network Page: [1] 2   next >   >>
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts