• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Publish VPN ??????

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 Firewall] >> VPN >> Publish VPN ?????? Page: [1] 2   next >   >>
Login
Message << Older Topic   Newer Topic >>
Publish VPN ?????? - 26.May2002 7:38:00 AM   
AnthonyS

 

Posts: 9
Joined: 26.May2002
Status: offline
I have been working on this for days now ... I have to ISA server ... I want to publish a VPN server but everytime I try to connect to it i get an error 721: computer not responding ... I'm stuck ... I tried to put the VPN server on the ISA server its self but that kills the internet to my network .. I know my ISP allows everything because I have a VPN server at work and I can connect to that ... but I can't connect from work to here ....

this is my network

(works)

Client --- ISA Server --- Internet --- Linksys --- VPN Server (this is at work)

but not the other way

VPN Server --- ISA Server --- Internet --- Linksys --- VPN Server

I have port 1723 open and the PTPP check box checked

if someone could help with either problem the ISA Server losing internet if i enable RRAS or publishing the VPN server I would be great ful

Thanks
Post #: 1
RE: Publish VPN ?????? - 26.May2002 3:21:00 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Anthony,

to my knowledge you simply cann't publish a VPN server behind ISA. The ISA server must be the VPN endpoint. This is by design. [Big Grin]

I have different installations running with ISA as VPN endpoint for external VPN clients, enabled PPTP passthrough for outbound VPN access and have never see that ISA is losing Internet connectivity in such a configuration. How have you installed the VPN? Through the ISA VPN wizard?

Check out:
- http://www.isaserver.org/shinder/tutorials/configuring_ISA_for_inbound_VPN.htm
- http://www.isaserver.org/shinder/tips/tip_ping_pptp.htm

HTH,
Stefaan

(in reply to AnthonyS)
Post #: 2
RE: Publish VPN ?????? - 26.May2002 5:17:00 PM   
AnthonyS

 

Posts: 9
Joined: 26.May2002
Status: offline
Well The problem is not ISA server ... its RRAS ... this has always happened ... I install ISA server ... then if RRAS is turned on in anyway ... following the manuals online of just opening it up ... I lose internet connection everywheree on the network ... my ISA is in intergrated mode .... i want it to do secureNAT and VPN ... i thought that it was my windows install but so i fdisked and installed again ... but i lost it again ... when i was just using NAT with windows2000 I lose everything when I turned VPNs on

any ideas on what to try ????? [Confused]

(in reply to AnthonyS)
Post #: 3
RE: Publish VPN ?????? - 26.May2002 6:26:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Anthony,

Your problem isn't RRAS, its DNS. Check the DNS entries for your ISA Server on the DNS server, and you'll see some things which should explain your situation. The fast way to fix the problem is to disabled DDNS. There are slower ways, too [Big Grin]

HTH,
Tom

(in reply to AnthonyS)
Post #: 4
RE: Publish VPN ?????? - 26.May2002 7:11:00 PM   
AnthonyS

 

Posts: 9
Joined: 26.May2002
Status: offline
Thanks ...

I how do you do that ????

I found something that said go to all my computers and uncheck the "Register this connections address in DNS" but that didn't fix it .... I can't even ping when I turn on RRAS

Thanks again [Confused] [Confused]

(in reply to AnthonyS)
Post #: 5
RE: Publish VPN ?????? - 26.May2002 8:48:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Anthony,

Good to hear you got it working!

Check out:

Q289735
Q246804
Q292822

HTH,
Tom

(in reply to AnthonyS)
Post #: 6
RE: Publish VPN ?????? - 26.May2002 10:21:00 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Tom,

never thought it could be a DNS issue! [Frown]

If I understand it well, this issue can only occure if the RRAS is enabled on a domain controller, or I'm missing something?

HTH,
Stefaan

(in reply to AnthonyS)
Post #: 7
RE: Publish VPN ?????? - 27.May2002 12:17:00 AM   
AnthonyS

 

Posts: 9
Joined: 26.May2002
Status: offline
you know what ... it didn't work ... I was just so happy to see it up ... i didnt notice that the VPNs weren't on ... I still have the same problem .... need some more ideas :-(

The thing that is weird is that I can't even ping anyone on the internet ... even if i have an ip address

[ May 27, 2002, 12:19 AM: Message edited by: AnthonyS ]

(in reply to AnthonyS)
Post #: 8
RE: Publish VPN ?????? - 28.May2002 12:32:00 AM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Anthony,

I've never seen such a problem myself. However I'm very curious what is causing that behaviour. [Wink]

Because I don't know your installation, lets start with the beginning. I hope you have setup the ISA interfaces properly. Check out http://www.isaserver.org/pages/articles.asp?art=67 and pay attention to the binding order, default gateway, DNS and WINS settings. Oh, don't forget to check the LAT also.

Next, thoroughly test the name resolving from ISA server itself. This should work without any problem. Also check out Tom's hint: check the DNS entries for your ISA Server on the DNS server with and without an active VPN connection. Do you see any difference?

HTH,
Stefaan

(in reply to AnthonyS)
Post #: 9
RE: Publish VPN ?????? - 28.May2002 2:35:00 AM   
AnthonyS

 

Posts: 9
Joined: 26.May2002
Status: offline
Well.... I redid everything ... fresh 2k install all updates fresh ISA install SP1 and the same thing ... nothing weird is going on in DNS ... and I'm stuck I almost think its my network card for some reason so I'm going to get another tomorrow ... but I'm stuck .... any more idea ... i would love them ... thanks again everyone

(in reply to AnthonyS)
Post #: 10
RE: Publish VPN ?????? - 28.May2002 6:12:00 AM   
AnthonyS

 

Posts: 9
Joined: 26.May2002
Status: offline
OK ... everyone I HAVE the answer ...

for some reason ... and right now i don't care ... when VPN (RRAS) was enabled ... it erased the 0.0.0.0 entry in the routing list ... this as we know is the default gateway ... meaning that i can't connect to anyone out side my subnet ... which answers all the problems ... now how to fix that ... well thats simply ... i just added a 0.0.0.0 static route in RRAS

THANK YOU for everyones help
[Smile] [Wink] [Smile] [Wink]

(in reply to AnthonyS)
Post #: 11
RE: Publish VPN ?????? - 28.May2002 9:50:00 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Anthony,

wow... very good! I wonder why RRAS is doing such a dirty thing only on some ISA installations?

Thanks,
Stefaan

(in reply to AnthonyS)
Post #: 12
RE: Publish VPN ?????? - 29.May2002 8:36:00 PM   
amurrey

 

Posts: 13
Joined: 20.May2002
From: Indianapolis
Status: offline
Good Job! [Cool]

(in reply to AnthonyS)
Post #: 13
RE: Publish VPN ?????? - 3.Jun.2002 2:58:00 AM   
shawnw

 

Posts: 12
Joined: 26.Sep.2001
From: Portland OR 97209
Status: offline
Could you print out exactly what I am supposed to add to the routing table as in the destination netorwk and the other fields

Thanks

(in reply to AnthonyS)
Post #: 14
RE: Publish VPN ?????? - 1.Nov.2002 3:00:00 PM   
jmargel

 

Posts: 72
Joined: 3.Apr.2002
Status: offline
This maybe close to what my problem is, but not sure.. I have internet connection for like 5 mins, then shuts off for 5 mins, then comes back (its a cycle) I hope tom answers my other post as well. For this static route the 209.50.143.193 is the external IP of my NIC on the firewall, and the other 209.xxx.xxx.xxx address is the address of my external switch where my ISA plugs into. Is this right?


(in reply to AnthonyS)
Post #: 15
RE: Publish VPN ?????? - 1.Nov.2002 5:56:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hey guys,

I look like part of the problem is that there are two external interfaces. Maybe that's the issue?

Thanks!
Tom

(in reply to AnthonyS)
Post #: 16
RE: Publish VPN ?????? - 4.Nov.2002 9:35:00 PM   
jmargel

 

Posts: 72
Joined: 3.Apr.2002
Status: offline
Nah.. I deleted the one & still same result. I disabled the server and re-enabled.. but still.. no go.

Ugh..

(in reply to AnthonyS)
Post #: 17
RE: Publish VPN ?????? - 5.Nov.2002 6:21:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi J,

Win2k VPN config is so easy, its got to be a very small detail that's left out or not configured. Probably just a matter of getting another pair of eyes who knows Win2k VPN setups well to go over your configuration. I doubt such a consultantion would take more than a couple of hours.

HTH,
Tom

(in reply to AnthonyS)
Post #: 18
RE: Publish VPN ?????? - 5.Nov.2002 10:04:00 PM   
jmargel

 

Posts: 72
Joined: 3.Apr.2002
Status: offline
ugh.. but what could be wrong? I'm an MCSE and thought I knew MS pretty well.

The place where I work will give me a hassle if I try to bring someone else in. They'll be asking 'why can't you figure it out?'

(in reply to AnthonyS)
Post #: 19
RE: Publish VPN ?????? - 6.Nov.2002 6:13:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi J,

Here's a suggestion. Configure a lab using VMware and recreate your situation. Configure the VPN gateways just as you would in your live environment. In the lab you'll see how the process works and get some insights that you might not have had before. I always mirror my ideas in a VMware lab before I roll it out at a customer site. I usually learn a lot about the process and try to make as many mistakes as possible, so that I'm prepared for the live network setup [Big Grin] You really do get a deeper understanding after you've run through a few exact and similar scenarios in the lab. Once you have that "hands-on" experience with the design you want, then its a lot easier rolling it out in the production environment.

HTH,
Tom

(in reply to AnthonyS)
Post #: 20

Page:   [1] 2   next >   >> << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 Firewall] >> VPN >> Publish VPN ?????? Page: [1] 2   next >   >>
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts