• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

GRE tunnel - FAILED

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> Access Policies >> GRE tunnel - FAILED Page: [1]
Login
Message << Older Topic   Newer Topic >>
GRE tunnel - FAILED - 24.Jul.2006 2:35:19 PM   
abissum

 

Posts: 21
Joined: 18.Aug.2003
Status: offline
I have a linux client trying to establish a GRE tunnel with a remote office. It gets Internet through VPN (static IP) and has All outbound protocols to External permitted. It also has an allow rule for all protocols from the remote office address, all users.
No connection appears. When I look into the logs, I see GRE - FAILED. In the protocol definitions there was no GRE protocol, so I created GRE - Ip-level - protocol #47. It did not help either.
I use ISA 2004 SP2 on W2k3 EE. PPTP fillter is enabled, everything allowed. All other VPN users have no problems, even with a slicky SIPv2 and even without explicit protocol definitions.
Can any ISA gurus advise me a solution to this problem?

< Message edited by abissum -- 25.Jul.2006 12:09:53 AM >
Post #: 1
RE: GRE tunnel - FAILED - 26.Jul.2006 6:54:19 AM   
abissum

 

Posts: 21
Joined: 18.Aug.2003
Status: offline
Dr. Shinder - do you have any comments on this matter?

(in reply to abissum)
Post #: 2
RE: GRE tunnel - FAILED - 26.Jul.2006 3:47:18 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
You can pass raw IP protocols only when there is a Route Network Rule for the source to destination connection.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to abissum)
Post #: 3
RE: GRE tunnel - FAILED - 26.Jul.2006 3:51:30 PM   
abissum

 

Posts: 21
Joined: 18.Aug.2003
Status: offline
There is a Route network rule of course - as I mentioned, this client get full Internet access via VPN connection with a static real IP address. The only thing not working is GRE tunnel.

(in reply to tshinder)
Post #: 4
RE: GRE tunnel - FAILED - 26.Jul.2006 3:55:56 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
A Route Network Rule from where to where?

Where is the client?

Where is the server?

What is the GRE tunnel being used for?

Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to abissum)
Post #: 5
RE: GRE tunnel - FAILED - 10.Aug.2006 3:24:50 PM   
abissum

 

Posts: 21
Joined: 18.Aug.2003
Status: offline
VPN Clients network and External network have Route relationship. The endpoints of a GRE tunnel reside in External and in VPN Client network. Neither of the sides can establish  GRE tunnel. ISA logs show GRE as a protocol type (even without creating a protocol definition for it) and as a result - FAILED.
One of our clients use GRE tunnels among different offices. All of their gateways are linux machines which use GRE transport for creating one big VPN for accounting, telephony, and so on. With every single provider they were able to get their GRE tunnels working - everyone but us, using ISA Server 2004. An advise to switch to Windows or use different transport, of course, is not an option.

(in reply to tshinder)
Post #: 6
RE: GRE tunnel - FAILED - 19.Aug.2006 12:42:48 AM   
abissum

 

Posts: 21
Joined: 18.Aug.2003
Status: offline
Dr. Shinder - can I get an answer please?

(in reply to abissum)
Post #: 7
RE: GRE tunnel - FAILED - 21.Aug.2006 4:33:49 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi AB,

Sounds like a PSS call, as I haven't a clue.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to abissum)
Post #: 8

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> Access Policies >> GRE tunnel - FAILED Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts