• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Outgoing Cisco VPN (NAT-T) quits working..

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> VPN >> Outgoing Cisco VPN (NAT-T) quits working.. Page: [1]
Login
Message << Older Topic   Newer Topic >>
Outgoing Cisco VPN (NAT-T) quits working.. - 5.Oct.2006 2:57:55 AM   
pstemper

 

Posts: 13
Joined: 17.Mar.2004
Status: offline
Setup:
Running ISA 2k4 Enterprise w/ 2 servers.  Users are establishing outgoing VPN connections to various sites using the Nortel Contivity and Cisco VPN Client software.  ISA(s) configured to allow NAT-T connections, destination VPN servers (and client software) using NAT-T.  Using NLB on the ISA boxes to load balance (and provide redundency) on and internal IP and several external IPs.

Problem:
Users can establish the VPN connections and use the remote resources without issue.  We have had at least 6 concurrent users connecting to the remote VPN sites without issue.  Then, occasionally, a user (who was connected earlier in the day) will try to re-establish an outgoing VPN connection, and they will get the Cisco error "Remote Peer is no longer responding" and they are never prompted for their credentials.  Other machines are still connected, and other people try to connect and are successful..

If I shut down one of the ISA boxes (doesn't matter which), then the users getting the errors can connect successfully.  If I bring both boxes back online, users can still connect, for a while.  Sometimes we go days without this issue, sometimes it happens several times a day.

When I have searched the web (and these forums) for this issue, I get two type of results back:
1) Users can never connect and receive the error.  This is NOT what we get.  We can properly establish the NAT-T VPN connection MOST of the time.
2) A user can connect, sometimes.  When they can't, the admin has fixed the problem by restarting the firewall service.  This is VERY similar to what we are seeing.  I only found 1 hit like this, and that was on these forums. (http://forums.isaserver.org/m_130254900/mpage_1/key_cisco,remote,peer,longer/tm.htm)  But that user was using ISA2k from SBS2000, and never documented a solution. 
I considered upgrading to ISA2k6, but I would like to resolve this first.

Any Suggestions on how to resolve or debug this?

Thanks.

Paul

< Message edited by pstemper -- 5.Oct.2006 2:59:43 AM >
Post #: 1
RE: Outgoing Cisco VPN (NAT-T) quits working.. - 5.Oct.2006 3:50:16 PM   
pstemper

 

Posts: 13
Joined: 17.Mar.2004
Status: offline
It just happened again.  I went to one of the ISAs, and told it to stop the firewall service.  It hung trying to stop the service, but then the user could VPN out again..

Ideas?

Paul

(in reply to pstemper)
Post #: 2
RE: Outgoing Cisco VPN (NAT-T) quits working.. - 5.Oct.2006 4:12:32 PM   
pstemper

 

Posts: 13
Joined: 17.Mar.2004
Status: offline
Another update.  It happened again.  This time, instead of resetting the firewall service, I stopped the RRAS service, which killed NLB.  I am wondering if it is an NLB issue now.

Paul

(in reply to pstemper)
Post #: 3
RE: Outgoing Cisco VPN (NAT-T) quits working.. - 16.Oct.2006 9:33:24 PM   
pstemper

 

Posts: 13
Joined: 17.Mar.2004
Status: offline
Update: I can make sure it never fails by only keeping one (doesn't matter which) ISA server up at a time.

Any suggestions?  Anyone else running ISA2k4 Ent with an ISA array and supporting outgoing VPN connections??

Paul

(in reply to pstemper)
Post #: 4
RE: Outgoing Cisco VPN (NAT-T) quits working.. - 25.Jun.2007 11:10:43 AM   
Meleyak

 

Posts: 1
Joined: 25.Jun.2007
Status: offline
I've your same configuration, and same problem too!
Did you get any other solution / idea / answer?

Best regards

Giulio

(in reply to pstemper)
Post #: 5
RE: Outgoing Cisco VPN (NAT-T) quits working.. - 25.Jun.2007 11:14:10 AM   
pstemper

 

Posts: 13
Joined: 17.Mar.2004
Status: offline
Nope.  I temporarally resolved the issue by only keeping one box active for load balancing (defeats the purpose though).  I am working on upgrading to isa 2006 Ent to see if that resolves the issue.

Paul

(in reply to Meleyak)
Post #: 6
RE: Outgoing Cisco VPN (NAT-T) quits working.. - 2.Nov.2007 6:38:30 PM   
jerrice

 

Posts: 28
Joined: 9.Dec.2005
Status: offline
Anyone have any news on this issue?  I am seeing the same thing, although I have an EE array with ISA 2006, and we are trying to VPN to another site which has a single ISA 2004 EE server.  Various machines will stop being able to VPN out (L2TP/IPSec).  We can get it working again on on an affected client by changing the IP address.  If I turn off either of the ISA servers, they are able to VPN out to the remote site without issue.  As long as they are both on, the problem randomly starts cropping up again.

Also, I should note that the NAT-T registry change for XP SP2 and Vista has not helped either of those types of clients.

Any ideas?

< Message edited by jerrice -- 2.Nov.2007 6:45:42 PM >

(in reply to pstemper)
Post #: 7

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> VPN >> Outgoing Cisco VPN (NAT-T) quits working.. Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts