• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

error message 0xc0040012 FWX_E_NETWORK_RULES_DENIED

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> VPN >> error message 0xc0040012 FWX_E_NETWORK_RULES_DENIED Page: [1]
Login
Message << Older Topic   Newer Topic >>
error message 0xc0040012 FWX_E_NETWORK_RULES_DENIED - 12.May2005 6:47:00 PM   
dcornwall

 

Posts: 16
Joined: 19.Jan.2005
Status: offline
Hi all,

I have my vpn setup for client access to internal working great; but i cannot get the computers from internal to talk to any VPN clients. I get the following message and was hoping someone might be able to help.

0xc0040012 FWX_E_NETWORK_RULES_DENIED

I have created new rules to allow all traffic from internal to vpn clients till i have this figured out. My VPN clients are NAT'd to my internal network which is spread over many subnets. I have created on my border router route entries so that I can get back to the ISA box. The VPN client addresses are ranged from 10.70.2.101 - .200 and the ISA logical IP from the VPN network is 10.70.2.100. The weird thing is that I can ping from internal to the 10.70.2.100 interface but when I ping and client I get the above mentioned entry in the log as being denied. Any Ideas???

THanks

DAve
Post #: 1
RE: error message 0xc0040012 FWX_E_NETWORK_RULES_DENIED - 12.May2005 9:09:00 PM   
ClintD

 

Posts: 1848
Joined: 26.Jan.2001
From: Keller, TX
Status: offline
If the VPN Clients NAT to the Internal network, then they would only be accessible through Server Publishing rules. You;ll probably have to change the network rule to Route in order for this to work correctly.

You can PING the ISA Server's VPN address because ISA has a Network Rule stating that it will route to all networks and the traffic flows correctly.

When 2 network route, the route relationship is mirrored (if A routes to B, it's implied that B routes to A), but on a NAT relationship, if A NATs to B, A is only accessible to B through server publishing rules.

[ May 12, 2005, 09:11 PM: Message edited by: ClintD ]

(in reply to dcornwall)
Post #: 2
RE: error message 0xc0040012 FWX_E_NETWORK_RULES_DENIED - 12.May2005 9:54:00 PM   
dcornwall

 

Posts: 16
Joined: 19.Jan.2005
Status: offline
That is what i was thinking. Thanks for the confermation.

David

(in reply to dcornwall)
Post #: 3

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> VPN >> error message 0xc0040012 FWX_E_NETWORK_RULES_DENIED Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts