Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN / ISA Problem?

Status
Not open for further replies.

Pristle

IS-IT--Management
Jul 27, 2003
9
0
0
NZ
System:
Microsoft SBS2k, 2 x NIC, Static IP, ISA and Netgear DG814 (FW4.8) or Nokia M1122 Router. The Netgear has more recently replaced the older Nokia unit.

I have a site where various employees are requesting access from home and/or on the road, with Win98/Me/XP client stations. When configuring the VPN setup 3 months back, the system was functioning correctly, I could log in, access Shared Folders on the Internal network etc. I also made use of the CMAK facility to create an easy setup solution for new users. Tested the files remotely, all seemed good.

However when I swapped the router, from Nokia to Netgear, the VPN broke. I reverted to the Nokia router to re-enable the service, all to no avail. The change was prompted due to the 100Mbit/s switch on the Netgear vs. the Nokia 10Mbit/s hub.

Current config:
Inhouse LAN
192.168.16.x
|
SBS Box
(Internal NIC 192.168.16.2, External NIC 192.168.1.252)
|
Netgear DG814 Router
192.168.1.254
|
ISP gateway
(with stat IP x.x.x.x)
|
web cloud
|
External Network
|
Remote User ISP Gateway
|
Either Router or Modem (ISP dynamic IP)
/ / / / Router Internal Serial Port on PC
IP 192.168.1.x IP N/A

No servers. Just workstations and/or laptops

Symptom:
Remote client clicks to VPN to SBS Box. Connection Status box reports “Establishing secure connection” briefly, indicating that a link is established. This is followed by “verifying password for USERNAME” for ±40 secs, with a failure notice as follows: “The remote computer did not respond. For further assistance, click More Info or search Help and Support Center for this error number. (Error 721)”

My Perception:
This says to me that the VPN works in terms of establishing the link. However it also says that the problem is that I cannot get authenticated on the SBS Box. This would indicate an error on the ISA Server portion of SBS, yes/no?

I’m struggling with this one and would appreciate any help at all.

Cheers,

Paul
 
I had this problem (with a DG814 as it happens), turned out to be ports on the router were blocked when they showed open. If it is a DG814 you are using, do the latest firmware update. Make sure you have 1723 and 1701 open.
 
also check if you can block open GRE port 47, as this is required for the LCP communication traffic between the two, sound like the infor is getting into you internal lan but not getting out again.

have you tried monitoriong the network traffic using network monitor on the internal lan to see if the vpn traffic is getting that far or not ??

just a few pointers

ITmontyp

So Long and thanks for all the fish :)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top