craig-schools Posted September 9, 2015 Posted September 9, 2015 I'm hoping someone can shed some light on this, it's going to be something very simple I'm sure but for the life of me I'm drawing a blank. I'm trying to setup a VPN so that teachers can access the network maps from home / starbucks etc on their staff laptops, saving the hassle of "I forgot my USB stick / Forgot to copy the files i wanted" etc problems. Spooled up a 2012 R2 HyperV VM, single LAN with internal static IP, installed RRAS and setup a L2TP connection with PSK. Spoke to our firewall / ISP and they opened the various ports and gave external IP. Spoke to our Filtering provider to ensure the proxy wouldn't cause agro. Should be a go-er. Tested using INTERNAL IP while on site - connects, picks up new DHCP range address. Tested using EXTERNAL IP while on site - fails. Error 789. Tested using EXTERNAL IP while using 4g tether - fails. Error 789. Re-spoke to Firewall / ISP and Filtering suppliers, all ports opened for a 5min testing window. retest yields same results and log files from firewall didn't seem to indicate a problem with them. What have I missed? Been at this on and off since the beginning of the summer holidays and it's starting to drive me nuts! Thanks
MatthewL Posted September 9, 2015 Posted September 9, 2015 Do you have a route/mapping/port forward from your firewall to server for the static address?
plexer Posted September 9, 2015 Posted September 9, 2015 Why did you choose to go for an L2TP connection rather than directaccess? Ben
craig-schools Posted September 9, 2015 Author Posted September 9, 2015 MatthewL - My Firewall provider says they have these setup yes. plexer - We only have windows 7 pro not enterprise so DA is not an option.
craig-schools Posted September 14, 2015 Author Posted September 14, 2015 Did some more testing on friday with our Firewall team and they have confirmed the traffic is going both ways, but looks like the server is refusing the connections. I've checked all the settings on client and the server and they match. What have I missed?
clockend25 Posted September 14, 2015 Posted September 14, 2015 You've enabled users for remote access in AD?
craig-schools Posted September 14, 2015 Author Posted September 14, 2015 Yup, I've done allow access in the DIAL IN tab both for me and also a brand new VPN1 user (testing). I've also done the same for the Computer objects which I am using for testing.
craig-schools Posted September 21, 2015 Author Posted September 21, 2015 anyone else going to offer anything?
mtillbrook Posted September 21, 2015 Posted September 21, 2015 Hi Craig I know this might be a silly question, but are you trying to test this from your internal network or from an external source?
craig-schools Posted September 21, 2015 Author Posted September 21, 2015 I've tried from both the internal network and using my 4g tethered phone connected to a laptop
mtillbrook Posted September 21, 2015 Posted September 21, 2015 hmm, i see it was a silly question as you did say that in your first post!! The simple answer is i dont know. TBH, i tend to use PPTP connections when i do this as they always seem to work easier that L2TP connections and you dont need to mess around with shared keys etc. There are some good points etc on this technet post: https://social.technet.microsoft.com/Forums/windows/en-US/630488b8-e638-488d-803a-08ef9281e4fb/windows-7-ipsecl2tp-vpn-connection-problem Other than that, i'm not sure I'm afraid!
craig-schools Posted September 21, 2015 Author Posted September 21, 2015 (edited) Ok, cheers. I've already put in the UDPEncapsulation registry entry on the server and client and my services are running (a service restart doesnt alter the problem). I don't really want to use PPTP but that may be my only option at this stage. Thanks tho Edited September 21, 2015 by craig-schools
craig-schools Posted September 23, 2015 Author Posted September 23, 2015 As I am getting desperate I have screenshotted the Server config, and both client configs. I've also got the packet captures from our firewall supplier from a 4g tether test. 1: 12:30:11.335218 802.1Q vlan#3 P1 85.255.233.197.4041 > 93.93.xxx.xxx.500: udp 528 2: 12:30:12.253999 802.1Q vlan#3 P1 85.255.233.197.4041 > 93.93.xxx.xxx.500: udp 528 3: 12:30:14.333600 802.1Q vlan#3 P1 85.255.233.197.4041 > 93.93.xxx.xxx.500: udp 528 4: 12:30:20.093867 802.1Q vlan#3 P1 85.255.233.197.30979 > 93.93.xxx.xxx.443: S 81889752:81889752(0) win 8192 5: 12:30:20.093912 802.1Q vlan#3 P0 93.93.xxx.xxx.443 > 85.255.233.197.30979: R 0:0(0) ack 81889753 win 8192 6: 12:30:20.755743 802.1Q vlan#3 P1 85.255.233.197.30979 > 93.93.218.56.443: S 81889752:81889752(0) win 8192 7: 12:30:20.755789 802.1Q vlan#3 P0 93.93.xxx.xxx.443 > 85.255.233.197.30979: R 0:0(0) ack 81889753 win 8192 8: 12:30:21.393488 802.1Q vlan#3 P1 85.255.233.197.30979 > 93.93.xxx.xxx.443: S 81889752:81889752(0) win 8192 9: 12:30:21.393534 802.1Q vlan#3 P0 93.93.xxx.xxx.443 > 85.255.233.197.30979: R 0:0(0) ack 81889753 win 8192 10: 12:30:21.556901 802.1Q vlan#3 P1 85.255.233.197.29917 > 93.93.xxx.xxx.1723: S 1992912569:1992912569(0) win 8192 11: 12:30:21.556947 802.1Q vlan#3 P0 93.93.xxx.xxx.1723 > 85.255.233.197.29917: R 0:0(0) ack 1992912570 win 8192 12: 12:30:22.192800 802.1Q vlan#3 P1 85.255.233.197.29917 > 93.93.xxx.xxx.1723: S 1992912569:1992912569(0) win 8192 13: 12:30:22.192845 802.1Q vlan#3 P0 93.93.xxx.xxx.1723 > 85.255.233.197.29917: R 0:0(0) ack 1992912570 win 8192 14: 12:30:22.833300 802.1Q vlan#3 P1 85.255.233.197.29917 > 93.93.xxx.xxx.1723: S 1992912569:1992912569(0) win 8192 15: 12:30:22.833346 802.1Q vlan#3 P0 93.93.xxx.xxx.1723 > 85.255.233.197.29917: R 0:0(0) ack 1992912570 win 8192 16: 12:30:23.034040 802.1Q vlan#3 P1 85.255.233.197.4041 > 93.93.xxx.xxx.500: udp 384 17: 12:30:24.054684 802.1Q vlan#3 P1 85.255.233.197.4041 > 93.93.xxx.xxx.500: udp 384 18: 12:30:26.077327 802.1Q vlan#3 P1 85.255.233.197.4041 > 93.93.xxx.xxx.500: udp 384 19: 12:30:30.162985 802.1Q vlan#3 P1 85.255.233.197.4041 > 93.93.xxx.xxx.500: udp 384 19 packets shown 1: 12:30:11.335309 802.1Q vlan#8 P1 85.255.233.197.4041 > 10.2.112.38.500: udp 528 2: 12:30:12.253999 802.1Q vlan#8 P1 85.255.233.197.4041 > 10.2.112.38.500: udp 528 3: 12:30:14.333600 802.1Q vlan#8 P1 85.255.233.197.4041 > 10.2.112.38.500: udp 528 4: 12:30:23.034040 802.1Q vlan#8 P1 85.255.233.197.4041 > 10.2.112.38.500: udp 384 5: 12:30:24.054699 802.1Q vlan#8 P1 85.255.233.197.4041 > 10.2.112.38.500: udp 384 6: 12:30:26.077327 802.1Q vlan#8 P1 85.255.233.197.4041 > 10.2.112.38.500: udp 384 7: 12:30:30.163001 802.1Q vlan#8 P1 85.255.233.197.4041 > 10.2.112.38.500: udp 384 7 packets shown Anyone else want to have a go?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now