Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hi,

 

I'm having problems with a VPN connection between two sites. Both sites run server 08 and both are using Routing and Remote Access with NAT. My setup is similar to this

 

 

WORKSTATION.A <--> SERVER.A <----> ROUTER <------- (INTERNET) -------> ROUTER <----> SERVER.B <-->WORKSTATION.B+

192.168.20.0 20.1 / 200.1 <-> 200.254 <--(Here lives the dragons)--> 100.254 <-> 100.1 / 10.1 <-->192.168.10.0

 

 

All Subnets are /24. At the moment, Workstation A can ping Workstation B and server B. Workstation B can ping Workstation A and Server A.

ServerA cannot ping ServerB (and vise versa). Each server can connect to each other network shares by \\[RemoteServerIP]

 

Things I've tried/done

  • Restarting both servers
  • Reseting both routers to factory defaults
  • Replacing both routers
  • Tested this setup on another network I manage which both have server 2003 and both servers could ping no problem. (however NAT is not being used in this situation)
  • Recreating VPN
  • Recrearing NAT interface
  • Allowed all ports from both remote subnets through the firewalls
  • Disabled Domain Firewall. (Group policy wouldnt let me disable private and public however I set "machine settings/dministrative templates/network/network connections/windows firewall to disabled.

 

They VPN is used for SQL, File and print sharing, Exchange<->Outlook.

 

When trying to RDP to the remote server from Workstation

Any help would be much appreached as I need this fixed as soon as. Even if someone to explain in detail how to allow all traffic through windows firewall as I have a strong suspicion this is related to the FW. Even if you tell me how to completely disable the FW all together as I can only find how to diable Domain Network in Group Policy. (I know it's in there somewhere! I've seen it before!)

 

 

Many Thanks,

Fraser

Posted

Hi Fraser

 

What exactly is the issue?

 

Server A and Server B cannot ping each other?

Can't RDP ? What is the exact issue with RDP?

 

Sukh

Posted
Hi Fraser

 

What exactly is the issue?

 

Server A and Server B cannot ping each other?

Can't RDP ? What is the exact issue with RDP?

 

Sukh

 

I think the firewalls are the cause here and are preforming some sort of blocking one one of the interfaces or something? This did work before, and as far as I'm aware, no settings have been changed.

 

Both servers cannot ping each other

ServerA cannot connect to Server's B SQL

Both servers cannot RDP to each other

Both servers CAN browse each other's network shares using \\IP_Address

 

WorkstationA to WorkstationB is fine, (RDP, ICMP, etc)

Workstations cannot RDP to remote server (have only tried on way actually)

Workstation can however ping remote server

 

I've opened/disabled the firewall's as much as I can ("some settings are control by group policy", but I've checked through all policies and removed all FW related settings. Also ran GPupdate /force)

 

 

 

Sorry, I know this seems a bit of a mess (I've just taken the systems over) If I can completely remove all firewall rules then I think i may be one step closer to the solution.

 

 

Thank you

Fraser

Posted

Hi

 

Are you in a position to disable the firewalls to test? If, so, we can at least start from there and work on firewall if this is the issue?

 

Sukh

Posted

Yes. Need this sorted as soon as. I'll be home in about 30mins so will be able to do some testing/modifications then.

 

I also tried setting a group policy setting (cant remember the exact one/name) to disable the firewalls but it didn't help. I am on very slow internet just now so cant go googling for it. Think it was like prevent firewall on interface and set it to disabled to stopped the firewall processes.

 

Edit: It was this Windows Firewall: Protect all network connections to Disabled.

 

I have tried recreating the VPN's and NAT interfaces. Im 95% sure this problem is firewall related. Just need to completely disable and remove all FW group policy settings first and if it works, build up security from there.

 

 

Thank you so much for your help. Just took over these servers last week you see.

 

 

Fraser

Posted

Hi

 

I'm assuming you have two nic's on each MS Windows 2008 server?

 

When configuring RRAS did you disbable static packets which is set by default on the interfaces?

 

Sukh

Posted
I'm assuming you have two nic's on each MS Windows 2008 server?

That is correct

When configuring RRAS did you disbable static packets which is set by default on the interfaces?

 

Sukh

 

 

Ehh... Not sure. How/Where would I find out?

 

 

P.S. No PM received?

Posted

Hi

 

Please try the following for troubleshooting:

1. On the server, open Routing and Remote Access from Administrative Tools.

2. Right click the server name and select “Disable Routing and Remote Access”.

3. After we disable it, right click and select “Configure and Enable Routing and Remote Access”.

4. Follow the wizard and select VPN.

5. When selecting the network that connects to Internet, ensure we de-select “Enable security on the selected interface by setting up static packets filtering”.

6. Finish the reset of the wizard and check whether we are able to connect or not.

 

Sukh

  • Thanks 1
Posted
Hi

 

Please try the following for troubleshooting:

1. On the server, open Routing and Remote Access from Administrative Tools.

2. Right click the server name and select “Disable Routing and Remote Access”.

3. After we disable it, right click and select “Configure and Enable Routing and Remote Access”.

4. Follow the wizard and select VPN.

5. When selecting the network that connects to Internet, ensure we de-select “Enable security on the selected interface by setting up static packets filtering”.

6. Finish the reset of the wizard and check whether we are able to connect or not.

 

Sukh

 

On both servers yeah?

Posted
Hi

 

Try on both yes.

 

Sukh

 

 

Sorry, not too sure where I'm doing this...

 

Is it "Route IP Packets on this Interface" I'm de-selecting?

or at the screen to add static route's do I enter none?

 

 

I dont see any options regarding security

 

Thank you

Posted

When selecting the network that connects to Internet, ensure we de-select “Enable security on the selected interface by setting up static packets filtering”.

 

 

Confirm you are using Windows 2008?

 

Sukh

Posted

Im sorry, I must be missing something. Tried both options of the wizard (VPN + NAT and Secure connection between two networks) and both say nothing about security on the interfaces.

 

Yes, using Server 2008 Foundation and Server 2008 SBS Std.

Posted

Hi sukh,

 

Sorry I haven't replied lately. I've just been really busy lately an haven't had two minutes to pick up on where we left off. Since my last post, I did find someone in the same situation as me and his solution was to add a static route on both servers. The other post did also say that this was automatically done for you with windows 2003 which explains why my setup worked with another two sites.

 

I'll will revisit my VPN set up over the weekend and report back.

 

Thank you for your help so far!

 

Fraser.

  • 1 month later...
Posted (edited)

OK, so I finally got round to fixing this over the long weekend with all offices being closed for the Royal Wedding and Public holidays.

 

My fix was to completely remove and reconfigured RRAS on both servers, setting up the VPN connection first, then later adding NAT. After the VPN server was created and connected, I still could not ping from both servers to the other server using it's internal IP address. Pinging from both servers to a workstation on the otherside was fine. Also pinging from workstationA,site1 TO workstationA,site2 worked.

 

After some (more) research, I found that with server 2008, a static route is required to be able to reach the other server using its local address:

For example:

Route Add [iP of Remote Server] mask 255.255.255.255 [iP of RRAS Inteface on local network] -p

 

With Server 2003, this route is automatically created for you.

 

If anyone else reading this with the same problem, have a look at Microsoft's response in the following article: **See Step 7**

Unable to ping the tunnel address of a Demand Dial Connection on Windows Server 2008 RRAS - Microsoft Enterprise Networking Team - Site Home - TechNet Blogs

 

 

Thank you for all your help Sukh

 

Fraser

Edited by Fraser-09
Posted
Np, glad it's resolved

Actually, not quite lol. Been testing this out and restarting various devices that could possibly break the VPN connection and I've noticed that the static route must be deleted and recreated every time the connection drops. Can't understand why. Not to worry tho, im sure i'll get to the bottom of it.

Posted

OK. What devices have you restarted, which causes the static route to fail?

 

Can you details the steps that you take?

 

I assume the route is a persistant route?

 

Sukh

Posted

Any device that would break the connection, ie network switch, router or either server. Even if I manually "disconnect" the VPN and let the remote server reconnect, I must delete then recreate the route. Yes, using persistence route.

 

Once the connection is dropped and recreated, I must do

Route delete 192.168.10.1
then
Route Add 192.168.10.1 mask 255.255.255.255 192.168.20.53 -p

 

Seems very odd or maybe I'm missing something?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...