Jump to content

Recommended Posts

Posted

Hi all

 

Just thought I'd ask here if anyone has had any similar problems to me.

 

Our firewall is TMG 2010, and all clients are W7. Users connect through a VPN connection I make for them through the W7 Network and Sharing centre.

 

Now, this arrangement has worked very well for about three years. Admittedly it sometimes took some of my users a few connection attempts, but apart from that there have been no issues.

 

All this changed a few weeks ago. We had a powercut which took down the vast majority of our servers apart from the firewall and the backup server.

 

Everything all came back online OK with no noticeable affects (or so I thought).

 

But, since around that time my users have been complaining bitterly about the VPN.

 

It still takes a few connection attempts but quite often now drivers aren't mapped, or the user is unable to browse the internet. Sometimes, if they disconnect and reconnect a few times everything is OK but it's very intermittent.

 

To make things more difficult, sometimes (at the same time) one VPN user will have no drive mappings, but another will.

 

I've been tearing my hair out trying to find the problem. Have been through all the TMG logs and events but can't see anything untoward.

 

I've since fully patched TMG and rebooted it a couple of times but with no joy.

 

Has anyone here ever experienced anything like this and fixed it? If so I will owe you a huge debt if you can help!!

Posted

Thought I'd update this after a day and half's fiddling!

 

I think I've tracked it down to a DNS issue. The VPN clients connect but cannot resolve internal addresses, even with a FQDN.

 

After further investigation I found my predecessor had set TMG to dynamically assign IP addresses. Apparently this isn't recommended so I'm now statically assigning them.

 

I'm now testing to see if this improves reliability.

 

Of course, why this has suddenly started being unreliable after years of faithful service is another question entirely!

Posted

Just to add a bit more. Yesterday I tested the VPN connection by using my phone as a wireless access point. I successfully connected about two times out of thirty attempts.

 

Today, after the change of method of address allocation, I have successfully connected six times out of six attempts.

 

The acid test will be tonight when my users try from home but it already appears much more robust.

 

So if you are reading this, have a TMG firewall with a remote access VPN configured on it, and are having connection issues then try the above!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...