ianh64
Members-
Posts
120 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ianh64
-
Thanks for the info. But, what do I use for the certificate files? As far as I can see, no certificate files were created as everything was auto generated and deployed. Do I have to export a certificate? I did do this for the Forefront TMG created one and that validated OK. But from your helpful comment, it looks like its the Exchange mail servers certificate that I need to be checking and installing on the TMG machine? There are a couple of nearly identical (only date/time differs) looking certificates in the 'other people' tab of the IE certificates view. These are both issued to the server name (sans domain) and issued by the same. Are these what I am after? If so, if its the right thing to do, how do I get them into the Enterprise Root CA so they can be picked up by other machines? Or do I simply export it, validate it, then copy it to the TMG machine and import? The status of these certificates when looking with ie on the exchange server machine is that neither are trusted because they are not in the trusted root certification authorities store. So it looks like somehow, if they are otherwise the ones that I need, I need to put them in there. If so, do I need both or can I remove the earlier one? Unfortunately certificates are not up on my list of knowledge. Thanks
- 5 replies
-
- -2146893019
- 0x80090325
-
(and 3 more)
Tagged with:
-
Actually, going back through and redoing the instructions - i'm convinced that I have done something wrong - in Internet Explorer/tool/contents/trusted root certificate authorities on the servers for Enterprise Root CA, Exchange Server and TMG/Edge Server I can now see a valid certificate for Forefront TMG HTTPS inspection certificate authority so it looks like it did deploy but still no joy - same error. Not sure when these appeared as they still have yesterdays generated certificate - didn't generate a fresh one today. Do I need to restart anything or will it sort itself out in time?
- 5 replies
-
- -2146893019
- 0x80090325
-
(and 3 more)
Tagged with:
-
When trying to access Exchange web mail from external, after logging in I get the following error reported in the browser: Error Code: 500 Internal Server Error. The certificate chain was issued by an authority that is not trusted. (-2146893019) Running TMG Management Console tests on the OWA firewall policy also indicate similar: Destination Server Certificate Error 0x80090325 - The certificate chain was issued by a certificate authority that was not trusted. Following the link reported in the test and actioning to generate a certificate and deploy reported in no errors, however I cannot see the certificate in the AD Certificate server store, nor any mention of certificates in any of the GPO's that I have looked at - the implication is that the certificate is deployed by GPO. The instructions that I followed were from here: Generating the https certificate Deploying the certificate Forefront TMG is running in a domain environment so I opted for automatic deployment as is recommended. We have an enterprise root CA. The note mentions up to 8 hours for the certificate to propagate, but I have done a GPUPDATE on each machine and also waited a significant number of hours, possibly more than 8, with reboots in between. So it looks like its not working rather than simply taking time to deploy. Any suggestions of debugging this error?
- 5 replies
-
- -2146893019
- 0x80090325
-
(and 3 more)
Tagged with:
-
I have a WSUS update that is marked as needed by 2 of our (virtual) Servers. However, I do not believe that it is actually needed or wanted. Its actually a WSUS update itself: Windows Server Update Services 3.0 SP2 Dynamic Installer for Server Manager x64 Edition (KB972493) However, a WSUS server is not installed on either of these servers. How can I signal this update as not needed on these servers so WSUS no longer flags it as needed.? Thanks Ian Windows 2008R2.
-
Thought that I had replied to this but cannot see the update to here we go again...probably didn't hit post - doh! Thanks for the info on the migration tools. There are only a 4 or so mailboxes (most important ones) on Navaho that initially need migrating and these all (should be) Outlook via imap users. I had thought about migrating by archiving to a pst then moving the pst across to their new PC/Outlook setup. But a migration tool that moves from Navaho to Exchange Server may be a better solution keeping things all in one place for continuity. As for splitting email accounts, I had hoped to use the 'Navaho Secondary Site Mode' which apparently forwards emails received by non matched local users to a smart host - which could hopefully be Exchange Server. But cannot find information regarding configuring smart hosts. Also thinking about Exchange as master email server, then somehow configuring some connectors to feed the Navaho server. Most user accounts are internal email so it would not be a great issue if we lost internet email access to these for a short period of time.
-
I have DNS forwarding setup - appears to be working correctly. Today the DC had internet status - it appears totally random. However a client PC on the test environment that routes through this DS is showing 'no internet access' yet does so maybe it is related - I have an Exchange Server connectivity issue with this PC today so may look at resolving both issues. Thanks for the suggestion though.
-
Exchange server license question - standard or enterprise
ianh64 replied to ianh64's topic in Licensing Questions
I'm beginning to think its a catchall statement - in which case its a useless piece of information. However, as I get more familiar with Exchange, and looking through some of the Enterprise options, it makes me wonder whether Enterprise is a necessity rather than a luxuary - for instance, I just found on my edge server that automatic updates of anti spam definitions is an Enterprise feature. But can't work out where to manually update them. Although looking on the web site for Exchange antispam updates, it looks like this is covered either by Exchange Server Enterprise CALs or by a Forefront Protection 2010 for Exchange Server license which I am likely to recommend to the school once I have evaluated it. I personally quite like Forefront TMG Gateway that I am currently evaluating for them and it makes some sense for an integrated solution. My only slight concern is that I use WSUS updates (3 times daily) for this server and they are manually applied. With Forefront TMG, can bypass WSUS and go direct to Microsoft Update so these are checked quite frequently during the day. Not sure if same override applies to Exchange Server updates. -Ian -
Does anyone have any suggestions for running a mixed Navaho / Exchange Server environment? Exchange server is 2010 in a new 2008R2 AD environment, Navaho is v3.8.70-teamcat. Looking to migrate from Navaho to Exchange. Office users first, then staff and pupils. Windows Server currently in standalone testbed environment, but won't be able to test with Navaho box except in production environment on day of migration. Seems that there are some hooks in Exchange and Navaho that will allow email accounts to be split between the two servers. Thanks Ian
-
Have just installed Exchange Server 2010 on a testbed for a small school and have run the Exchange 2010 Organisational Health Check to get the licensing requirements. Currently we have 5 Standard Device CALs to cover 3 office machines and a couple spare. Whilst I realise that Organisational Health Monitor does not report on device CALs, it is reporting that I need a couple enterprise CALs as well as a couple user CALs. Why is it reporting that I need Enterprise CALs? It's a clean install, with no unified messaging (but it does show in Organisation Configuration - disabled), just Mailbox, Hub and CAS (all on same VM) plus Edge (on separate VM). Thought that it was only UM that triggered Enterprise licensing. Also have Outlook Web App and would like to try Active Synch. MAPI, POP3 and IMAP4 also reported but I'm in the middle of configuration so this may change - did notice a warning about enterprise licensing for one option but cannot remember where and whether I selected the option - unlikely. Thanks in advance Ian
-
I am getting an occasional incorrect 'No Internet' status in taskbar and network sharing screen on our domain controller. Turned on box this morning and task bar indicated 'no internet'. Looking at 'Network and Sharing Center', the two domain NIC's (static IP) indicated no network - one is a virtual NIC, yet WSUS updates and IE and probably everything else have internet access. After about 15 minutes, I just start writing this post, popped back to look at some terminology, and its got internet access OK. But two days ago, it had a false No Internet Access for the whole day. What determines this status? Internet access is via a virtual server running Forefront TMG. All other machines, virtual servers or otherwise are showing a correct status. It just seems to be the DC.
-
Client PC's routing through multi NIC 2008R2 server
ianh64 replied to ianh64's topic in Wireless Networks
Actually this was going to hold me up so I decided to install RRAS and select LAN routing and its fixed my issue. Seeing the management roles screen, memories of RRAS still being installed have come flooding back, but I decided not the document it because I thought that I had removed all the configuration options - the issue being that LAN routing was still installed. Thanks anyway PS. Must stop talking/posting to myself. -
Client PC's routing through multi NIC 2008R2 server
ianh64 replied to ianh64's topic in Wireless Networks
OK. I have broken things and its stopped working! Basically I am in the process of doing a production ready full rebuild (rather than a prototype test environment likely to change) and the rebuild is not working like the prototype environment. Theoretically both should be identical, except the test environment was used for experimenting with configurations so would have at some stage, been had its network reconfigured many times trying to sort out the original problem. Prior to destroying the prototype environment, I documented the final build configuration of the prototype environment, plus routing tables were documented in these threads. Everything looks the same, but the main server (griffin) seems not to be routing the subnets to the main gateway. Quickly recapping, I have 4 networks, across a mix of physical and virtual networks. 192.168.3.x (Office LAN) and 192.168.4.x (School LAN) are physical networks. The school LAN has nothing connected yet, the Office LAN has one Windows 7 PC in addition to the switch. It gets its IP (reserved 192.168.1.101) by DHCP and that all looks fine. In addition, there is a virtual LAN 192.168.2.x (IT LAN) which has a couple of Hyper-V virtual machines hanging off of it, one of which, 192.168.2.11, is the Internet WAN gateway via Microsoft Forefront TMG 2010 firewall and routing. Everything hanging off of the IT LAN is working fine, including the griffin server 192.168.2.1 so the internet gateway is fine. The problem is that, from Windows 7 client, which is untouched from prototype config, I cannot PING 192.168.2.1 or any other subnet, or any devices on other subnets. But PING of 192.168.3.1 is fine. office1 - Windows 7 DHCP - IP:192.168.3.100, Mask 255.255.255.0, Gateway 192.168.3.1, Access type - No Internet access | ----------------------------------------------------------------------------------------------- | Netgear GS108T Smartswitch Static - IP:192.168.3.2, Mask 255.255.255.0, Gateway 192.168.3.1 | ----------------------------------------------------------------------------------------------- | griffin - Windows 2008R2 Server AD Domain Controller, DNS, DHCP, Hyper-V host | Office NIC Static - IP:192.168.3.1, Mask 255.255.255.0 X No access ie PING X IT LAN NIC Static - IP:192.168.2.1, Mask 255.255.255.0, Gateway 192.168.2.11, Access type - Internet School NIC Static - IP:192.168.4.1, Mask 255.255.255.0, currently unused subnet - for info only | ----------------------------------------------------------------------------------------------- | Internet via TMG Gateway At some point in the prototype phase, I will have installed and configured in various guises, RRAS routing, but its not documented in my build document so I either removed this role or, failed to document it as an over sight, not sure which. So my question is, would I expect clients connected to 192.168.3.1 NIC to route to the default gateway on 192.168.2.1 or, do I have to install and configure RRAS routing? -
Client PC's routing through multi NIC 2008R2 server
ianh64 replied to ianh64's topic in Wireless Networks
Hi Thanks for getting back. The DHCP issue may be a red herring - it was found in connectivity testing that I could not swap from Office NIC to School NIC and have DCHP provide me a valid scoped set of addresses. Seems to be a 'non issue' in a real world environment because I have since discovered that the Windows DHCP server needs to be restarted to bind the newly connected NIC port to the DCHP server - the old NIC port would then drop off. In addition, I had not realised that if the subnet of the Netgear Smart switch changed, it also needed a reboot to pickup a new IP address (via DHCP). Had incorrectly assumed that the IP address only affected the management of the switch and not that the IP address also affected the switch operation itself - first time that I have used a smart/managed switch. The reason for multiple subnets is for two reasons. Firstly it is something that I am comfortable with. In a former life I was an application developer for global applications. Subnets were a way of life, even if we had dedicated network guys to manage them. Its been 15 years since I last configured a windows server, back in NT Server 3.51days. I've got alot of catching up to do in a short time frame. Sticking with what is familiar and avoiding additional complexities over and above all the necessary new things that I am having to implement should have given me a fighting chance. Second, the school that I am doing this for has a very dated IT infrastructure. By using multiple NICs and subnets, I am largely mirroring what they already have. So migrating legacy bits across should be alot easier and will be in logical chunks. Anyway, back to my problem... Apart from the circular routing issue which appears only to be detectable by tracert/ping to unknown IP addresses on the Office/School LANs, i'm not sure if its going to be an issue in the future. I have added routing tables from the office client, server host and security gateway below. One slight difference from above is that IP address of office1 is now 192.168.3.101 due to smartswitch being assigned .100 in dhcp. I will go back and edit initial post for consistency. I should also note that I have disabled IPV6 to remove added complexity. office1, Windows 7 DHCP assigned IP 192.168.3.101, mask 255.255.255.0, gateway 192.168.3.1 (griffin Office LAN), dns 192.168.2.1, dhcp server 192.168.3.1 =========================================================================== Interface List 11...00 25 64 b8 42 7a ......Broadcom NetLink (TM) Gigabit Ethernet 1...........................Software Loopback Interface 1 12...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter 13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.3.1 192.168.3.101 10 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306 192.168.3.0 255.255.255.0 On-link 192.168.3.101 266 192.168.3.101 255.255.255.255 On-link 192.168.3.101 266 192.168.3.255 255.255.255.255 On-link 192.168.3.101 266 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306 224.0.0.0 240.0.0.0 On-link 192.168.3.101 266 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306 255.255.255.255 255.255.255.255 On-link 192.168.3.101 266 =========================================================================== Persistent Routes: None griffin, Windows Server 2008r2 office LAN NIC static IP 192.168.3.1, mask 255.255.255.0, gateway nc, dns 192.168.2.1 school LAN NIC static IP 192.168.4.1, mask 255.255.255.0, gateway nc, dns 192.168.2.1 IT LAN NIC static IP 192.168.2.1, mask 255.255.255.0, gateway 192.168.2.11 (eagle IT LAN), dns 192.168.2.1 C:\Users\Administrator>route print =========================================================================== Interface List 21...a4 ba db 0a af 88 ......GB2 - IT LAN 17...00 10 18 6b a8 00 ......Broadcom BCM5709C NetXtreme II GigE (NDIS VBD nt) #2 13...00 10 18 6b a8 02 ......Broadcom BCM5709C NetXtreme II GigE (NDIS VBD nt) 1...........................Software Loopback Interface 1 12...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter 14...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2 16...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3 =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.2.11 192.168.2.1 261 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306 192.168.2.0 255.255.255.0 On-link 192.168.2.1 261 192.168.2.1 255.255.255.255 On-link 192.168.2.1 261 192.168.2.255 255.255.255.255 On-link 192.168.2.1 261 192.168.3.0 255.255.255.0 On-link 192.168.3.1 266 192.168.3.1 255.255.255.255 On-link 192.168.3.1 266 192.168.3.255 255.255.255.255 On-link 192.168.3.1 266 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306 224.0.0.0 240.0.0.0 On-link 192.168.2.1 261 224.0.0.0 240.0.0.0 On-link 192.168.3.1 266 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306 255.255.255.255 255.255.255.255 On-link 192.168.2.1 261 255.255.255.255 255.255.255.255 On-link 192.168.3.1 266 =========================================================================== Persistent Routes: Network Address Netmask Gateway Address Metric 0.0.0.0 0.0.0.0 192.168.2.11 Default =========================================================================== eagle, security gateway, Windows Server 2008r2 hyper-v virtual machine running Microsoft Forefront TMG evaluation IT LAN NIC static IP 192.168.2.11, mask 255.255.255.0, gateway nc, dns 192.168.2.1 Internet WAN NIC static IP 192.168.2.50, mask 255.255.255.0, gateway 192.168.1.254 (O2 router), dns 192.168.2.1 static routes destination 192.168.3.0 (office LAN), mask 255.255.255.0, gateway 192.168.2.1 (griffin IT NIC), interface Office LAN destination 192.168.4.0 (school LAN), mask 255.255.255.0, gateway 192.168.2.1 (griffin IT NIC), interface Office LAN (unused) C:\Users\Administrator>route print =========================================================================== Interface List 12...00 15 5d 00 c1 01 ......Microsoft Virtual Machine Bus Network Adapter 11...00 15 5d 00 c1 00 ......Microsoft Virtual Machine Bus Network Adapter 1...........................Software Loopback Interface 1 =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.1.254 192.168.1.50 556 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306 192.168.1.0 255.255.255.0 On-link 192.168.1.50 556 192.168.1.50 255.255.255.255 On-link 192.168.1.50 556 192.168.1.255 255.255.255.255 On-link 192.168.1.50 556 192.168.2.0 255.255.255.0 On-link 192.168.2.11 261 192.168.2.11 255.255.255.255 On-link 192.168.2.11 261 192.168.2.255 255.255.255.255 On-link 192.168.2.11 261 192.168.3.0 255.255.255.0 192.168.2.1 192.168.2.11 261 192.168.4.0 255.255.255.0 192.168.2.1 192.168.2.11 261 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306 224.0.0.0 240.0.0.0 On-link 192.168.1.50 556 224.0.0.0 240.0.0.0 On-link 192.168.2.11 261 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306 255.255.255.255 255.255.255.255 On-link 192.168.1.50 556 255.255.255.255 255.255.255.255 On-link 192.168.2.11 261 =========================================================================== Persistent Routes: Network Address Netmask Gateway Address Metric 0.0.0.0 0.0.0.0 192.168.1.254 Default =========================================================================== for completeness only leo, application server, Windows Server 2008r2 hyper-v virtual machine IT LAN NIC static IP 192.168.2.21, mask 255.255.255.0, gateway 192.168.2.11 (eagle IT LAN), dns 192.168.2.1 -
Windows 7 client routing through multi NIC 2008R2 server
ianh64 replied to ianh64's topic in Windows Server 2008 R2
Please consider this thread closed. Having been freed from the clutches of restricted browsing on server, I have found the network forum so have started a more pertinent thread on there -
Now that I have narrowed down my issue to a routing problem, I am posting here in the hope that this forum is more active. Previously started in Windows Server 2008R2 forum here. Basically I am setting up a new office network for a local school. Its a fresh build and currently running in a testbed environment at my home, hence O2 router etc. The initial requirement is 3xoffice Windows 7 PCs (office1,2,3) running on an active directory domain Windows 2008R2 server - configured as a host (griffin) and two hyper-V virtual machines - one for applications (leo) and the other for security/firewall (eagle). The host has 4 NIC's, one for office LAN (192.168.3.x) host only, one school LAN (192.168.4.x) host only for future use, one IT LAN (192.168.2.x) host and VMs and one Internet WAN (192.168.1.x) VM only. The security/firewall app runs a trial of Microsoft Forefront TMG that is routing 192.168.2.x and 192.168.1.x. Internally I am happy with the configuration, however, when I attach a client to the Office or School LANs, they cannot see the internet. I tracked this issue down to a routing issue where the security server (the default gateway of the host) could not route back to the office and school LANs. I thought that I had fixed this by setting up static routes on the security server back to the host, but subsequent testing indicated that this had, in some circumstances (when the destination IP was unavailable) caused circular routing and DHCP and domain membership of the office and school LANs are highly intermittent. My configuration is as follows...omitted school LAN for clarity. office1 - Windows 7 DHCP - IP:192.168.3.100, Mask 255.255.255.0, Gateway 192.168.3.1 (Access type - No Internet access unless static route on eagle added) | | Netgear GS108T Smartswitch Static - IP:192.168.3.2, Mask 255.255.255.0, Gateway 192.168.3.1 | | griffin - Windows 2008R2 Server AD Domain Controller, DNS, DHCP, Hyper-V host Office NIC Static - IP:192.168.3.1, Mask 255.255.255.0 (Access type - Internet) | IT LAN NIC Static - IP:192.168.2.1, Mask 255.255.255.0, Gateway 192.168.2.11 (Access type - Internet) | | eagle - Windows 2008R2 Server (Virtual) IT LAN NIC Static - IP:192.168.2.11, Mask 255.255.255.0 (Access type - No Internet access) static route added dest 192.168.3.0, Mask 255.255.255.0, gateway 192.168.2.1 | Forefront TMG 2010 Eval | Internet NIC Static - IP:192.168.1.50, Mask 255.255.255.0, Gateway 192.168.1.254 (Access type - Internet) | | O2 Router (homebased testbed) Internet NIC Static - IP:192.168.1.254, Mask 255.255.255.0, Gateway as O2 default When the circular route is detected, its basically bouncing between griffin (192.168.2.1) and eagle (192.168.3.11) as follows... C:\Users\Administrator>tracert 192.168.3.100 Tracing route to 192.168.3.100 over a maximum of 30 hops 1 * * * Request timed out. 2 <1 ms <1 ms <1 ms griffin.???.school [192.168.2.1] 3 <1 ms * <1 ms eagle.???.school [192.168.2.11] 4 <1 ms <1 ms <1 ms griffin.???.school [192.168.2.1] 5 <1 ms * <1 ms eagle.???.school [192.168.2.11] 6 <1 ms <1 ms <1 ms griffin.???.school [192.168.2.1] 7 1 ms * <1 ms eagle.???.school [192.168.2.11] 8 <1 ms <1 ms <1 ms griffin.???.school [192.168.2.1] 9 <1 ms * <1 ms eagle.???.school [192.168.2.11] etc I am assuming that DHCP, active directory domain join requests and other broadcast messages etc are getting lost in the circular routing as they are broadcast so do not have a valid destination address. Appreciate any help on this. Unfortunately, it is a small primary school and finance is very limited. The configuration may not be ideal/best practice, but the fact is, I have to work with what I have available to me.
-
Windows 7 client routing through multi NIC 2008R2 server
ianh64 replied to ianh64's topic in Windows Server 2008 R2
Oh dear. The 'fix' seems to have created its own issue. Looks like, in some situations, I have setup circular routing bouncing between 192.168.2.1 (the main server NIC) and 192.168.2.11 (the LAN side of the internet gateway). This only appears to be an issue if the destination IP is not connected. However, I also think it affects broadcast requests, ie DHCP. C:\Users\Administrator>tracert 192.168.3.100 Tracing route to 192.168.3.100 over a maximum of 30 hops 1 * * * Request timed out. 2 <1 ms <1 ms <1 ms griffin.???.school [192.168.2.1] 3 <1 ms * <1 ms eagle.???.school [192.168.2.11] 4 <1 ms <1 ms <1 ms griffin.???.school [192.168.2.1] 5 <1 ms * <1 ms eagle.???.school [192.168.2.11] 6 <1 ms <1 ms <1 ms griffin.???.school [192.168.2.1] 7 1 ms * <1 ms eagle.???.school [192.168.2.11] 8 <1 ms <1 ms <1 ms griffin.???.school [192.168.2.1] 9 <1 ms * <1 ms eagle.???.school [192.168.2.11] etc A side effect of this is that DHCP also appears to have got broken plus the client is temperemental at joining the domain once it has lost connection - I was doing connectivity tests and found that the client could not be swapped between NIC's and rejoin at will. Appreciate anyones thoughts on this. Using a seperate hardware router is out of the question. Is it possible to 'break' the circular reference, possibly by setting up further static routes, or possibly setting up a dynamic routing protocol such as RIP or IGMP - have tried to set these up but no luck. -
Windows 7 client routing through multi NIC 2008R2 server
ianh64 replied to ianh64's topic in Windows Server 2008 R2
OK. I think I have solved the issue. Need to test fully but this is being written on the Windows 7 client on the Office LAN. The issue was routing, but not on the main server, but on the security server. What I needed to do was, on the IT LAN side of the security/TMG server, setup a static route back to the IT LAN NIC on the main server. So basically, adding the static route on the IT LAN interface within RRAS on the security server (192.168.2.11) for IT LAN, destination 192.168.3.0 (the IT LAN), mask 255.255.255.0, gateway 192.168.2.1 (IT LAN NIC on main server) seems to have me up and running. Thanks for reading. Hope this will help someone in the future. -Ian -
Windows 7 client routing through multi NIC 2008R2 server
ianh64 replied to ianh64's topic in Windows Server 2008 R2
I am 99% sure this is a subnet routing issue. I easily managed to get the Windows 7 PC to connect to the internet simply by connecting to the IT (192.168.2.x) LAN and ensuring that the gateway was set to the security/TMG server at 192.168.2.11. I also removed the Netgeat Smartswitch to remove any oddies with that but it made no difference. So any pointers as to what static routes that I need to setup or how to configure RIP or IGMP routers for dynamic routing would be appreciated so I can put it back on the office (192.168.3.x) LAN would be appreciated. Thanks in advance Ian -
Hi First post. Sorry its a long/detailed one. I am setting up a new school office network for a local school. First time W7 and Server 2008 user - last time I configured Server was in 3.51 days! A VMS application developer in a previous life and we had network guys to setup the routing specifics. We have a server with 4 NICs. One is for internet, one for school office which is what I am configuring for, one is for IT/servers LAN and a final one spare for when school machines get added. I am using an active server domain. I currently have a Windows 7 PC connected via DHCP to office LAN. Subnet is 192.168.3.x. The Server is on .1, a Netgear Smartswitch is on .2 and DHCP allocated .100 to the Windows 7 PC. On the IT LAN (192.168.2.x), in addition to the physical server (192.168.2.1) I have two Hyper-V virtual machines, one is an application server (.22) and the other is a security server (.11) running and evaluation of TMG. The security server then uses the Internet Lan (192.168.1.50) to go out to my broadband router (192.168.1.254). I am 90% happy that server network is working as it should, except for routing from the 192.168.3.x subnet. On the server I can access the internet, likewise from application server and security server. DNS appears to be working fine. The problem that I am having is that the windows 7 PC cannot connect to the internet, or more specifically, cannot connect/ping through the W2008R2 server other than to its specific IP addresses, 192.168.3.1 and 192.168.2.1. DNS resolution on W7 PC works fine and I can remote desktop in from the server. I suspect subnet routing issues on the server. To simplify this a little, it didn't work when I had the single server without virtual machines and TMG so I think that whilst TMG must be considered, its not the fundamental problem. On main server, the IT LAN (192.168.2.1) has a default gateway of the security server, 192.168.2.11. On the Win7 client, it has a default gateway of the server office NIC, 192.168.3.1. I have tried other values and if set to other than this, I loose DNS name resolution. I have installed routing and remote access on server and tried both RIP and IGMP routers, the later currently being in use. I have added all the NIC's to these but no routing appears to be going on. Possibly I need to setup static routes? I have tried many options, but no luck. Of course, with me being new to 2008R2 and AD, it may be something simple like I need to authorise the W7 client to access the network, even though it is part of the domain and I am testing it with domain admin user. Have also tried turning various firewalls off. Apologies for the long question. Hopefully the solution will be nice and simple! -Ian Windows 7 DHCP - IP:192.168.3.100, Mask 255.255.255.0, Gateway 192.168.3.1 (Access type - No Internet access) | | Netgear GS108T Smartswitch Static - IP:192.168.3.2, Mask 255.255.255.0, Gateway 192.168.3.1 | | Windows 2008R2 Server Office NIC Static - IP:192.168.3.1, Mask 255.255.255.0 (Access type - Internet) | IT LAN NIC Static - IP:192.168.2.1, Mask 255.255.255.0, Gateway 192.168.2.11 (Access type - Internet) | | Windows 2008R2 Server (Virtual) IT LAN NIC Static - IP:192.168.2.11, Mask 255.255.255.0 (Access type - No Internet access) | Forefront TMG 2010 Eval | Internet NIC Static - IP:192.168.1.50, Mask 255.255.255.0, Gateway 192.168.1.254 (Access type - Internet) | | O2 Router (homebased testbed) Internet NIC Static - IP:192.168.1.254, Mask 255.255.255.0, Gateway as O2 default
