F
Franz Schenk
Have a strange problem with a Windows 2003 SP1 RAS Server, configured as a
VPN Server accepting only inbound VPN IPSec connections. The RAS server is
configured as a router (LAN routing only) and a remote access server. VPN
client IP address assignment is over the internal DHCP server in the LAN and
is working fine. The DHCP Relay agent is installed and configured.
The interface connected to the internet is protected by the Windows
firewall, and all internet access (except IPsec) is disabled by the Windows
firewall. So we created some static routes so that VPN clients can access
intranet ressources.
The problem is that sometimes when VPN clients sucessfully to the VPN
server, this static routes are getting wrong entries! After disconnecting,
the routing table is ok again.
Example:
Static entry 172.0.0.0 255.0.0.0 172.29.16.1 172.29.16.6
1
172.0.0.0 is the intranet, 172.29.16.1 is the LAN internal internet gateway,
172.29.16.6 is the IP address of the LAN interface of the VPN RRAS Server.
With this entry, everything works fine.
When a VPN client connects, "route print" shows the following entry (among
others):
172.0.0.0 255.0.0.0 172.29.16.52 172.29.16.58 1
Both addresses 172.29.16.52 and 172.29.26.58 are IP addresses of the DHCP
scope, assigned to the VPN server.
Does anybody have an idea what's going on here? Thank you all in advance for
any help!
Franz
VPN Server accepting only inbound VPN IPSec connections. The RAS server is
configured as a router (LAN routing only) and a remote access server. VPN
client IP address assignment is over the internal DHCP server in the LAN and
is working fine. The DHCP Relay agent is installed and configured.
The interface connected to the internet is protected by the Windows
firewall, and all internet access (except IPsec) is disabled by the Windows
firewall. So we created some static routes so that VPN clients can access
intranet ressources.
The problem is that sometimes when VPN clients sucessfully to the VPN
server, this static routes are getting wrong entries! After disconnecting,
the routing table is ok again.
Example:
Static entry 172.0.0.0 255.0.0.0 172.29.16.1 172.29.16.6
1
172.0.0.0 is the intranet, 172.29.16.1 is the LAN internal internet gateway,
172.29.16.6 is the IP address of the LAN interface of the VPN RRAS Server.
With this entry, everything works fine.
When a VPN client connects, "route print" shows the following entry (among
others):
172.0.0.0 255.0.0.0 172.29.16.52 172.29.16.58 1
Both addresses 172.29.16.52 and 172.29.26.58 are IP addresses of the DHCP
scope, assigned to the VPN server.
Does anybody have an idea what's going on here? Thank you all in advance for
any help!
Franz