Forefront Edge Security Virtual Private Networks ForumA forum for the discussion of issues and ideas regarding VPN site-to-site connectivity and roaming client VPN access in Forefront Edge Security (ISA Server).© 2009 Microsoft Corporation. All rights reserved.Mon, 30 Nov 2009 09:08:22 Z00830a0b-4254-45e0-81ca-fbbbcd608de8http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/16d224f3-bb2c-4899-9686-2e6ba22d86c8http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/16d224f3-bb2c-4899-9686-2e6ba22d86c8rnc3009http://social.technet.microsoft.com/Profile/en-US/?user=rnc3009VPN client route over site to site vpn ISA 2006I have enabled VPN client access and created a site to site VPN (ipsec)<br/> The VPN clients are on 10.10.20.x (RRAS assigned)<br/> The ISA is on 10.10.10.x lan<br/> The remote site is 147.89.x.x<br/> <br/> How do I get the VPN clients to route to the remote network. Currently they just route over their normal default gateway. <br/> <br/> We used to have this setup on a Cisco and it automatically placed an entry in the routing table of the clients for 147.89.x.x, but I can't see how to do it with ISAThu, 26 Nov 2009 17:22:23 Z2009-11-30T09:08:22Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/1c3e1018-2c68-459e-9aca-5d14160cb57ehttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/1c3e1018-2c68-459e-9aca-5d14160cb57eGavinChambers9http://social.technet.microsoft.com/Profile/en-US/?user=GavinChambers9Oracle NET v2 S2S VPN through ISA 2006Hi,<br/><br/>I hope somebody has come across this issue before, i'll try to keep it as breif as possible. We have a S2S VPN between and Juniper SSG and ISA 2006. The tunnel comes up fine and we are able to route between Enc-Domains no problems. We have a Oracle 10g DB server behind the ISA server which is monitored using SQLNet v2 over the VPN from behind the Juniper. Connecting to the DB is no problem on port 1521, we can see the connections passing through the ISA when telnetting on 1521 the policy is 'ANY tcp/udp' traffic, when telnetting the connection is made in the telnet session. However because of the way that SQLNetV2 (used in Oracle 8 onwards) handles connections in - apparently requesting the client to connect in on another port than 1521 I think that this is failing despite the ANY flag, see following link.<br/><br/>http://www.orafaq.com/maillist/oracle-l/2000/07/21/0173.htm<br/><br/>Now from experience Juniper and Checkpoint firewalls have a specified SQLNetv1 and V2 service profiles that must in some way allow for this type of connection. Can anyone tell me if ISA has allowed for this and if not can this custom service be created. Has anyone else experienced and overcome this problem?<br/><br/>Thank You.Fri, 13 Nov 2009 12:34:17 Z2009-11-23T02:06:05Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/944a3d1f-7aeb-40a2-b4d7-c407c1e56cc7http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/944a3d1f-7aeb-40a2-b4d7-c407c1e56cc7artemnethttp://social.technet.microsoft.com/Profile/en-US/?user=artemnetIsa 2006. IPSec VPN vs. Kerberos, LDAP<p>Good day.<br/>Our config: DC &lt;- Cisco 851 &lt;- Site-to-Site IPSec -&gt; ISA 2006 Standard -&gt; DC<br/>Few days ago we find replication between this DC`s dont work.<br/>In ISA Monitoring list of different errors - isa blocs Kerberos-SEC (TCP), LDAP, Unidentified IP Traffic (diff. ports). All this errors comes with empty Rule field.<br/>All other traffic work perfect.<br/>We enable IPSec Logging on ISA and this is the events:<br/>Event Type: Information Event Source: IPSec Event Category: None Event ID: 4291 Date: 11.11.2009 Time: 12:51:48 User: N/A Computer: ХХХ Description: The IPSec driver has dropped the following outbound packet: Source IP Address: Х.Х.Х.Х Destination IP Address: У.У.У.У Protocol: 6 Source Port: 35278 Destination Port: 88 Offset for IPSec status code: 0x14 Offset for Offload status code: 0x10 Offset for Offload flags: 0x20 Offset for packet start: 0x28 For more information, see Help and Support Center at <a href="http://go.microsoft.com/fwlink/events.asp">http://go.microsoft.com/fwlink/events.asp</a>. Data: 0000: 00 00 2a 00 06 00 76 00 ..*...v. 0008: 00 00 00 00 c3 10 00 40 ....Ã..@ 0010: 00 00 00 00 01 00 00 c0 .......À 0018: 00 00 00 00 00 00 00 00 ........ 0020: 00 00 00 00 00 00 00 00 ........ 0028: 45 00 05 dc 7f c7 40 00 E..ÜÇ@. 0030: 7f 06 d2 25 ac 10 04 04 .Ò%¬... 0038: ac 10 48 0a 89 ce 00 58 ¬.H.‰Î.X 0040: da 6c f6 a2 f6 a5 b2 07 Úlö¢ö¥². 0048: 50 10 ff ff 36 f3 00 00 P.ÿÿ6ó.. 0050: 00 00 .. <br/><br/>Isa works on Windows Server 2003, reg value NoDefaultExempt=3<br/><br/>Thanks for any help.</p>Wed, 11 Nov 2009 14:20:47 Z2009-11-20T02:21:43Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/3e260663-f364-4757-a5dd-7a6718d77a17http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/3e260663-f364-4757-a5dd-7a6718d77a17shoaib_okhttp://social.technet.microsoft.com/Profile/en-US/?user=shoaib_okSonic Wall Global VPN clientHi, we have a ISA Server 2006 Standard.  I'm trying to setup a SonicWall Global VPN client from a PC internally to access an external network.  Following this article <a href="http://www.isaserver.org/articles/IPSec_Passthrough.html"><span style="color:#003399">http://www.isaserver.org/articles/IPSec_Passthrough.html</span></a> <br/>got me connected, but I'm not receiving an IP addr.  It kept indicating &quot;acquiring network address&quot; and stays there forever. Can anyone help pls?Wed, 04 Nov 2009 14:01:08 Z2009-11-06T08:14:57Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/1e30d1d3-0f17-41eb-a1d6-c261d47ba74bhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/1e30d1d3-0f17-41eb-a1d6-c261d47ba74bCasinoTechhttp://social.technet.microsoft.com/Profile/en-US/?user=CasinoTechIssues with Outbound Cisco VPN Client connection through ISA 2004<p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;font-family:Arial">We have a few computers which need to be able to connect to a database on a server inside an external network. From these computers a VPN tunnel is created to the VPN Server in the external network using the Cisco VPN Client with IKE Client - UDP port 500 and IPSec NAT-T Client - UDP port 4500. I have created a rule on our ISA 2004 server which allows these Protocols between the IP addresses of our computers and the external VPN Server.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;font-family:Arial"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;font-family:Arial">On the computers, the VPN connection shows that it has been connected and the ISA logs confirm this. However, no traffic is actually passed through the VPN tunnel with the Firewall Client installed on the computers. Immediately, I can see DNS traffic bound for the external network in the ISA logs, traffic which should be passing through the VPN tunnel. The same is true for the SQL traffic when attempting to create the ODBC connection, no connection can be established.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;font-family:Arial"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;font-family:Arial">With the firewall client uninstalled, the ISA logs show the connection of the VPN Tunnel and then nothing else as the DNS and SQL traffic are passed through the VPN Tunnel and connection to the database is established.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;font-family:Arial"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;font-family:Arial">What do I need to do for the traffic to be passed through the VPN Tunnel, with the Firewall Client installed on the computers?</span></p>Thu, 05 Nov 2009 00:04:42 Z2009-11-06T00:05:36Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/5ab6f680-cd19-4365-a762-569cd812d273http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/5ab6f680-cd19-4365-a762-569cd812d273lee159http://social.technet.microsoft.com/Profile/en-US/?user=lee159IAS ErrorHi We have a WIn2003 R2 Domain controller that is also running RRAS and we are getting this error everytime a user logs in through VPN to our system. It onlys happens once in the day for that user even if the user logs in and out numerous times that day. If he logs in again next day we get the error again. The error we get is <br/><br/>Event Source:    IAS<br/>Event Category:    None<br/>Event ID:    5052<br/>Date:        8/17/2009<br/>Time:        12:53:26 PM<br/>User:        N/A<br/>Computer:    <em>SERVERNAME</em> <br/>Description:<br/>The description for Event ID ( 5052 ) in Source ( IAS ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: DOMAIN.LOCAL.&quot;<br/><br/>Thanks for your help.<br/><br/>Forgot to mention that we do not use IAS as part of our VPN<br/><br/>Fri, 30 Oct 2009 08:30:39 Z2009-11-06T09:51:46Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/71f32686-bff5-45c1-aad2-f969cb856f4fhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/71f32686-bff5-45c1-aad2-f969cb856f4fErdal01http://social.technet.microsoft.com/Profile/en-US/?user=Erdal01how connect 2 networks with VPNHello people,<br /> <br /> I am probably going to ask something common, but I haven't figured this one completely.<br /> A customer has a small network installed with SBS 2003 server.<br /> Now he has opened another office and from the second office we can connect to the head office with VPN.<br /> This works quite well, but now I want to merge the second office with the head office, so we would have only one network.<br /> The reason is that it would be much easier to manage and we can share resources.<br /> I know there are VPN routers that can do the job, but is there an alternative on how to connect the 2 networks?<br /> <br /> Regards,<br /> Erdal<br /> <br />Fri, 16 Oct 2009 21:58:37 Z2009-10-20T11:02:48Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/b5c615c6-0ce8-4aed-95d9-64dad84ddad1http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/b5c615c6-0ce8-4aed-95d9-64dad84ddad1deckihttp://social.technet.microsoft.com/Profile/en-US/?user=deckiISA 2006 VPN with a WIN XP SP2Hi,<br /> My corporate network uses a ISA 2006 FW. The admin created a new VPN connection on my XP laptop and I was able to connect to the shared resources on our LAN once I established the VPN.<br /> <br /> So, last week, I purchased a new wireless N router and at the same time, my XP laptop died and I had the admin replace the HD.<br /> <br /> Now, I just reinstalled all of my programs and I had the admin recreate the VPN connection and at the same time, we installed my new Wireless N router at my home.<br /> <br /> Issue: I can successfully establish the VPN, but I cannot access any network resources in the corporate office. I cannot PING by IP or hostname, RDP, or cannot even access shared files. <br /> I can do a IPCONFIG, and my laptop does pull an IP address properly from the ISA FW.<br /> <br /> I have disabled my firewalls and AV programs.<br /> <br /> So, Ive come to conclude that two things have changed.&nbsp; I installed a new router, and I had to have my laptop reformatted.<br /> The admin says there is nothing he has to do on his end to accept the new VPN connection.<br /> Could it be something in my new wireless router that is blocking shared resources? Since I can connect to the VPN, but not shared resources, to me, it seems that the VPN is working.<br /> <br /> Any help would be very appreciated.<br />Tue, 13 Oct 2009 12:51:16 Z2009-10-19T11:33:19Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/128d619e-4279-44b1-966a-c674fa5e861ehttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/128d619e-4279-44b1-966a-c674fa5e861eBryan Almquisthttp://social.technet.microsoft.com/Profile/en-US/?user=Bryan%20AlmquistWake on LAN through Site to Site VPNI'm having trouble getting Wake on LAN to work across an ISA 2006 site to site VPN.  Attemping this using unicast packets.  I can see the traffic on both sides of the vpn link.  Logs below.  Still, the target machine doesn't wake up.  When I send the same WoL packet on the local subnet it works fine. Any ideas?<br/><br/>Initiated Connection<br/>Log type: Firewall service<br/>Status:<br/>Rule: Allow Wake on LAN to Branch<br/>Source: Internal (xxx.xxx.xxx.xxx:4786)<br/>Destination: Branch1 (yyy.yyy.yyy.yyy:9)<br/>Protocol: Wake on LAN<br/>Result Code: 0x0 ERROR_SUCCESS<br/><br/>Closed Connection<br/>Log type: Firewall service<br/>Status:<br/>Rule: Allow Wake on LAN to Branch<br/>Source: Internal (xxx.xxx.xxx.xxx:4786)<br/>Destination: Branch1 (yyy.yyy.yyy.yyy:9)<br/>Protocol: Wake on LAN<br/>Result Code: 0x80074e20 FWX_E_GRACEFUL_SHUTDOWN<br/><br/>Fri, 25 Sep 2009 01:35:36 Z2009-10-09T19:52:06Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/b203ccb9-65e9-4c81-bd53-c0b510b62079http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/b203ccb9-65e9-4c81-bd53-c0b510b62079bladibla3http://social.technet.microsoft.com/Profile/en-US/?user=bladibla3After Cisco VPN client uninstalled, Internet Connection Sharing is f*cked upI've installed a recent Cisco VPN clientin Windows XP SP3, fully patched.<br/>And uninstalled it again after a succesful test connecting to work.<br/>But now the other computers on my LAN cannot use Internet Conection Sharing (ICS) _completely_.<br/>DNS works and *some* HTTP pages load, but others don't.<br/>F.e. google.com and imdb.com work, but microsoft.com does not work.<br/><br/>Can anyone help please please? I've tried all kinds of firewall changes / reset but nothing changes.<br/><br/>Thanks in advance,<br/>Richard<br/><br/>BTW: Looking arounf the internet I see that the &quot;Cisico VPN client&quot; has caused a million hours of grief already. Grrr.<br/>Fri, 18 Sep 2009 16:03:58 Z2009-09-29T01:59:28Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/c18dc981-1847-4d28-991e-fdba05142ef5http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/c18dc981-1847-4d28-991e-fdba05142ef5David Jerwoodhttp://social.technet.microsoft.com/Profile/en-US/?user=David%20JerwoodForefront TMG MBE - Remote VPN - RSA SecureIDI have built a new Forefront Threat Management Gateway MBE server running RSA Authentication manager 6.3.1 on a Windows 2008 Server. Additionally I am running RSA SecureID 6.1.3 Server on Windows 2003 hyperv machine. Running a test authentication from the TMG to RSA is successful.<br/>Configuration as per <a href="http://technet.microsoft.com/en-us/library/cc441545.aspx">http://technet.microsoft.com/en-us/library/cc441545.aspx</a><br/><br/>But how do I actually configure my PPTP VPN connection to require SecureID Details? Currently when I connect via vpn it connects without prompting for my RSA details just my username and password.<br/><br/>Any help would be much appreciated.Fri, 18 Sep 2009 14:17:13 Z2009-09-18T14:17:15Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/01628ae1-b7ab-4081-911c-37798d21e3f9http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/01628ae1-b7ab-4081-911c-37798d21e3f9lovrovrhttp://social.technet.microsoft.com/Profile/en-US/?user=lovrovrOutbount VPN connection on ISA Server 2004Hello,<br/><br/>I have ISA Server 2004 and several Site-to-Site VPN connections. All connections works fine.<br/><br/>I have problem with one connection, where I cannot make VPN connection. It is PPTP connection and I got an error on ISA Server.<br/>I also got an error if I tried to establish connection from client behind the ISA server. I got an error 619.<br/>If I connect this client directly to the Internet, I can establish the connection.<br/>I also tried to established VPN connection to several destination and all gone fine.<br/><br/>I also tried to turn off ISA server and set up the same IP to my client and I succeed to establish connection.<br/><br/>Is there any idea, what can cause problem to only one VPN connection?<br/><br/>Regards,<br/>Lovro<br/>Mon, 31 Aug 2009 13:33:27 Z2009-09-08T06:26:10Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/f92d8239-a510-4d35-8b41-e9d30e137213http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/f92d8239-a510-4d35-8b41-e9d30e137213DawidGKhttp://social.technet.microsoft.com/Profile/en-US/?user=DawidGKISA 2006 EE VPN for users from trusted domainHi,<br/>  <p style="margin:0in;font-family:Verdana;font-size:10pt" lang=en-US>is it possible to authenticate PPTP VPN users from Windows Server 2008 R2 RC Domain A which is trusted by Windows Server 2003 R2 Domain B (validated ONE way trust)<span style="">  </span>on NLB of ISA Servers 2006 Enterprise SP1? Please, give me some hints or helpful links 'cos I'm desperate.<br/><br/>Thanx,<br/>Dawid</p>Tue, 21 Jul 2009 08:38:00 Z2009-08-24T15:21:02Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/60d40cdb-0a8a-43dc-8211-a42deff1c67dhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/60d40cdb-0a8a-43dc-8211-a42deff1c67dguysonhttp://social.technet.microsoft.com/Profile/en-US/?user=guysonEvent ID ( 5052 ) in Source ( IAS ) I recently migrated from an NT4 domain to a Server 2003 With Active Directory domain. Following the instructions in Article 884452 I implemented a Small Business Server into an existing Active Directory domain. The SBS server is the Primary Domain controller. The other DCs are configured as backup DCs. (2 of them)<br/> <br/> Today I was trying to install Exchange Server 2003. SBS had me run through an internet connection wizard. As well as forest prep and domain prep. Ever since these events happened my remote workers can no longer connect to our RRAS server (on another server entirely). They are receiving a 691 error. <br/> <br/> When I check in the event viewer, I am getting the following error message: &quot;Event Type:    Error<br/> Event Source:    IAS<br/> Event Category:    None<br/> Event ID:    5052<br/> Date:        8/17/2009<br/> Time:        12:53:26 PM<br/> User:        N/A<br/> Computer:    <em>SERVERNAME</em> <br/> Description:<br/> The description for Event ID ( 5052 ) in Source ( IAS ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: DOMAIN.LOCAL.&quot;<br/> <br/> Can someone please advise what I need to do to allow remote connectivity again. I am not running ISA (AFAIK).<br/> <br/> Thanks in advanceMon, 17 Aug 2009 17:06:57 Z2009-08-24T01:36:28Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/139dd12a-588f-4efc-909a-02ed7eb21a71http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/139dd12a-588f-4efc-909a-02ed7eb21a71Leonard McCoyhttp://social.technet.microsoft.com/Profile/en-US/?user=Leonard%20McCoyPUblishing to specific private IP for an IPSEC VPN partner<p>I have an edge only two member load balanced ISA 2004 EE array with only internal and external interfaces. I have a partner site that I need to create an IPSEC VPN tunnel with. They route to a network that has the same IP scheme that I have on my internal LAN, so we will need to NAT to each other. He is going to NAT his side behind a 150.30.0.0/16 and needs me to NAT behind 10.163.195.16/29 (this range works for me).</p> <p>I've created many IPSEC VPNs before but none where the other side routed to a network with the same IP scheme as ours. I've never published a server to a private IP address. The only thing I've published was my e-mail server to a public address.</p> <p>How do I publish an internal server to a specific private IP address for an IPSEC VPN partner site to access? I'm assuming I will need to add an IP address to one of the NICs? If so which one, the external or internal? I guess I'll need to set up a NAT route rule between the VPN network and my internal?</p> <p>Any help would be appreciated.<br/><br/>Oh, I forgot to mention; this is not a web publishing rule, but needs to be a server publishing rule for a protocol that I will define.</p> <hr class=sig> Leonard McCoySun, 16 Aug 2009 21:01:18 Z2009-08-18T08:20:05Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/84cadcdb-8f45-41ca-b785-9c99b1002ef1http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/84cadcdb-8f45-41ca-b785-9c99b1002ef1lauramdsmhttp://social.technet.microsoft.com/Profile/en-US/?user=lauramdsmRandom IP requesting and making successful connections ... should only have host and private vpn IP's requesting connections.<p>ISA Server 2006<br/>Users connect through VPN and get assigned a 10.10.10.x IP address.<br/><br/>Looking through the logs, under &quot;C_IP&quot; (IP of requesting client) I see some IP addresses of the host (for updates and such, makes sense) and some private IP addresses of clients connecting through the VPN (10.10.10.x) but then I also see some random IP addresses. WHAT ARE THESE??<br/><br/>A whois does not give me much information at all... It shows they are are using HTTP to access websites... and they are being provided the service by my host IP address.<br/><br/>No one else should be connecting other than the host connections and the vpn users with the private IPs, so where are these coming from????<br/><br/>THANKS.</p>Thu, 13 Aug 2009 18:21:14 Z2009-08-21T09:29:53Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/e376ff06-f867-4dbc-bfe6-887dfa5bcf1dhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/e376ff06-f867-4dbc-bfe6-887dfa5bcf1dmissybuffhttp://social.technet.microsoft.com/Profile/en-US/?user=missybuffGetting rid of red x's.How do I get rid of the red x's that come up on my web pages instead how what should be there?<br/><br/>And how can I work on web pages that don't work with Explorer 8?Mon, 10 Aug 2009 19:09:11 Z2009-08-18T02:00:46Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/ad901666-2a8f-4f89-b021-bf5648abbf3ehttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/ad901666-2a8f-4f89-b021-bf5648abbf3eStephen Starkhttp://social.technet.microsoft.com/Profile/en-US/?user=Stephen%20StarkLDAP Integration SetupWe are trying to setup a new ISA server in our DMZ that will not be a domain member, but rather will authenticate VPN users against the domain via LDAP.  I believe we have all of the LDAP settings correct, and have verified connectivity to the domain server using LDP.exe (as well as a connectivity verifier).  However, when we go to the Groups tab in the VPN Client Properties dialouge box and try to add a new group from the domain, we are only given the choice to add groups from the local machine...as if it does not see the domain server.<br/><br/>Does anyone have any setup or troubleshooting tips around this problem?<br/><br/>Thanks in advance.<br/><br/>Stephen<hr class="sig">Stephen StarkMon, 27 Jul 2009 21:30:33 Z2009-08-03T01:52:47Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/e329dcb7-9fe8-4d25-9344-338a0f3b0c50http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/e329dcb7-9fe8-4d25-9344-338a0f3b0c50Vinjanahttp://social.technet.microsoft.com/Profile/en-US/?user=VinjanaISA serverIn virtual lab i have configured One web server in internal network and one client in external. I published two websites <a href="http://www.deny.com">www.deny.com</a> and <a href="http://www.access.com">www.access.com</a> in internal web server. I tried to redirect the web site if user from client want to access <a href="http://www.deny.com">www.deny.com</a> but i can't redirect itTue, 14 Jul 2009 07:48:03 Z2009-07-21T20:35:36Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/df75edd6-3cfb-45a0-8c0c-38472accddafhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/df75edd6-3cfb-45a0-8c0c-38472accddafEl Zilchohttp://social.technet.microsoft.com/Profile/en-US/?user=El%20ZilchoRAS VPN problem following windows updates<p>We run ISA 2006 SP1 on Windows 2003 Std. SP2. It's a Celestix firewall appliance. Everything was running perfectly until recently when we applied a raft of Windows critical and security updates (about 30+). Since then if you restart the firewall PPTP MS VPN clients cant connect. Restarting the RAS service within ISA Manager doesn't clear the problem, if you restart the firewall service, then RAS it all works again and is stable.<br/><br/>I need to find out which Windows update has messed the VPN up but removing each of the 30 updates one by one and restarting will be a pain. Can anyone suggest any updates that might be at fault here post Server 2003 SP2?<br/><br/>I was wondering if I would have claim to a free support issue from Microsoft on this, given the circumstances.<br/><br/>Any help appreciated.<br/><br/>Paul</p>Thu, 16 Jul 2009 08:09:34 Z2009-07-18T19:09:41Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/d0951399-6874-46ed-be24-cc567d394855http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/d0951399-6874-46ed-be24-cc567d394855Helpdesk-LVCCULhttp://social.technet.microsoft.com/Profile/en-US/?user=Helpdesk-LVCCULSite to Site VPN Connection problems    I am adding a 4th Branch office to our network via VPN. Currently, 3 branch offices are running ISA 2006 Std with ISA 2006 EE at the Main office. I would like to set up the 4th office using a Netgear FVS318 VPN router.<br/>    I set up the Site to Site vpn using IPSec ( recomended in the setup with 3rd party VPN ) rather than the L2TP that the other branches are set with. With all the settings checked and double checked I have no connectivity with the Netgear router. <br/>    I can ping the Ext. IP address of the router but not the lan ip address<br/>    The ISA EE connectivity verifiers report Time Out errors<br/>    The Netgear router has access to the Internet<br/>I feel that I am missing something , but I had this issue before with a Linksys  vpn router and was not able to configure it.  <br/>Any suggestions?<br/>Wed, 08 Jul 2009 23:39:58 Z2009-07-20T03:56:05Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/be0b7674-6b78-4c0c-a5b4-84a2f27ab69ahttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/be0b7674-6b78-4c0c-a5b4-84a2f27ab69aGeneTekAhttp://social.technet.microsoft.com/Profile/en-US/?user=GeneTekAIPSec L2TP site-to-site VPN from ISA 2004 on SBS to Windows 2003 - no longer working<p>As of today the remote office Windows 2003 Server was no longer able to connect in our site-to-site VPN.  There were no changes to either server.<br/><br/>We have since tried anything we could think of.  We are using pre-shared key rather than certificates so the pre-shared keys were re-entered, we rechecked the AD VPN user's to make sure they were active, IPSec and RRAS services were restarted at both locations.  And we checked event logs (more on that below).  Client's connecting through PPTP are still able to connect.<br/><br/>Event log: Error 20111 from RemoteAccess &quot;A Demand Dial connection to the remote interface VPN_*HEADOFFICE* on port VPN3-127 was successfully initiated but failed to complete successfully because of the  following error: The L2TP connection attempt failed because security negotiation timed out.<br/><br/>Prior to that error, however, there are two events 20186 &quot;<span style="font-size:xx-small">Interface VPN_*HEADOFFICE* is now reachable.&quot; and 20180 &quot;<span style="font-size:xx-small">Interface VPN_*HEADOFFICE* is unreachable because the connection attempt failed.&quot;<br/><br/>So it appears to make a connection, but then drops the connection.  I've also looked into the Oakley logs and found the following:<br/> <ul style="margin-top:0cm" type=disc> <li>  <ul style="margin-top:0cm" type=circle> <li>  <ul style="margin-top:0cm" type=square> <li>  <ul style="margin-top:0cm" type=disc> <li>  <ul style="margin-top:0cm" type=circle> <li class=MsoNormal style="text-indent:-18pt;margin:0cm 0cm 0pt;tab-stops:list 180.0pt"><span style="font-family:'Times','serif'"><span style="font-size:small"><span style=""> </span>6-08: 22:20:13:367:c04 <span style="background:yellow">MatchMMFilter failed 13013</span></span></span></li> <li class=MsoNormal style="text-indent:-18pt;margin:0cm 0cm 0pt;tab-stops:list 180.0pt"><span style="font-family:'Times','serif'"><span style="font-size:small"><span style=""> </span>6-08: 22:20:13:367:c04 Responding with new SA 0</span></span></li> <li class=MsoNormal style="text-indent:-18pt;margin:0cm 0cm 0pt;tab-stops:list 180.0pt"><span style="font-family:'Times','serif'"><span style="font-size:small"><span style=""> </span>6-08: 22:20:13:367:c04 <span style="background:yellow">HandleFirstPacketResponder failed 3601</span></span></span></li> </ul> </li> </ul> </li> </ul> </li> </ul> </li> </ul> <p>I wasn't able to locate any information that would resolve this issue based on the highlighted items.  There are other people reporting similar issues, but no one with a resolution.<br/><br/>I also noticed that the &quot;Receive: (get) SA&quot; value was &quot;0x00000000&quot; for transmissions from the Remote office VPN.  Obviously those should be filled with a real value.  When I looked at the oakley log in more detail I was able to find SA values but they would then be followed by other transmissions where the SA was reset back to 0.  I wasn't able to find any information about the cause of this.<br/><br/>Finally, I found this in the log:</p> <ul style="margin-top:0cm" type=disc> <li>  <ul style="margin-top:0cm" type=circle> <li>  <ul style="margin-top:0cm" type=square> <li>  <ul style="margin-top:0cm" type=disc> <li>  <ul style="margin-top:0cm" type=circle> <li class=MsoNormal style="text-indent:-18pt;margin:0cm 0cm 0pt;tab-stops:list 180.0pt"><span style="font-family:'Times','serif'"><span style="font-size:small">Sending: SA = 0x07DB3BC8 to xxx.xxx.xxx.xxx:Type 2.500</span></span></li> <li class=MsoNormal style="text-indent:-18pt;margin:0cm 0cm 0pt;tab-stops:list 180.0pt"><span style="font-family:'Times','serif'"><span style="font-size:small">sadb_schedule_kill_oldPolicy_sas</span></span></li> <li class=MsoNormal style="text-indent:-18pt;margin:0cm 0cm 0pt;tab-stops:list 180.0pt"><span style="font-family:'Times','serif'"><span style="font-size:small">isadb_set_status sa:07DB3BC8 centry:00000000 status 3619</span></span></li> <li class=MsoNormal style="text-indent:-18pt;margin:0cm 0cm 0pt;tab-stops:list 180.0pt"><span style="font-family:'Times','serif'"><span style="font-size:small">New policy invalidated SAs formed with old policy</span></span></li> <li class=MsoNormal style="text-indent:-18pt;margin:0cm 0cm 0pt;tab-stops:list 180.0pt"><span style="font-family:'Times','serif'"><span style="font-size:small"><span style=""> </span>Sent first (SA) payload<span style="">  </span>Initiator.<span style="">  </span>Delta Time 30<span style="">   </span>0x0 0x0</span></span></li> <li class=MsoNormal style="text-indent:-18pt;margin:0cm 0cm 0pt;tab-stops:list 180.0pt"><span style="font-family:'Times','serif'"><span style="font-size:small"><span style=""> </span>constructing ISAKMP Header</span></span></li> <li class=MsoNormal style="text-indent:-18pt;margin:0cm 0cm 0pt;tab-stops:list 180.0pt"><span style="font-family:'Times','serif'"><span style="font-size:small">constructing DELETE. MM 07DB3BC8</span></span></li> <li class=MsoNormal style="text-indent:-18pt;margin:0cm 0cm 0pt;tab-stops:list 180.0pt"><span style="font-family:'Times','serif'"><span style="font-size:small"><span style=""> </span>6-08: 22:49:27:874:c04</span></span></li> </ul> </li> </ul> </li> </ul> </li> </ul> </li> </ul> <p>What that appears to be saying is that a new policy is invalidating and destroying the old policy (the old SA?).  However, we did not implement any new policy?!  No changes were made until after the VPN broke and I have kept notes of those changes (the most significant being the change in the shared key).<br/><br/>Ideas anyone?<br/><br/><br/></p> </span></span></p>Tue, 09 Jun 2009 03:22:40 Z2009-06-24T06:43:03Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/bc7d7e9a-88fd-4a5e-88a0-526a7c38f171http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/bc7d7e9a-88fd-4a5e-88a0-526a7c38f171RussSchttp://social.technet.microsoft.com/Profile/en-US/?user=RussScSite to Site VPN not passing traffic on port 80Hi, <br/> <br/> <br/> I currently have configured a site to site VPN to a 3rd party hosting some web servers for us <br/> <br/> Although i have configured ISA to pass all traffic types across the VPN tunnel ISA does not appear to pass traffic on port 80 ( although i can connect to a telnet session on port 80 )<br/> <br/> All other traffic types appear to route correctly ( ie 443 )<br/> <br/> <br/> <br/> I have followed advice with regards to setting up a 2nd HTTP protocol that does not apply the Web proxy filter and denied the use of the original HTTP protocol for this firewall rule<br/> <br/> Although this does not seem to have had the desired effect <br/> <br/> <br/> ISA returns an error <span>10065 A socket operation was attempted to an unreachable host on monitoring</span> with the additional information below :<br/> <br/> <ul style=""> <li><strong>Client agent: </strong> Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10 (.NET CLR 3.5.30729)</li> <li><strong>Object source: </strong> Internet (Source is the Internet. Object was added to the cache.)</li> <li><strong>Cache info: </strong> 0x0</li> <li><strong>Processing time: </strong> 62969 ms</li> <li><strong>MIME type: </strong> </li> </ul> can anyone advise ? .. has anyone seen this in thier environment?<br/> <br/> Kind RegardsFri, 05 Jun 2009 15:48:14 Z2009-06-15T07:58:55Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/b403498d-0962-4985-a8a6-63698a84ff43http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/b403498d-0962-4985-a8a6-63698a84ff43Montcohttp://social.technet.microsoft.com/Profile/en-US/?user=MontcoISA ipsec site-to-site VPN limit proposed addresses<p>We've got a few ISA 2004 servers in-place, and a relatively complex network (multiple subnets with rules controlling traffic between them). We support a few VPN connections, and we're attempting to create another one. <br/>What makes the new one interesting is that it is a simple IPSEC connection to a Cisco router owned by an external entity. I've created the remote site, an appropriate network rule (only two of our subnets need to access the remote site), and the appropriate firewall rules. All should be well.<br/>However, I've hit a stumbling block. Although I can easily restrict (using network rules) which local networks can use the new VPN, and (using firewall rules) what traffic to allow, the IPSEC proposal still includes ALL of my internal networks (well, all of the ones that this particular ISA box uses). I haven't been able to find anywhere in the GUI that lets me limit that. I'd be happy to do it from a command-line as well, but I'm not even sure that I can see a way to do that, either. In essence, I want to make the IPSEC proposal include ONLY the appropriate subnets, and not ALL of our networks. Including all of them will automatically make the VPN connection fail, as I'm sure some of our internal (private IP-range) networks overlap with the ones used by the remote site. <br/>Any help that anyone can supply would be very much appreciated. Thanks!</p>Fri, 15 May 2009 14:21:43 Z2009-06-08T16:46:03Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/0d57a60d-a335-4c03-8b94-9a54e7ace18ahttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/0d57a60d-a335-4c03-8b94-9a54e7ace18aARAS Securityhttp://social.technet.microsoft.com/Profile/en-US/?user=ARAS%20SecurityProblem with Site to Site vpn with ISA 2004 and SBS2003I recently configured a site to site VPn from our branch to main office.<br/>After 10 days continuesly work, it stops today.<br/><br/>On the main site it says : <span style="font-size:xx-small"> <p>A Demand Dial connection to the remote interface xxxx_be_sts_vpn on port VPN4-2 was successfully initiated but failed to complete successfully because of the following error: Access was denied because the username and/or password was invalid on the domain<br/><br/>To be sure I changed the credentials in both servers to meet the same passwords....in User in AD, but also in ISA and RAS.<br/><br/>How to find out what the problem is...nothing changed on hardware or IP side.</p> </span>Tue, 02 Jun 2009 11:48:20 Z2009-06-08T06:13:29Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/4ecdaf9e-aa07-4410-9877-696150f10acehttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/4ecdaf9e-aa07-4410-9877-696150f10aceChris Downeshttp://social.technet.microsoft.com/Profile/en-US/?user=Chris%20DownesSite to Site VPN for remote accessI have been asked to setup a site to site VPN for one of our customers. We normally support our customers using webex but this customer wants to use a vpn for remote access. I've received the info from our customer but have a couple of questions before I implement it (I've never set this up before) We are using SBS2003 with ISA 2004<br/><br/>1. They have specified AES256 as the encryption but I can only see DES/3DES in ISA2004, is AES256 possible for IPSEC in ISA2004?<br/>2. Once the VPN is established will all outgoing traffic try to route over the VPN?<br/>3. If it will, can I set the VPN so it only routes RDP traffic for one IP address<br/><br/>Thanks.Fri, 05 Jun 2009 08:32:51 Z2009-06-11T10:40:20Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/6e6570cf-5cfb-4f43-84c2-514f8c16107ehttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/6e6570cf-5cfb-4f43-84c2-514f8c16107eMatt Jones.http://social.technet.microsoft.com/Profile/en-US/?user=Matt%20Jones.ISA Server 2006 Branch office array unable to connect to the CSS in main officeHello, <br/> <br/> I have set up a lab using ISA 2006 Enterprise Edition consisting of a single Enterprise with two arrays to simulate a main office/branch office site to site VPN scenario. I have configured the CSS in the main office to be located on the same box that is running ISA 2006 EE. No replica CSS has been deployed in the branch office and therefore the array member in the branch office is configured to connect to the CSS/ISA in the main office. The VPN connection is active and the branch ISA can communicate with a DC at the main office. <br/> <br/> The problem that I'm experiencing is that the ISA 2006 EE array member in the branch office array is unable to connect to the configuration storage server in Main office. Also, the main office CSS/ISA is failing to connect to the branch office array member as the mgmt console of the ISA/CSS shows that it's unable to retrieve information from the server in the branch array. <br/> <br/> When the branch office ISA tries to connect to the main office CSS/ISA, the logs on the main office array show that connections are being denied for the MS Firewall Storage and Control protocols. The source address is shown as the Branch ISA IP address assigned from the DHCP server on the main office internal network and the destination is the internal IP address of the CSS/ISA. When the main office CSS/ISA tries to retrieve information from the branch office array member, the logs show that connections are being denied to 'RPC (All Interfaces)'. In this case, the main office array logs show that the source address is the main office CSS/ISA IP address assigned from a static address pool configured on the branch ISA and the destination address is the internal IP address of the branch ISA. <br/> <br/> Can anybody please help? <br/> <br/> Thanks in advance.Thu, 04 Jun 2009 13:39:49 Z2009-06-04T20:52:44Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/bbd1e384-0d04-46f2-9683-c0dc41e870a3http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/bbd1e384-0d04-46f2-9683-c0dc41e870a3jcampbell76http://social.technet.microsoft.com/Profile/en-US/?user=jcampbell76Mac OS X 10.5 Client to ISA 2006 VPN via L2TP/IPsec<span style="border-collapse:collapse;color:#333333;font-family:Arial;font-size:12px;line-height:15px">I have been working diligently with our network engineer to get a Mac OS X 10.5 client to connect to our ISA 2006 VPN via L2TP/IPsec. I have searched high and low all over the place for information on this and I can't find much (not even &quot;it doesn't work&quot;) so there is room for hope here... I know a lot of people are interested in getting it to work, but may not have the resources to really solve it -- I do, and am willing to try, but need help from someone besides the two of us here... <br/><br/><br/>Here's the facts so far to cover where we are... <br/><br/>- ISA 2006 configured for VPN access via L2TP/IPsec. <br/><br/>- Confirmed configuration and accessibility; XP clients, even through NAT'ed home connections, either with PSKs or Certs can connect. <br/><br/>- Testing environment has been set up in the server room behind the external firewall to eliminate that variable (despite knowing Windows clients are OK though it). We are connected directly to the external interface of the ISA 2006 server so we are as hardwired as we can be to eliminate variables. <br/><br/>- Mac OS X 10.5 is the client in question. There have been older internet posts on 10.4 and prior, but that is not useful. PPTP works fine but is not viable for our needs. L2TP/IPsec is a MUST. Also, old posts alluded to a problem with MS-CHAPv2 -- we've tested with all auth methods enabled, but under 10.5, MS-CHAPv2 is supported (but I don't think we're even getting that far). <br/><br/>- Additional debug logging has been enabled for the OS X client (beyond it's publicly accessible setting of 'verbose'); We see it is failing at the end of Phase-1 negotiation. It appears that the proposals are being accepted by ISA (3DES, SHA1, etc) so we don't seem to have a problem with that part of it... <br/><br/>- The failure comes after the OS X client appears to send a Phase-1 packet, assumedly to complete that part of the process, and it does not digest what it gets back from the ISA server. It repeats this a handful of times until the connection timeout cuts us off. The timeout can be extended, but given the negotiation (on Windows) takes mere seconds, that doesn't seem to be the problem. <br/><br/>- Attempting to use a pure IPsec connection (using a 3rd party tool) gets through Phase-1 in its attempt, but dies in Phase-2 (assumedly since the tunnel isn't under L2TP so it fails with bad ID information). Regardless, this doesn't help much but assumedly tell us we can get farther than we are getting, so worth the mention. <br/><br/><br/>We have pretty extensive knowledge of both pieces of the puzzle (OS X and ISA) and have a solid test environment -- what I am hoping is that someone out there has the secret sauce or has some new ideas since we are pretty much deadlocked at this point. I'll take anything... <br/><br/>PS&gt; I can post log/config info if needed...</span>Wed, 03 Jun 2009 17:50:26 Z2009-06-10T05:13:04Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/e9406f83-2bde-4b2e-96cb-cc44cb32cac6http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/e9406f83-2bde-4b2e-96cb-cc44cb32cac6Baptiste Schwartzbarthttp://social.technet.microsoft.com/Profile/en-US/?user=Baptiste%20SchwartzbartVpn connection on a second domainHi,<br/><br/>I've a problem with my vpn client.<br/><br/>My Isaserver (ISA 2006 SP1 on Windows 2003 Server R2 SP1) was on my first domain and i've two domain with relashonship.<br/><br/>When i want to connect a VPN client on my isa when is account is on the <br/>second domain, i've a 691 error on the client.<br/><br/>I've insert the dns of the second domain on isaserver, i've add the client <br/>group on isaserver but it doesn't work.<br/><br/>Thank's you for your help. <br/>Tue, 19 May 2009 22:09:24 Z2009-05-25T19:42:26Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/3150125f-be5e-4b05-8741-511b713cd764http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/3150125f-be5e-4b05-8741-511b713cd764bgusenethttp://social.technet.microsoft.com/Profile/en-US/?user=bgusenettroubleshoot isa 2004 site to site vpn<br/> Hello,<br/> <br/> I need to create a site to site vpn using an isa 2004 set on a 2003 box on  my side and a netasq firewall on the other. I am not able to get the tunnel.<br/> <br/> This isa is already used for an other vpn which is working.<br/> <br/> The vpn uses a preshared key, and, as far as I can see, the parameters set on both sides are the same.<br/> The phase I completes but I never get the Phase II<br/> I have enabled auditing and oakley log to have information but they are not as usefull as I could hope :<br/> <br/> The security events are :<br/> <br/> <strong>IKE security association negotiation failed.<br/>  Mode: <br/> Data Protection Mode (Quick Mode)<br/> <br/>  Filter: <br/> Source IP Address 217.167.*.*<br/> Source IP Address Mask 255.255.255.255<br/> Destination IP Address 10.32.*.*<br/> Destination IP Address Mask 255.255.255.0<br/> Protocol 0<br/> Source Port 0<br/> Destination Port 0<br/> IKE Local Addr 217.167.*.*<br/> IKE Peer Addr 84.96.*.*<br/> IKE Source Port 500<br/> IKE Destination Port 500<br/> Peer Private Addr <br/> <br/>  Peer Identity: <br/> Preshared key ID.<br/> Peer IP Address: 84.96.*.*<br/> <br/>   Failure Point: <br/> Me<br/> <br/>  Failure Reason: <br/> IKE SA deleted before establishment completed<br/> <br/>  Extra Status: <br/> Processed third (ID) payload<br/> Initiator.  Delta Time 64<br/>  0x0 0x0</strong> <br/> <br/> <br/> On the Other side the logs for the netasq are :<br/> <br/> <strong>16:33:48.322662 FW_AC2i.isakmp &gt; Firewall_Externe.isakmp: isakmp: phase 1 I ident[E]: [encrypted id]<br/> 16:33:48.324747 Firewall_Externe.isakmp &gt; FW_AC2i.isakmp: isakmp: phase 1 R ident[E]: [encrypted id]<br/> 16:33:48.573812 FW_AC2i.isakmp &gt; Firewall_Externe.isakmp: isakmp: phase 2/others I oakley-quick[E]: [encrypted hash]<br/> 16:33:49.489603 FW_AC2i.isakmp &gt; Firewall_Externe.isakmp: isakmp: phase 2/others I oakley-quick[E]: [encrypted hash] 16:33:51.476120 FW_AC2i.isakmp &gt; Firewall_Externe.isakmp: isakmp: phase 2/others I oakley-quick[E]: [encrypted hash]<br/> </strong> <br/> We have tried to the parameters but we have never have any success with it.<br/> <br/> Could someone see what goes wrong or what I could do to get some more accurate details ?<br/> <br/> Best regards,<br/> <br/> -- <br/> BG<br/>Thu, 14 May 2009 08:28:24 Z2009-05-22T03:38:36Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/3f17b452-e0be-4592-9d05-2362e96ae062http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/3f17b452-e0be-4592-9d05-2362e96ae062Edward Forgacshttp://social.technet.microsoft.com/Profile/en-US/?user=Edward%20ForgacsSite-to-site vpn only works from ISA Server machineI am trying to get a site-to-site VPN to work between two sites. One is running ISA 2006 standard (the main site) and the remote site is running RRAS on Server 2003. I have looked at probably 20 different guides to setting up this kind of scenario, but it just will not work. Current, for testing, I have only tried to set it up using PPTP (not LT2P/IPSec) as I suspected it wouldn't work first go.<br/><br/>The demand dial connections in RRAS successfully connect on both machines, and from the ISA server machine I can ping the remote network (172.16.0.0/24). From the single machine on the remote network (running RRAS), I can also ping the ISA server (192.168.0.0/24).<br/><br/>*However*, from any other machine on the main network, I can't ping the remote site. And from the remote site, I also can't ping any other machine on the main network except the ISA server.<br/><br/>There is a route relationship network rule in ISA with Source=Main Network (internal) and Destination=Remote Network, and there are two separate access rules to allow all outbound traffic both ways between the remote site and main network, and vice versa.<br/><br/>Bizzarely, I can also ping the address on the VPN subnet (e.g. 172.16.0.2) that ISA gets assigned from the other machines on the main network, so I think it's safe to assume the routing is OK on those machines? It seems that ISA is just refusing the pass the data.<br/><br/>The only information that appears in the ISA live log when you try to ping the remote site from another machine is &quot;connection closed&quot; with the system policy ICMP rule, nothing else, and it only shows up in the logs intermittently.<br/><br/>Any ideas on what could be wrong with this config? I would like to stress that the pings work from the ISA machine to the remote site, and from the remote site to the ISA machine, but not from any other machines on the main network to the remote site.Thu, 23 Apr 2009 08:58:59 Z2009-04-29T05:32:22Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/847a86a0-6d3a-4b79-b013-ded1e35738c2http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/847a86a0-6d3a-4b79-b013-ded1e35738c2Bobo1234http://social.technet.microsoft.com/Profile/en-US/?user=Bobo1234User is not prompted to change password when using VPN at logon time<span style="font-size:x-small;font-family:Verdana"><span style="font-size:x-small;font-family:Verdana"> <p dir=ltr>We are using Windows Vista SP1 VPN with RSA Authentication Agent for Windows v. 6.1.2 to connect to a Microsoft ISA 2006 Server with RSA Authentication Manager v. 6.1.2. We are using EAP with secure ID tokens. We have no problem in establishing the VPN connection and getting access to internal network resources!</p> <p dir=ltr>The problem arise when an administrator enables &quot;User must change password at next logon&quot; on the users domain account <strong>or</strong> when the users password expires. When the user then establishes the VPN connection at logon time, the user is <strong>not</strong> prompted by Vista for changing password (as it would if the user was directly on the company LAN)??? However since the domain require that the password <strong>must</strong> be changed, is seems that the user is <strong>not </strong>allowed access to the PC and the user is returned to the login screen!? The result is that the user is not able to login to his PC.</p> <p dir=ltr>Anyone seen this before? Is there a solution somewhere??<br/><br/>Best regards<br/>Bobo</p> </span></span>Mon, 30 Mar 2009 13:28:23 Z2009-04-27T21:08:57Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/a6095462-f8dc-4955-a304-c33a4777365dhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/a6095462-f8dc-4955-a304-c33a4777365dAlexanderParoulhttp://social.technet.microsoft.com/Profile/en-US/?user=AlexanderParoul2 WAN adapters and VPN access.Hi.<br/> I have ISA 2006 Std. Usually we connect to Internet through our superior organisation's proxy (let's call it Proxy1 for short), which is configured on ISA as a gateway(WAN1). Now we need a possibility to create a VPN connection directly to our ISA server, bypassing that Proxy1. We've installed another NIC and configured a static direct IP on it, provided by ISP (WAN2). <br/> So, if i configure gateways on both of our WAN cards, the internet connection go nuts (which is understandible). But it seems, i have to configure a gateway on WAN2, if i want to use it for VPN connections. Is there a way i can configure my server to use WAN2 for VPN, and WAN1 for Internet access? It's even possible to use WAN2 as internet access, but we steel need to be able to access Proxy1. <br/> <br/> I was thinking about removing a gateway on WAN1, leaving only WAN2, and configuring a static route to allow internal usert to access Proxy1.Fri, 24 Apr 2009 10:53:03 Z2009-04-27T06:08:34Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/b0f8efbd-fb14-4bf2-8bf6-44fcdcd68e92http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/b0f8efbd-fb14-4bf2-8bf6-44fcdcd68e92JokkeBEhttp://social.technet.microsoft.com/Profile/en-US/?user=JokkeBEISA 2004 SP3: Any active directory user can connect trough VPNHello all<br/> <br/> I am working trough the ISA server 2004 self-paced training kit for Microsoft exam 70-350 and during my testing I hit the following problem:<br/> <br/> I configured the ISA server to accept connections from the external network with a active directory group &quot;testusers1&quot; configured in the remote-access permissions list.<br/> <br/> When trying to connect from a windows XP machine on the external network the connection succeeds for any user that has the &quot;Remote access permission (Dial-in or VPN)&quot; set to &quot;Allow Access&quot; in the user account properties of the active directory user profile. It seems it does not matter what active directory groups I allow to connect on the ISA server, the connection always succeeds. Even when I remove the &quot;testusers1&quot; group from the remote-access permissions list in ISA server, the connections still succeed.<br/> <br/> What does work are the firewall rules, for instance:<br/> A member of the &quot;Testusers1&quot; group has HTTP access from the &quot;VPN Clients&quot; network to the external network. The rules here apply as intended, a VPN user who is not part of the &quot;testusers1&quot; group can not use the internet while connected trough VPN.<br/> <br/> It seems to me the group membership of a user is not taken into account when the user connects to the ISA server trough VPN. I also tried RADIUS authentication but this has the same results.<br/> <br/> I'm quite sure this is due to a configuration issue on my part but I'm not sure where to look. <br/> <br/> Let me know if you need more information.<br/> <br/> Thanks in advance<br/> <br/> Regards<br/> <br/> <br/>Fri, 10 Apr 2009 12:28:52 Z2009-04-17T08:42:35Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/3ca24723-e58c-4d7f-8c09-439f293b38b2http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/3ca24723-e58c-4d7f-8c09-439f293b38b2Bombadillhttp://social.technet.microsoft.com/Profile/en-US/?user=BombadillISA 2006: How to set up IPSec VPN access with remote Windows XP / Vista clientsI'm having serious trouble setting up an IPSec VPN connection between WinXP / Vista clients and my test rig ISA 2006 Enterprise server.<br><br>PPTP works perfectly fine.<br>ISA server is domain member<br>There is a 2008 enterprise CA in place<br>All Servers / Clients are fully up-to-date<br><br>Please somebody explain to me the following for starters:<br><br> <ol> <li>I have issued an IPSec certificate from my CA and installed it on the ISA server's Local Computer Personal certificate store. Is this right? I had to do this manually, <font color="#000000">as the <font size=2>Active Directory Certificate Services </font>web console issues certificates only to the user </font></li> <li>Do I need to issue some kind of certificate from the same CA to the client PCs?? If so, how ?</li> <li>Can IPSec VPN work without a RADIUS server? Can I use IPSec with authentication from the Windows Domain namespace?</li> <li>Do you know of a definitive step-by-step guide for such an installation</li></ol> <p>Many thanks in advance<br><br>Andreas</p>Thu, 26 Mar 2009 11:38:16 Z2009-10-07T10:57:28Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/1b9d7f8d-a454-4ddc-94e6-a8afc47f03c1http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/1b9d7f8d-a454-4ddc-94e6-a8afc47f03c1Timiashttp://social.technet.microsoft.com/Profile/en-US/?user=TimiasVPN selective restriction to internal resources<p>Hi all,<br/>In Cisco FW (PIX or ASA) I have the possibility to create several resource IP address pools assigned to a VPN Client configuration (IPSec Client with shared passfrase) and then restrict those IP pools to selected network resources (ip / services) using access rules.<br/>In Stonesoft Stonegate FW I have the possibility to create more or less the same has with cisco but now I can also restrict access to network resources (IP / services) using access rules that are granular to an ldap user / group (AD also).<br/>In Microsoft ISA (don't know about TMG) the VPN configuration is global and I don't know how to replicate these other firewals behavior.<br/><a href="../../forums/en-US/ForefrontedgeVPN/thread/8681d6bc-bb8a-4454-9e7e-7f4c7a1e4f50">http://social.technet.microsoft.com/forums/en-US/ForefrontedgeVPN/thread/8681d6bc-bb8a-4454-9e7e-7f4c7a1e4f50/</a> seems to explain a work around but...<br/>The Issue is:</p> <ol> <li>I have several support external companies that I want to give access to selective internal resources </li> <li>ex: Company A needs RDP access to Server1 and Server2 and nothing else </li> <li>ex: Company B needs SSH access to Server5 and nothing else </li> <li>These company support people do not have their machines in my company Domain nor they have ISA firewall client installed (So they can not authenticate with a AD user of mine, I think!) </li> <li>I have a L2TP shared passfrase ISA2006 VPN configuration in place with a dedicated IP address pool </li> </ol> <p>How can I acomplish this using ISA 2006 (or even with TMG, is there any new ways to do this in TMG?)<br/>Thanks</p>Wed, 01 Apr 2009 13:20:05 Z2009-06-16T17:11:59Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/c4e3f5cd-8c80-4bf3-a0bb-685622bd9e2dhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/c4e3f5cd-8c80-4bf3-a0bb-685622bd9e2dLanky Doodlehttp://social.technet.microsoft.com/Profile/en-US/?user=Lanky%20DoodleClient DNSHiya, <br><br>Got VPN client access all working hunky dorey. Only thing missing is the DNS suffix is not being pushed out to VPN clients, so cannot ping by host name, only IP or FQDN. <br><br>I have a 2 member array so DHCP VPN IP assignment is not possible. <br><br>Any ideas? <br><br>Thanks  Sat, 06 Sep 2008 16:46:26 Z2009-06-16T17:12:54Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/d5843c2d-5874-4986-bd35-28a07244c011http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/d5843c2d-5874-4986-bd35-28a07244c011SysADProhttp://social.technet.microsoft.com/Profile/en-US/?user=SysADProvpn users do not disconnect their sessions<p>hello all.<br><br>I have multiple users who connect to our ISA server through vpn and they do not disconnect their sessions, and each time I get called from others remote users that they are not able to connect to our ISA Server through VPN, I go and check ISA Server and see that there are 10 sessions currently open. I call the users that are connected and find out that they left their pcs long time ago.</p> <p>I do not wish to go each time to isa server and disconnect these session manualy, I need a script or something to check who is active or not.</p>Fri, 13 Mar 2009 08:46:54 Z2009-03-28T07:29:22Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/25a4dc5d-361c-42a6-9423-eec6ff93f259http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/25a4dc5d-361c-42a6-9423-eec6ff93f259mamu001http://social.technet.microsoft.com/Profile/en-US/?user=mamu001When connected throught vpn need to use fully qualified dns nameWe have TMG with windows essential server installed. We use pptp for vpn.<br>When we connect to network through vpn, we need to use fully qualified dns name. What can i change to get it working withought fully qualified name?<br><br>For example:<br>Server Name: qabox1<br>within network i can use qabox1<br>but when connected through vpn it can't resolve qabox1, need to use qabox1.hq.bubba.com<br><br>Any help is appreciated. Wed, 18 Feb 2009 16:26:54 Z2009-02-20T16:29:14Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/efa55bab-2478-49ed-878a-05b79f882b91http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeVPN/thread/efa55bab-2478-49ed-878a-05b79f882b91g33kb0yhttp://social.technet.microsoft.com/Profile/en-US/?user=g33kb0yVPN Clients SMB DisconnectsI've been working through a real head-scratcher, here... hope someone can help me.  Users connect to the VPN and everything seems to work OK, but we're having troubles with file transfers (SMB / CIFS) erring out.<br><ol><li>User connects to VPN</li><li>User copies files to/from shared drive, (ex: \\fileserver1\share\)</li><li>File transfer begins</li><li>File transfer stops with error message &quot;The specified network name is no longer available&quot;</li></ol>ISA 2004 Server details:<br>- Windows Server 2003 Enterprise w/SP1 (x86 of course)<br>- ISA 2004 Enterprise w/SP3<br>- Single NIC<br>- VPN clients are NAT'd to internal net<br><br>Details:<br>This problem is 100% reproducible.  As a vpn client, begin a file transfer to/from \\fileserver1.  On the ISA 2004 server, open any share on \\fileserver1.  VPN client will receive error message in #4 above.<br><br><br>Verbose details from Packet sniff:<br>1.  VPN Client opens \\fileserver1\share<br><blockquote>Client IP: &lt;ISA Server IP&gt;<br>Source port: 6798<br>Destination IP: 192.168.252.252<br>Destination Port: 445<br>Session Setup AndX Request, NTLMSSP_NEGOTIATE<br></blockquote><br>2.  Packet sniff shows successful connection, VPN client can see files.<br>3.  Second VPN client opens any share on same file server:<br><br><blockquote>Client IP: &lt;ISA Server IP&gt;<br>Source Port: 6291<br>Destination IP: 192.168.252.252<br>Destination Port: 445<br>Session Setup AndX Request, NTLMSSP_NEGOTIATE<br><br></blockquote><blockquote>Client IP:  192.168.252.252<br>Source Port:  445<br>Destination IP:  &lt;ISA Server IP&gt;<br>Destination Port: 6798<br>[RST, ACK]<br></blockquote><br>4.  First VPN client sees error message and transfer fails, second VPN Client's session works OK.<br><br><br><br>I've successfully reproduced the error on file servers running:<br>- Windows 2003 w/SP1 - x86<br>- Windows 2003 w/SP2 - x86 and x64<br>- Windows 2008 - x86 and x64<br><br><br>Instead of writing out the thirty pages of details on what I've tried, I'm reaching out and hoping someone can help me figure this out. :)  Any and all suggestions are welcome.  Thanks!<br> Sun, 01 Feb 2009 22:19:28 Z2009-06-17T17:59:54Z