I am having an issue with one of my site to site vpn's.
I have a hub spoke network with Headquarters connecting to 4 remote sites.
As of last Monday a user called and we found that one of the remote sites stopped connecting to an Exchange server on the HQ network. This network has been up and running with the current hardware/software configuration for months. No recent changes have been made on our end to any of the hardware or software.
In an attempt to isolate the issue, I recreated the VPN tunnel between HQ and the remote site. No problem. I can ping machines back and forth. The firewall rules allow all traffic on all ports to and from the remote subnet and the HQ subnet. I then unplugged all network devices on the remote network and recreated the VPN using a new subnet on the remote network. The VPN tunnel worked again.
Here are a couple of symptoms of my problem.
I can not put the LAN IP address of a web server (OWA) on the HQ network in IE on a machine in the remote network and get a response from the server. I can ping it and when the local DNS server is up, I can resolve the correct IP using the server name. I was able to do this before and I can do this from my other remote networks and all of my site to site VPN tunnels are set up the same. I can RDP to servers from the remote network, but I can not RDP to the Server in the remote network. I was always able to do this in the past. I can RDP to a remote server on my other remote LANs. Again the VPN settings are the same for all my site to site tunnels.
The fact that IE will not respond when I put the HQ LAN IP of the OWA server in the browser I believe is the key to my problem. I have other web servers on the HQ network and the behavior happens when trying to connect to them as well. I am 100% sure that these servers are up and running because I can RDP into machines on my other remote subnets and put the web server IPs in IE and the web pages will respond. I can also RDP to my other servers on my remote LANs accept the server in my problem remote site.
I can however put the public IP of my OWA server in IE at the problem site and I am able to connect. Why cant I run OWA through the VPN tunnel anymore? I could before, and I can from my other remote sites.
The service at my remote site is a DSL provided by AT&T. My Sonicwall TZ-190 connects to an AT&T supplied Netopia 3347W which is set up as a pass through so my Sonicwall can have my public static IP assigned to the WAN side.
I apologize for the length of this explanation. I hope I conveyed my problem clearly. I have set up many remote sites like this. I have never had a problem like this.
Any help is much appreciated
Thanks
JDM
Start Free Trial