Advertisement

03.08.2008 at 11:31AM PST, ID: 23225579
[x]
Attachment Details

VPN Connectivity issue

Asked by jmarenghi in Networking Hardware Firewalls, Web Servers, Networking Hardware

Tags: Windows 2003 Server Network, Sonicwall 3010, sonic wall tz190

I am having an issue with one of my site to site vpn's.
I have a hub spoke network with Headquarters connecting to 4 remote sites.
As of last Monday a user called and we found that one of the remote sites stopped connecting to an Exchange server on the HQ network. This network has been up and running with the current hardware/software configuration for months. No recent changes have been made on our end to any of the hardware or software.

In an attempt to isolate the issue, I recreated the VPN tunnel between HQ and the remote site. No problem. I can ping machines back and forth. The firewall rules allow all traffic on all ports to and from the remote subnet and the HQ subnet. I then unplugged all network devices on the remote network and recreated the VPN using a new subnet on the remote network. The VPN tunnel worked again.

Here are a couple of symptoms of my problem.
I can not put the LAN IP address of a web server (OWA) on the HQ network in IE on a machine in the remote network and get a response from the server. I can ping it and when the local DNS server is up, I can resolve the correct IP using the server name. I was able to do this before and I can do this from my other remote networks and all of my site to site VPN tunnels are set up the same. I can RDP to servers from the remote network, but I can not RDP to the Server in the remote network. I was always able to do this in the past. I can RDP to a remote server on my other remote LANs. Again the VPN settings are the same for all my site to site tunnels.

The fact that IE will not respond when I put the HQ LAN IP of the OWA server in the browser I believe is the key to my problem. I have other web servers on the HQ network and the behavior happens when trying to connect to them as well. I am 100% sure that these servers are up and running because I can RDP into machines on my other remote subnets and put the web server IPs in IE and the web pages will respond. I can also RDP to my other servers on my remote LANs accept the server in my problem remote site.

I can however put the public IP of my OWA server in IE at the problem site and I am able to connect. Why cant I run OWA through the VPN tunnel anymore? I could before, and I can from my other remote sites.

The service at my remote site is a DSL provided by AT&T. My Sonicwall TZ-190 connects to an AT&T supplied Netopia 3347W which is set up as a pass through so my Sonicwall can have my public static IP assigned to the WAN side.

I apologize for the length of this explanation. I hope I conveyed my problem clearly. I have set up many remote sites like this. I have never had a problem like this.

Any help is much appreciated
Thanks
JDM
Start Free Trial
[+][-]03.08.2008 at 01:46PM PST, ID: 21078764

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.08.2008 at 02:46PM PST, ID: 21079005

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.08.2008 at 03:59PM PST, ID: 21079277

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Networking Hardware Firewalls, Web Servers, Networking Hardware
Tags: Windows 2003 Server Network, Sonicwall 3010, sonic wall tz190
Sign Up Now!
Solution Provided By: meverest
Participating Experts: 3
Solution Grade: A
 
 
[+][-]03.08.2008 at 06:23PM PST, ID: 21079739

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.09.2008 at 09:09PM PDT, ID: 21084142

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.10.2008 at 04:33AM PDT, ID: 21085411

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628