Advertisement

09.04.2007 at 11:54AM PDT, ID: 22806139
[x]
Attachment Details

No ipsec connection to ISA 2006. PPTP works fine.

Asked by LTIADMIN in IPSec Security Protocol, Virtual Private Networking (VPN), MS Internet Security & Accel

Tags: isa, 2006, ipsec, pptp

I am having difficulties connecting via VPN with IPSEC to our ISA 2006 Server. Connecting using PPTP will work just fine. I'll describe the environment, then the steps I've taken.

The ISA 2006 Server is directly connected to the internet on a Windows 2003 Server Standard R2 SP2. The server is a Dell Poweredge 860 with a 2 NIC configuration. (one external, the other internal) The ISA Server is a member of the domain.

The client pc is a Dell Latitude D820 laptop with Windows XP SP2. The laptop is connected to the internet via DSL.  The laptop is also a member of the same domain.

The user for authentication is a Domain Admin.
The dial in permissions in AD have been set to allow.
Created the rule "allow VPN User to Internal"

Using the built in XP networking connectoid, the client laptop was able to make a successful connection using PPTP. After that I tried to use just a pre-shared key for an L2TP ipsec connection, which returned a RAS 800 Error.

I then issued client & server certificates to the laptop and server from a standalone CA. Then issued ipsec certificates from the same CA in the same domain. The certificates were installed to the local computer store and exported and imported to the trusted root certicates store as per the Microsoft kb.

Restarted the RAS service on ISA and tried again and was returned with a 678 error on the laptop. Tried checking and unchecking the preshared key option, but same result.

Confirmed the LDAP settings in ISA, VPN access is configured for domain users. IP assignment is handled by DHCP. Tried configuring IP Filtering on/off. All with no luck.

The response from the ISA log is "unspecified ip traffic" from the client ip address.

Is there something I'm missing?  Any help would be appreciated.

(I asked this question before and Keith A helped out, but the project was temporarily suspended and the original questions was deleted.)
Start Free Trial
[+][-]09.04.2007 at 12:12PM PDT, ID: 19827584

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.04.2007 at 01:13PM PDT, ID: 19828149

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09.05.2007 at 09:56AM PDT, ID: 19833888

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.05.2007 at 10:18AM PDT, ID: 19834062

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: IPSec Security Protocol, Virtual Private Networking (VPN), MS Internet Security & Accel
Tags: isa, 2006, ipsec, pptp
Sign Up Now!
Solution Provided By: keith_alabaster
Participating Experts: 1
Solution Grade: A
 
 
[+][-]09.05.2007 at 10:20AM PDT, ID: 19834077

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09.05.2007 at 10:59AM PDT, ID: 19834380

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.05.2007 at 11:30AM PDT, ID: 19834630

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09.20.2007 at 10:08AM PDT, ID: 19929806

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.20.2007 at 10:10AM PDT, ID: 19929816

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_1_20070628