Advertisement

03.31.2008 at 09:44PM PDT, ID: 23284817
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

Cannot see SBS server shares through VPN tunnel - different subnets

Tags: Microsoft, SBS, 2003
Hi. I've searched EE for this one and there are some similar ones but can't find step-by-steps to get this working. Situation is this:

SBS03 on 192.168.116.x - all working sweetly.
IPSEC VPN tunnel through 2 x Netgear DG834G v4 - tunnel up fine, second subnet on 192.168.117.x.

I can ping server from second location- even server name resolves to correct IP though tunnel, so all is nice there.

The problem is that I cannot see shares on SBS03 server. No authentication even comes up. I can RDP through it without an issue, but I'm pretty sure RRAS just needs to be configured to allow 192.168.117.x requests to be accepted, as it's configured for 192.168.116.x connections.

Can anyone give me step-by-step instructions on how to configure this so i don't kill the routing on my nice fresh SBS?

Thanks heaps.
Nathan.
Start your free trial to view this solution
Question Stats
Zone: Networking
Question Asked By: wait1
Solution Provided By: wait1
Participating Experts: 2
Solution Grade: A
Views: 25
Translate:
Loading Advertisement...
03.31.2008 at 11:11PM PDT, ID: 21251565

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
04.01.2008 at 05:30AM PDT, ID: 21253200

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
04.01.2008 at 07:07AM PDT, ID: 21254054

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
04.01.2008 at 07:38AM PDT, ID: 21254356

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
04.02.2008 at 07:43AM PDT, ID: 21263550

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
04.02.2008 at 07:58AM PDT, ID: 21263730

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
04.02.2008 at 05:40PM PDT, ID: 21268832

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
04.02.2008 at 07:58PM PDT, ID: 21269443

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
04.03.2008 at 02:32AM PDT, ID: 21270783

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
Loading Advertisement...
Microsoft
  • Internet Protocols
  • Applications
  • Development
  • OS
  • Hardware
  • Windows Security
Apple
  • Operating Systems
  • Hardware
  • Programming
  • Networking
  • Software
Internet
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Spy / Ad Blockers
  • Web Browsers
  • New Net Users
  • Web Development
  • Chat / IM
  • Anti Spam
  • Web Servers
  • Anti-Virus
  • Email Clients
Gamers
  • Tips
  • Online / MMORPG
  • Puzzle
  • Emulators
  • Action / Adventure
  • Role Playing
  • Consoles
  • Game Programming
  • Strategy
  • Sports
  • Misc
  • Computer Games
Digital Living
  • Hardware
  • Automotive
  • New Net Users
  • New Users
  • Software
  • Digital Music
  • Gaming World
  • Home Security
  • Apple
  • Networking Hardware
Virus & Spyware
  • Vulnerabilities
  • IDS
  • Encryption
  • Anti-Virus
  • Operating Systems Security
  • Software Firewalls
  • WebApplications
  • Cell Phones
  • Operating Systems
  • Internet
  • Hardware Firewalls
Hardware
  • Displays / Monitors
  • Handhelds / PDAs
  • Components
  • Peripherals
  • Laptops/Notebooks
  • Servers
  • Misc
  • Apple
  • Embedded Hardware
  • Networking Hardware
  • Storage
  • Desktops
  • New Users
Software
  • System Utilities
  • Industry Specific
  • Network Management
  • Photos / Graphics
  • Page Layout
  • VMware
  • Misc
  • Web Development
  • OS
  • CYGWIN
  • Voice Recognition
  • Virtualization
  • Message Queue
  • Quality Assurance
  • Security
  • Firewalls
  • MultiMedia Applications
  • Development
  • Database
  • Office / Productivity
  • Business Management
  • OS/2 Apps
  • Server Software
  • Internet / Email
ITPro
  • OS
  • Storage
  • Encryption
  • Operating Systems Security
  • Apple Hardware
  • Laptops & Notebooks
  • Servers
  • Networking Hardware
  • Peripherals
  • Devices
  • Displays / Monitors
  • WebTrends / Stats
  • Search Engines
  • Firewalls
  • Web Computing
  • WebApplications
  • IDS
  • Vulnerabilities
  • Email Clients
  • File Sharing
  • Spy / Ad Blockers
  • Web Browsers
  • Web Servers
  • Networking
  • Anti-Virus
  • Consulting
  • Chat / IM
  • Anti Spam
Developer
  • Web Servers
  • Web Browsers
  • Game Programming
  • Dev Tools
  • Industry Specific
  • Office / Productivity
  • Database
  • CYGWIN
  • Web Development
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Programming
  • Content Management
  • Application Servers
  • Protocols
Storage
  • Removable Backup Media
  • Storage Technology
  • Servers
  • Grid
  • Remote Access
  • Backup / Restore
  • Misc
  • Hard Drives
OS
  • Miscellaneous
  • Security
  • Development
  • Linux
  • VMware
  • MainFrame OS
  • Unix
  • Apple
  • OS / 2
  • AS / 400
  • BeOS
  • Microsoft
  • VMS / OpenVMS
Database
  • Oracle
  • Miscellaneous
  • MySQL
  • Software
  • Sybase
  • Contact Management
  • PostgreSQL
  • Data Manipulation
  • Clarion
  • InterSystems Cache
  • Siebel
  • MUMPS
  • OLAP
  • SQLBase
  • SAS
  • GIS & GPS
  • 4GL
  • Berkeley DB
  • DB2
  • Informix
  • Interbase / Firebird
  • FoxPro
  • Reporting
  • LDAP
  • Filemaker Pro
  • MS SQL Server
  • dBase
  • MS Access
Security
  • Misc
  • Web Browsers
  • Software Firewalls
  • Operating Systems Security
  • File Sharing
  • Spy / Ad Blockers
  • Vulnerabilities
  • WebApplications
  • IDS
  • Anti-Virus
  • Encryption
  • Anti Spam
  • Email Clients
  • VPN
  • Chat / IM
Programming
  • Editors IDEs
  • Installation
  • Handhelds / PDAs
  • Multimedia Programming
  • System / Kernel
  • Automation
  • Algorithms
  • Game
  • Signal Processing
  • Project Management
  • Open Source
  • Database
  • Misc
  • Languages
  • Processor Platforms
  • Theory
Web Development
  • Scripting
  • Blogs
  • Web Servers
  • Software
  • Search Engines
  • Web Graphics
  • Web Services
  • Images
  • Internet Marketing
  • Images and Photos
  • Components
  • Document Imaging
  • Web Languages/Standards
  • Illustration
  • WebApplications
  • Fonts
  • WebTrends / Stats
  • Authoring
  • Digital Camera Software
  • Miscellaneous
Networking
  • Protocols
  • Apple Networking
  • Network Management
  • Message Queue
  • Application Servers
  • Content Management
  • File Servers
  • Email Servers
  • Misc
  • Java Editors & IDEs
  • Wireless
  • Networking Hardware
  • Backup / Restore
  • System Utilities
  • ISPs & Hosting
  • Web Servers
  • Storage Technology
  • Removable Backup Media
  • Servers
  • Web Computing
  • Broadband
  • Grid
  • OS / 2
  • Novell Netware
  • Unix Networking
  • Windows Networking
  • Security
  • Telecommunications
  • Operating Systems
  • Linux Networking
Other
  • Lounge
  • Business Travel
  • Community Support
  • New Net Users
  • Philosophy / Religion
  • Math / Science
  • Miscellaneous
  • URLs
  • Expert Lounge
  • Politics
  • Puzzles / Riddles
  • Automotive
Community Support
  • Suggestions
  • New to EE
  • New Topics
  • CleanUp
  • Announcements
  • General
  • Feedback
  • Input
  • EE Bugs
 
03.31.2008 at 11:11PM PDT, ID: 21251565
Set your DNS on your remote PC to be the IP of the SBS server.
 
04.01.2008 at 05:30AM PDT, ID: 21253200
Correct me if i'm wrong, but given that it pings the name of the server (which already resolves to the correct IP) I doubt this is the issue. I'll try when i'm there again tomorrow, but DNS seems fine.
What is your basis for this theory? Something i'm missing when connecting to shared drives?
 
04.01.2008 at 07:07AM PDT, ID: 21254054
Sorry my problem of not reading the post correctly.
 
04.01.2008 at 07:38AM PDT, ID: 21254356

Rank: Genius

It may be the windows firewall/s. By default when file and print sharing is enabled it will create a firewall exception, but only for connections from the same LAN/subnet. This can be modified using the firewall scope options for the exception, to allow access from any subnet, or specific subnets. There is an outline explaining how to do so for RDP/3389 in the following link. I know your RDP works fine, but use it as an example to do the same for the file and print sharing exception. RDP requires modifying 1 port file and print is 4 ports.
http://www.lan-2-wan.com/RD-FW.htm
 
04.02.2008 at 07:43AM PDT, ID: 21263550
Went to check firewall on SBS and it's not even running. Says: "Windows firewall is not running because another service is running that might use the network address translation component (Ipnat.sys)"
So i guess it's not a firewall issue.
Any other ideas? I've now configured a Std2003 server on 117.x and even with that VPNed in and DNS set up on it and all things resolving nicely it still won't get through. If you connect a direct VPN from one server to the other it's all sweet. I'm thinking somehow these netgear routers are crap. There's an article about them dropping packets through VPN tunnels. Can't turn off fragmentation option with these ones.
???
 
04.02.2008 at 07:58AM PDT, ID: 21263730

Rank: Genius

Is this a name resolution issue or a connection issue., ie. can you connect to a share by ip ?
\\192.168.116.123\ShareName

There is an option in the Netgear VPN configuration to enable NetBIOS broadcasting which may help with name resolution, but you should be able to rely on DNS rather than NetBIOS.

I have a few clients with Netgear VPN's that work great.

The remote clients should point ONLY to your SBS for DNS, do not add the ISP even as an alternate.

>>"....another service is running that might use the network address translation component (Ipnat.sys)""
Indicates RRAS is enabled, and therefore the Windows firewall is disabled.

 
04.02.2008 at 05:40PM PDT, ID: 21268832
Tried \\192.168.116.1\sharename... no joy.
An annoying thing about these Netgears is that when you do a 'manual' VPN tunnel the blue 'help' bar on the right talks about the NETBIOS option, but there IS NO netbios option during configuration. How stupid is that?
Just called Netgear suport - fairly useless is being kind. They said it's a MS sharing problem...I asked what the point of a VPN tunnel is (**answer: sharing files securely**) - she didn't even know what it was for.... yikes.

Going to try other routers and drive over these ones.

What about an IPSEC from Std2003 to SBS2003, anyone... ? i'll do an EE search on that one. Bypass these routers.
Thanks for your help.
 
04.02.2008 at 07:58PM PDT, ID: 21269443

Rank: Genius

The NetBIOS option should be at the top of the "VPN auto policy" page and labeled "enable NetBIOS".

Must say you are better off asking for help at the local MacDonalds than Netgear, then again the companies that do provide excellent support, such as Cisco, charge more than double the cost of your router, annually, just for support. We shouldn't expect a whole lot for a one time fee of $100

Unless you have a defective unit I wouldn't give up on Netgear, they usually work very well. As for using IPSec with 2 Windows servers, that is a major project.
 
04.03.2008 at 02:32AM PDT, ID: 21270783
Ladies and Gents - the answer: faulty Netgear software.

Surprisingly Netgear emailed me back only 6hrs later with a firmware upgrade. A known issue, would you believe it? Nice of them to put it on their site. For those wanting it - they said they'd post it soon. Can i post it here? Not sure if i'm allowed.

Firmware upgrade on both ends, and all is well. My IPSEC tunnel between my servers is sweet!
In Netgear's defense, even though i hate them right now, this was the easist tunnel i've ever done, and it's so quick to join and rejoin.

Thanks for the inputs.
Can we take points off Netgear?
Accepted Solution
 
 
20080236-EE-VQP-29 / EE_QW_2_20070628