Advertisement

04.19.2007 at 07:21AM PDT, ID: 22521382
[x]
Attachment Details

L2TP / IPSEC 3DES VPN doesnt allow connections from the same NAT'ed external IP address for client PCs

Asked by admin_lss in Microsoft Server, Miscellaneous Networking, Virtual Private Networking (VPN)

Tags: , , , ,

We are using a L2TP/IPSEC 3DES Microsoft VPN at our company. Within the last 3 weeks (it worked prior to this), staff cannot connect simultaneously from locations where they are NAT'ed to the same external, publicly routable IP address. We were able to connect with the same NAT'ed to external IP address up until around 3 weeks ago.  We do have the NAT-T patch AND/OR Windows XP Service Pack 2 inplace to allow NAT IPs to be able to connect the VPN. The staff PCs are ALL running Windows XP and the VPN server is running Windows 2003 Server. IF PC1 connects to the VPN, they connect fine. If PC2 (both in the same location with the same NAT'ed IP) PC2 gets the following error:

 Error 678 "The remote computer did not respond"


If PC1 disconnects, then PC2 can connect and if PC1 then tries to reconnect, it gets the same error. The problem seems to be SPECIFICALLY tied to the fact that the PCs have the same IP address to the outside world (they do have differnet Private IP address's when ipconfig is ran). I have looke over my VPN server setting and dont know if anything has changed there, although it could have, and our firewall seems to let he traffic through.

When I watch the firewall log the traffic, the first PC sends both NAT-T and ISAKMP and connects fine. The second PC to connect sends ust ISAKMP and gets the 678 error. We have not changed our rules in the Corporate Firewall.

Has there been a patched released that may have broken the ability to connect to our L2TP/IPSEC Windows VPN? Is there a setting that may have been misconfigured? Any ideas where I should start looking?

Thanks!

Start Free Trial
[+][-]04.19.2007 at 09:39AM PDT, ID: 18940402

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.19.2007 at 09:51AM PDT, ID: 18940497

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Microsoft Server, Miscellaneous Networking, Virtual Private Networking (VPN)
Tags: vpn, 678, l2tp, ipsec, windows
Sign Up Now!
Solution Provided By: KCTS
Participating Experts: 2
Solution Grade: B
 
 
[+][-]04.19.2007 at 11:02AM PDT, ID: 18941051

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]06.02.2007 at 03:45PM PDT, ID: 19201867

Experts Exchange has a courteous staff of administrators who help members get the most out of the website by means of administrative comments like this one.

Start your 7-day free trial to view this Administrative Comment or ask the Experts your question.

 
[+][-]06.06.2007 at 09:12AM PDT, ID: 19226281

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32