Advertisement

05.06.2008 at 02:46PM PDT, ID: 23381064 | Points: 500
[x]
Attachment Details
VPN does not connect after WAN IP change - is this a certificate issue ?
Tags: Microsoft, SBS2003R2SP1 with ISA2004SP3, Using SBS VPN
Hi Guys,
I'm a little unclear about how certificates work with SBS2003 so need some help.
I have an SBS2003R2 SP1 server with ISA2004 SP3 (also exchange 2003 ) there about 6 users some of which are remote. I use VPNs for remote users to gain access to exchange mail accounts.

The company moved premises recently and the broadband account changed (so the IP address changed too) after changing the DNS entries for the mx records and the server.XXXXX.com sub domain inbound mail started working and so did remote access to OWA.

My problem is that VPNs won't connect (I haven't seen the actual error yet I haven't been to a users site yet and no one has done a screen grab for me) Given this scenario can anyone tell me if I need to rebuild certificates IE after an IP change ???? If this is the case why does OWA still work OK.

If I have to rebuild the certificate, where do I start ???

Thanks, I'll get more info from the VPN client tomorrow.

Thanks
Trevor

Start your free trial to view this solution
Question Stats
Zone: OS
Question Asked By: TrevorWhite
Question Asked On: 05.06.2008
Participating Experts: 3
Points: 500
Views: 0
Translate:
Loading Advertisement...
05.06.2008 at 02:58PM PDT, ID: 21511408

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.06.2008 at 03:03PM PDT, ID: 21511434

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.06.2008 at 03:03PM PDT, ID: 21511439

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.06.2008 at 03:37PM PDT, ID: 21511624

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.06.2008 at 03:43PM PDT, ID: 21511647

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.06.2008 at 04:21PM PDT, ID: 21511797

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.07.2008 at 05:04AM PDT, ID: 21515398

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.07.2008 at 05:08AM PDT, ID: 21515431

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.07.2008 at 01:34PM PDT, ID: 21520148

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.07.2008 at 03:55PM PDT, ID: 21521064

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 05:20PM PDT, ID: 21529582

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 05:25PM PDT, ID: 21529602

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.09.2008 at 03:31AM PDT, ID: 21531515

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.09.2008 at 03:53AM PDT, ID: 21531592

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
Loading Advertisement...
Microsoft
  • Internet Protocols
  • Applications
  • Development
  • OS
  • Hardware
  • Windows Security
Apple
  • Operating Systems
  • Hardware
  • Programming
  • Networking
  • Software
Internet
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Spy / Ad Blockers
  • Web Browsers
  • New Net Users
  • Web Development
  • Chat / IM
  • Anti Spam
  • Web Servers
  • Anti-Virus
  • Email Clients
Gamers
  • Tips
  • Online / MMORPG
  • Puzzle
  • Emulators
  • Action / Adventure
  • Role Playing
  • Consoles
  • Game Programming
  • Strategy
  • Sports
  • Misc
  • Computer Games
Digital Living
  • Hardware
  • New Net Users
  • New Users
  • Software
  • Digital Music
  • Gaming World
  • Home Security
  • Apple
  • Networking Hardware
Virus & Spyware
  • Vulnerabilities
  • IDS
  • Encryption
  • Anti-Virus
  • Operating Systems Security
  • Software Firewalls
  • WebApplications
  • Cell Phones
  • Operating Systems
  • Internet
  • Hardware Firewalls
Hardware
  • Handhelds / PDAs
  • Displays / Monitors
  • Components
  • Networking Hardware
  • Peripherals
  • Laptops/Notebooks
  • Storage
  • Servers
  • Desktops
  • New Users
  • Misc
  • Apple
Software
  • System Utilities
  • Industry Specific
  • Network Management
  • Photos / Graphics
  • Page Layout
  • VMWare
  • Misc
  • Web Development
  • OS
  • CYGWIN
  • Voice Recognition
  • Message Queue
  • Quality Assurance
  • Security
  • Firewalls
  • MultiMedia Applications
  • Development
  • Database
  • Office / Productivity
  • Business Management
  • OS/2 Apps
  • Server Software
  • Internet / Email
ITPro
  • OS
  • Storage
  • Encryption
  • Operating Systems Security
  • Apple Hardware
  • Laptops & Notebooks
  • Servers
  • Networking Hardware
  • Peripherals
  • Devices
  • Displays / Monitors
  • WebTrends / Stats
  • Search Engines
  • Firewalls
  • WebApplications
  • IDS
  • Vulnerabilities
  • Email Clients
  • File Sharing
  • Spy / Ad Blockers
  • Web Browsers
  • Web Servers
  • Networking
  • Anti-Virus
  • Chat / IM
  • Anti Spam
Developer
  • Web Servers
  • Web Browsers
  • Game Programming
  • Dev Tools
  • Industry Specific
  • Office / Productivity
  • Database
  • CYGWIN
  • Web Development
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Programming
  • Content Management
  • Application Servers
  • Protocols
Storage
  • Removable Backup Media
  • Storage Technology
  • Servers
  • Grid
  • Remote Access
  • Backup / Restore
  • Misc
  • Hard Drives
OS
  • Miscellaneous
  • Security
  • Development
  • Linux
  • VMWare
  • MainFrame OS
  • Unix
  • Apple
  • OS / 2
  • AS / 400
  • BeOS
  • Microsoft
  • VMS / OpenVMS
Database
  • Oracle
  • Miscellaneous
  • MySQL
  • Software
  • Sybase
  • Contact Management
  • PostgreSQL
  • Data Manipulation
  • Clarion
  • InterSystems Cache
  • Siebel
  • MUMPS
  • OLAP
  • SQLBase
  • SAS
  • GIS & GPS
  • 4GL
  • Berkeley DB
  • DB2
  • Informix
  • Interbase / Firebird
  • FoxPro
  • Reporting
  • LDAP
  • Filemaker Pro
  • MS SQL Server
  • dBase
  • MS Access
Security
  • Misc
  • Web Browsers
  • Software Firewalls
  • Operating Systems Security
  • File Sharing
  • Spy / Ad Blockers
  • Vulnerabilities
  • WebApplications
  • IDS
  • Anti-Virus
  • Encryption
  • Anti Spam
  • Email Clients
  • VPN
  • Chat / IM
Programming
  • Editors IDEs
  • Installation
  • Handhelds / PDAs
  • Multimedia Programming
  • System / Kernel
  • Algorithms
  • Game
  • Signal Processing
  • Project Management
  • Open Source
  • Database
  • Misc
  • Languages
  • Processor Platforms
  • Theory
Web Development
  • Scripting
  • Blogs
  • Web Servers
  • Software
  • Search Engines
  • Web Graphics
  • Images
  • Internet Marketing
  • Images and Photos
  • Components
  • Document Imaging
  • Web Languages/Standards
  • Illustration
  • WebApplications
  • Fonts
  • WebTrends / Stats
  • Authoring
  • Digital Camera Software
  • Miscellaneous
Networking
  • Protocols
  • Apple Networking
  • Network Management
  • Message Queue
  • Application Servers
  • Content Management
  • File Servers
  • Email Servers
  • Misc
  • Java Editors & IDEs
  • Wireless
  • Networking Hardware
  • Backup / Restore
  • System Utilities
  • ISPs & Hosting
  • Web Servers
  • Storage Technology
  • Removable Backup Media
  • Servers
  • Broadband
  • Grid
  • OS / 2
  • Novell Netware
  • Unix Networking
  • Windows Networking
  • Security
  • Telecommunications
  • Operating Systems
  • Linux Networking
Other
  • Community Advisor
  • Lounge
  • Community Support
  • New Net Users
  • Philosophy / Religion
  • Math / Science
  • Miscellaneous
  • URLs
  • Expert Lounge
  • Politics
  • Puzzles / Riddles
Community Support
  • Suggestions
  • New to EE
  • New Topics
  • Community Advisor
  • CleanUp
  • Announcements
  • General
  • Feedback
  • Input
  • EE Bugs
 
05.06.2008 at 02:58PM PDT, ID: 21511408
First thing I would check is the actual IP on client's side on VPN dialup adapter, which is probably your old IP. Change it to new one.

And my comment:
you don't need to use VPN only for remote Outlook access. Instead go with SSL certificate and establish RPC over HTTP connection from client's Outlook to your Exchange server. ISA supports this without a problem.
 
05.06.2008 at 03:03PM PDT, ID: 21511434
Also, check the port forwarding has been configured correctly on the router for the updated IP.

Adam
 
05.06.2008 at 03:03PM PDT, ID: 21511439

Rank: Genius

If you are using the standard Windows VPN, it uses PPTP and no certificates. However, the proper way to have users connect with SBS's VPN is using the Create remote access disk method or download the VPN client from the remote web workplace page. In order to update both of these after changing your public IP you need to re-run the Configure Remote Access Wizard (located: server management | internet and e-mail | configure remote access). Then have the clients install the updated client. As Labsy stated, they may be connecting to the old IP. You cannot manually change that on the SBS VPN client.
 
05.06.2008 at 03:37PM PDT, ID: 21511624
Hi Guys,
Thanks to you all for your comments. RobWill, the original VPN clients were setup using the SBS connection wizard, etc. I've converted to the 'Run the wizards' school of thought for all SBS activities (it saves time in the long run). What I'm trying to understand is 'does the certificate change if the IP address changes' so does the SBSpackage contain a resolved version of the FQDN.

I'm going to run the Connection wizard again (since i now know the DNS propagations have happned) and try the VPN. If that doesn't work I'm going to rebuild the SBSpackage (thorugh the RRW) and download to a user and try that. I'll let you all know ho I get on.

Thanks again for your inputs, any more background would be appreciated, I'd liek to get on top of this once and foro all.

Regards
Trevor
 
05.06.2008 at 03:43PM PDT, ID: 21511647

Rank: Genius

If OWA is working then your certificates are OK. The SBS VPN does not use certificates at all so that would not be the problem. But it does create the VPN client using the current IP, so rerunning the configure remote access wizard and redeploying the client "should" fix the problem.
 
05.06.2008 at 04:21PM PDT, ID: 21511797
And to answer the last question:
NO, SSL cert is not locked to and does not contain IP, because it is not Layer3 protocol, but rather applied on top of it.  
 
05.07.2008 at 05:04AM PDT, ID: 21515398
Hi Guys,
OK so I get the picture with regard to SBS VPN. IE SBSpackage uses PPTP therefore no certificates involved. So all I need to do is ensure SBS VPN server is setup OK and download the resulting SBSpackage to the client, install and presto we should be go . . . .hmmmm. (By the way there is a Draytek 2820 router on the external side of the 2 NIC server this has VPN passthrough set both by unticking the PPTP,L2TP and IPSEC options but also by forwarding port 1723 to the servers external NIC.

I did that just now but the Connection manager has installed on the client with mini port configured as L2TP not PPTP. I have checked a machine which has not been updated and that still says PPTP. I have rerun the Routing and Remote access wizard on the server and see 5 wan mini ports setup for PPTP only, no L2TP.
How do I ensure that teh SBSpackage is built for PPTP only not L2TP?? Is this a client configuration issue or is it (as I suspect) part of the SBSpackage build and/or config file.

Thanks again for your valued comments

Regards
Trevor
 
05.07.2008 at 05:08AM PDT, ID: 21515431

Rank: Genius

I have never heard of the SBS "packager" creating L2TP VPN clients. Nothing you can edit so perhaps you are best just to create a manual VPN client on the user's machine, at least as a test. To do so follow the details outlined in the following:
http://www.lan-2-wan.com/vpns-RRAS-1nic.htm
 
05.07.2008 at 01:34PM PDT, ID: 21520148
Hi Guys,
I've taken the heat out of the problem by setting up the VPN clients manually (I used to do this but converted to using the SBS tools as per advice) The connections worked straight away so the problem must be with the SBSpackager. Thanks for the pointers on this RobWill.

Can anyone tell me how to control what protocol is specifiied for use in the SBSpackager? I thought this might have been something to do with the Routing and Remote access wizard which builds the config file for the SBSPackager. There was nothing obviously available to indicate the use of L2TP or PPTP I'd really liek to get this understood as I can see it is going to come back and bite me again.

Regards
Trev
 
05.07.2008 at 03:55PM PDT, ID: 21521064

Rank: Genius

There is no way to configure the SBS "packager". The only thought I would have is to re-run the "configure remote access" wizard, but choose disable, then go to RRAS and make sure it is disabled. Then re-run the "configure remote access" wizard again.
 
05.08.2008 at 05:20PM PDT, ID: 21529582
My guess is that L2TP might get created through wizard in case your server has private addresses on both NIC cards, so wizard assumes L2TP Compulsory tunneling needs to be created, which makes your SBS box as a forwarding machine for VPN requests between clients on one side and another server on the other side. But his is just a guess.
 
05.08.2008 at 05:25PM PDT, ID: 21529602
Another guess:
Since PPTP does not need certificate, just user authentication and then establishes encrypted link, and L2TP/IPSec DOES need SSL cert, it might be SSL cert guilty for your wizard, which then automatically thinks L2TP needs to be created for client VPN.
I guess RobWill's advice might get rid of it.
 
05.09.2008 at 03:31AM PDT, ID: 21531515
Hi Labsys
Both NICs have private IPs yes, but this has always been the case on this a the other servers that I run.
The SBSpackager normally instals OK . . .hmmm. Can anyone say when the packager actually gets built. Is it at the point of download (RWW), after Routing and Remote Access wizard is run, or when the Email and Internet connection wizard is run . . . or some other time.
This may help determine the issue . . . but there again . . .
Haven't tried RobWills suggestion yet as I've had to play catchup.

Regards
Trevor
 
05.09.2008 at 03:53AM PDT, ID: 21531592

Rank: Genius

The download package is written/updated when you run the "configure remote access wizard"
 
 
20080236-EE-VQP-29 / EE_QW_2_20070628