Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


Client not receiving default gateway info from W2K RAS Server

Posted on 2003-11-12
Medium Priority
Last Modified: 2010-03-19
I am trying to resolve an issue whereby a Windows 2000 RAS Server is not allocating a default gateway to clients, and hence they can't get Internet access via the corporate network.

When I connect  a client via ISDN or Modem dial-up, ipconfig states the subnet mask of the connection as, and the default gateway is the same as the IP address assigned to the dial-up client.

Computer Name: RASSERVER
Static IP x.x.x.21
DG x.x.x.130 router to US office

We also have a Firewall x.x.x.10


Setup as a Remote Access Server only.
Enable IP Routing is ticked
Allow IP based remote access... is ticked
Static address pool is defined

IP Routing

General ->Loopback, LAN and Internal. Enable IP Router Management and Router Discovery options both ticked for LAN and Internal interfaces.

Static Routes -> None defined

IGMP -> LAN Connection is enabled as proxy. Internal enabled as router.

Apparently this was working before the firewall was put in place. But now is not. I imagine its a routing thing but not too sure. The firewall is managed by a third party.

Please help.
Question by:gmoore96
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Expert Comment

ID: 9732057
I assume your Internet traffic goes via the Firewall? If so, does you router re-direct unknown traffic to use the firewall, or do you use a web proxy?

Can you do a tracert or ping to an external web site from the RAS server? From the dial-up client? How far do these get?

Let us know, post back the results of the tracert if you like.

Author Comment

ID: 9732322
Here are the results of a tracert to www.microsoft.com direct from the Rasserver console.

Tracing route to a562.cd.akamai.net [] over a maximum of 30 hops:
  1   <10 ms   <10 ms   <10 ms  x.x.x.10

  2   <10 ms   <10 ms   <10 ms  demon.internet.router[x.x.x.129]

  3   <10 ms   <10 ms   <10 ms  rea1-bstdx-1.router.demon.net []

  4   <10 ms    15 ms   <10 ms  anchor-backbone-11.router.demon.net []

  5   <10 ms   <10 ms   <10 ms  anchor-border-1-1-0-2-551.router.demon.net []

  6   <10 ms    16 ms    16 ms  tele-border-4-228.router.demon.net []

  7   <10 ms    16 ms    15 ms  tele-core-11-1-0-238.router.demon.net []

  8    78 ms    94 ms    94 ms  ny1-border-2-x-0-1-1-102.router.demon.net []

  9    78 ms    94 ms    94 ms  gige5-0-225.ipcolo2.newyork1.level3.net []

 10    78 ms    94 ms    94 ms  ae0-56.bbr2.newyork1.level3.net []

 11    94 ms    93 ms   110 ms  so-0-1-0.mp1.boston1.level3.net []

 12    94 ms    94 ms    94 ms  gige11-2.hsa1.boston1.level3.net []

 13    93 ms    94 ms    94 ms  unknown.level3.net []

Trace complete.

We also have an Internet router with the .129 address (as well as the router to the US with the .130 address)

I am not able to dial-in at the moment but can supply a tracert later tonight.


Expert Comment

ID: 9732849
I presume the Internet router is only connected to the Firewall and the ISP?

I forgot to ask earlier, how do your RAS clients get IP addresses, via DHCP or a static pool? If static, what is the range? On the same subnet as the RAS server?
 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks


Author Comment

ID: 9732951
Yes the router is only connected to the Firewall and ISP.

The clients get IPs from a static pool in the range x.x.x.140-149, on the same subnet as the rest of the network, including the RAS Server

Expert Comment

ID: 9733018
That all sounds OK so far, let's see if there is any more info in the client's tracert.

I'm going home soon, will catch up tomorrow... :-)

Author Comment

ID: 9733064
Thanks Roly, speak tomorrow

Author Comment

ID: 9733959
Output of tracert from DUN client to www.microsoft.com.      x.x.x.140 is the dynamically assigned IP address of the client.

Tracing route to a562.cd.akamai.net [] over a maximum of 30 hops:

  1   147 ms   135 ms   128 ms  x.x.x.140
  2   142 ms   142 ms   143 ms  x.x.x.10
  3     *        *        *     Request timed out.
  4     *        *        *     Request timed out...... and so on

Expert Comment

ID: 9734542
This is normal and by design. To use the internet while connected to the vpn, untick the box for "Use Default Gateway on Remote Network". This is set on the client machine within the properties of the VPN Connection. This way, only VPN traffic will travel over the vpn, all other traffic (web browsing) will go out directly over the internet connection.

Author Comment

ID: 9738438
Thanks drev001 but this is actually a RAS Dial-Up server rather than VPN. We have a VPN server and we use your method for Internet access that way. however, we also have a need for some remote users to dial-in and want to make use of the LAN's connection to the Internet.

Accepted Solution

Roly_Dee earned 375 total points
ID: 9738859
So it seems that your IP packets from RAS clients aren't making it past the firewall. I guess the problem is that the firewall knows that all these packets arrive from the RAS server's NIC, but with different source IP addresses.

Can you double-check that RAS clients can ping hosts on your LAN and also on the WAN link to the US: this will definately eliminate any IP routing problems. I can't see this as an issue, but your outsourcer might :-)

You should then get the firewall logs and rules checked.

The firewall logs will show the reason the packets are being rejected, and this rule will need to be adjusted. The RAS server probably needs to be identified as a router, so that it is permitted to send traffic with a different source address. Failing that, it could just allow all traffic from the x.x.x.140-149 range, but that is a bit slack :-o and defeats the object of a firewall

Let me know how you get on

Author Comment

ID: 9738952
I can ping hosts on both the LAN and WAN. I will get the Firewall people to check over the logs and rules as per your suggestion and get back to you. Thanks for all your help so far.

Author Comment

ID: 9873530
Hi Roly, sorry for the delay but we finally got there. There were firewall rules preventing replies going back to the client.


Expert Comment

ID: 11147064
I am having the same problem, but I do not believe it to be related to the firewall rules.  To answer some questions that were asked earlier:

-This worked without a problem until about three weeks ago.  Not sure what changed.

-The RAS server can access the internet, but the dial-up clients cannot.

-The Dial-up clients can access network resources but not the internet.

-The Dial-up clients have their own IP address as the gateway or no default gateway listed at all.

-tracert of www.microsoft.com yeilds the following results:
"Unable to resolve target system name www.microsoft.com"

-Trying to go to the internet from a Dialed-up client spawns absolutely no traffic on the firewall.  No denys, no allows, nothing...

-We are not, nor were we ever, using the RAS server as a router ( I assume because we want to know exactly who the network traffic is coming from on the firewall, so we do not want to mask the IP address in any way), but it worked this way before.

-All other network settings are being pushed down to the machine (DNS, WINS, IP are all correct or within range)

-The Subnet Mask and Default Gateway are the only two incorrect settings.  The SM ends in 255 when it should be 0.

-RAS clients get IP addresses via static pool between 210 and 235.  This is on the same subnet as the RAS server.

-Internet traffic does go through the firewall and we do not use proxy.

-Some of the things I have tried:
>setting the RAS server to be a router
>deleting the TCP/IP protocol and reinstalling
>deleting the network card and reinstalling
>in routing and remote access management, I set a static route = 10.0.0.xx Internal and 10.0.0.xx Local area network

-I'm not saying that it is definitely unrelated to the firewall rules, but you would think that denied traffic would be present on the firewall log if it were.  Seems like the traffic never leaves the DUN PC or the RAS server one.

Any help would be greatly appreciated.  Thanks much!


Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

FIPS stands for the Federal Information Processing Standardisation and FIPS 140-2 is a collection of standards that are generically associated with hardware and software cryptography. In most cases, people can refer to this as the method of encrypti…
Trying to figure out group policy inheritance and which settings apply where can be a chore.  Here's a very simple summary I've written which might help.  Keep in mind, this is just a high-level conceptual overview where I try to avoid getting bogge…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question