Can't connect to Terminal Server over VPN from Windows 2000 clients, Only XP Professional

Posted on 2004-09-27
Last Modified: 2010-04-14
We have 2 servers. One is the PDC running SBS 2000 Server and the 2nd is a BDC setup as a VPN/Terminal Server.

The VPN server has only one network card and we are passing port 1723 through a 3com Officeconnect Firewall to the internal IP address of the VPN server.

Any remote client CAN successfully connect and authenticate to the VPN Server regardless of OS.

The problem is that only XP Professional remote pc's can connect to the VPN/TS via it's internal ip address. Windows 2000 Professional clients cannot connect to the Terminal Server and also cannot ping it by IP address.

Since Terminal Services and VPN Services are setup properly, what is different between Win 2000 Pro and XP Pro which is preventing some clients from hitting the TS.

I have tried 2 different Win 2000 Pro clients on different remote networks and neither can ping the TS while an XP Pro client on the same remote network has no problem whatsoever. I have setup all pc's to use the default gateway setting in the VPN client.
Question by:amkbailey
  • 2
  • 2
  • 2

Expert Comment

ID: 12162977
Before we try troubleshooting, how many remote clients are at this particular site?
LVL 14

Accepted Solution

dlwyatt82 earned 250 total points
ID: 12163007
I answered a question very similar to this a month or so ago... the problem turned out to be that on both sides of the VPN (in the office and on the home network), the connections were going through a cable router, and the cable routers were both set up to use the same private subnet address (192.168.1.*).

Is this how you have your network set up by any chance? If so, change the subnet you're using on one side or the other of the VPN so they're not identical anymore, and your routing problems will clear up.

Author Comment

ID: 12163030
There will be 4 remote sites with about 5 pc's at each site.

Corporate has about 20 pc's.

Get up to 2TB FREE CLOUD per backup license!

An exclusive Black Friday offer just for Expert Exchange audience! Buy any of our top-rated backup solutions & get up to 2TB free cloud per system! Perform local & cloud backup in the same step, and restore instantly—anytime, anywhere. Grab this deal now before it disappears!


Author Comment

ID: 12163040
Yes all remote sites have the same subnet address as corporate but what is odd is that XP Pro handles the routing fine.

Is this an improvement in XP that allows it to work properly versus Win 2000 Professional?
LVL 14

Expert Comment

ID: 12163254
No, it's just a slight difference in which network adapter gets listed in the routing tables for your 192.168.1. whatever subnet. You'll find that on the XP systems, you can't ping anything LOCAL while you're connected to the VPN... you can only connect to systems on the remote network. Windows 2000 does the opposite, but neither can really be considered a "bug" or "improvement" since it's a faulty IP network design that is the root of the problem.

Expert Comment

ID: 12163276
If feasible you may want  to look at having each remote being a Lan-Lan connection instead of Client to lan.  That way you only have to worry about one connection from each remote, instead of 30 clients.

You may want to consider setting up seperate IP segments for each remote site to help the segmentation of your network for easier admin.

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Cannot access port 443 4 573
P2V Windows NT/2000 SP4 3 1,812
Windows 2000 Server to 2008 upgrade 8 506
Windows 2000 Print Server 2 971
NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now