Solved

Cannot connect to SBS 2003 VPN

Posted on 2004-09-28
12
358 Views
Last Modified: 2012-06-21
I have configured my Small Business Server 2003 server for VPN access.  I can
connect to the Remote Web Workplace, and download the Connection Manager.

When I try to use the SBS connection to connect from my home XP Pro computer to
the server , I get this error:

Error 721.  The remote computer did not respond.

I am using a Linksys BEFVP41 router on the server and have ports 1723 and 47
forwarded to the server, TCP and UDP.  I can look at the incoming log on the
router, and see the requests from my home IP, destination port 1723.  I do not
see any outgoing responses from my server to my home IP address.

I am running ZoneAlarm at home, but shutting it down seems to have no effect.

I am an adminstrator for the domain, and can connect with Remote Desktop fine.
I have permissions to connect (as far as I can tell!).  There are no error
messages logged in the event logs that I have found.

What are my next steps to troubleshoot / resolve this issue?  
0
Comment
Question by:localmagic
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 4
12 Comments
 
LVL 5

Expert Comment

by:Dragonmen
ID: 12169003
If you have any firewall on the server try to shut it down (especially integrated windows firewall).
Try to install some packet-analyzer (like commview) to see if you are getting any request on the server. If you are not getting request that means that packet is never reached that server. Try to check on the router where packer is going and on what port.
0
 
LVL 3

Expert Comment

by:ccceqo2
ID: 12171940
Figure out if it is the router or the server blocking access.
Go in to your router and put the server as the "DeMilitarizedZone" DMZ
This will make sure the router is not blocking anything traveling to the server.
Now test and if you can connect, the problem lies with the router.
If you still can't connect the problem lies with the server (and possibly the router too!).
0
 
LVL 3

Expert Comment

by:ccceqo2
ID: 12173018
0
Defend Your Organization from The Greatest Threats

Looking to fill the gaps in your security? Bring together information from the network, endpoint and threat intelligence feeds to really see what's happening in your organization. Join the WatchGuardians in their adventures fighting cyber crime!

 

Author Comment

by:localmagic
ID: 12174959
Thanks for the ideas.  I will experiment some and get back with the results.
0
 

Author Comment

by:localmagic
ID: 12180690
I tested this morning with the server in the DMZ zone.  Got the same 721 error.
0
 
LVL 3

Accepted Solution

by:
ccceqo2 earned 500 total points
ID: 12200498
Make double sure that you are using the latest firmware on the linksys.
0
 

Author Comment

by:localmagic
ID: 12209636
This router is running their latest, which is 1.41.1, Sep 2003.
0
 
LVL 3

Expert Comment

by:ccceqo2
ID: 12389469
Hi, hope you are still watching this thread.
I just finished working on a VPN connection that started working after I installed all the windows XP service packs and updates. Might be another thing worth checking.
0
 

Author Comment

by:localmagic
ID: 12390270
We are current on the updates as far as I know.  MS really needs a 'windows update' version for servers that links to all the updates for the various components (Exchange, SQL, etc.).

Anway, on the VPN connection, I opened an incident with Microsoft last week.  The server side seems to function ok (I can connect to it internally via VPN).  

We currently suspect the Linksys Router.  I worked with their tech support, but beyond reflashing it, they ran out of ideas.  I have to go onsite to reflash it and/or replace it.  I plan to post updates when I know more.
0
 

Author Comment

by:localmagic
ID: 12396586
Today I reflashed the Linksys Router, and the symptoms remained the same (port 1723 traffic flows, but not GRE Protocol 47).

I temporarily replace the current Linksys (WRT54GS) with our previous router (BEFVP41) and got the same results.

As a further test, I replaced the server with my laptop, and ran a Port 1723 / GRE test back to the client machine.  It ran fine, which indicates to me that the local ISP (Road Runner) is not doing the filtering.

Since the server works to local clients, and since the RR to client connection works, I can only conclude that the Linksys Routers are not passing the protocol properly.

I contacted Linksys Technical Support again, and after another hour, and getting ugly, they finally 'discovered' a new firmware release, version 3.17.4, released last Tuesday!  I am going to install the update and test by this coming Tuesday.
0
 

Author Comment

by:localmagic
ID: 12415445
I installed the firmare update for the router (3.17.4), and can now successfully connect to the SBS server.

Interestingly, this update was created the day that I first called Linksys and reported the problem.  It is clearly a requirement for VPN.

I can view the shares of the the server machine by IP address now, but not other machines on the network.  Is this a configuration problem or a VPN fact of life?  I  thought I could specify other machine address on the remote network (e.g., \\192.168.20.xxx) and browse them like I do the server (\\192.168.20.3).  They use a different subnet from my home machine (192.168.1.xxx).


0

Featured Post

Defend Your Organization from The Greatest Threats

Looking to fill the gaps in your security? Bring together information from the network, endpoint and threat intelligence feeds to really see what's happening in your organization. Join the WatchGuardians in their adventures fighting cyber crime!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For many of us, the  holiday season kindles the natural urge to give back to our friends, family members and communities. While it's easy for friends to notice the impact of such deeds, understanding the contributions of businesses and enterprises i…
This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question