Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Internal clients cannot access Internet when VPN client is connected

Posted on 2004-10-13
9
Medium Priority
?
255 Views
Last Modified: 2010-05-18
We have a Windows 2003 Server running ISA Server 2000 with routing and remote access configured to accept VPN connections.

There is no problem connecting to the network with the VPN client except that once connected the clients on the internal side of the network can no longer access the internet.

As a side note, this "lockup" also freezes the ISA server until such time that the VPN client disconnects.

Once the VPN client has disconnected, all functions return to normal.

This is a dual-homed server utilizing static-ip addressing for the VPN clients.

Any help is most appreciated.
0
Comment
Question by:BHHanley
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
9 Comments
 
LVL 23

Expert Comment

by:Tim Holman
ID: 12306602
You need to setup split tunnelling.  This means that the VPN tunnel will only encrypt traffic to and from the remote network, rather than trying to send everything (inc. HTTP) down the same connection.
The 'use default gateway on remote network' tickbox under TCP/IP / Advanced settings is the box that enables/disables split tunnelling.
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 12306603
This article should fill in the gaps -

http://www.isaserver.org/tutorials/vpnclientsecurity2.html
0
 

Author Comment

by:BHHanley
ID: 12353032
I apologize for the delay in responding. The above article did not resolve my situation.

I have asked for this question to be closed.

0
Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

 
LVL 23

Expert Comment

by:Tim Holman
ID: 12369077
Bhanley - how did you fix it ?
0
 

Author Comment

by:BHHanley
ID: 12372294
See the question.
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 12380263
> See the question.

Sorry - I can't see anywhere how you've resolved this.  This information could be of use to others out there...  :)
0
 

Author Comment

by:BHHanley
ID: 12381818
The solution lies in the fact that the VPN client must access the Internet via the local proxy server (in this case the ISA server). The VPN must setup it's Internet connection as a dial-up rather than a LAN connection even though it is accessing the local network via the LAN. This forces the client to use the ISA servers' Internet connection and not the ISP providers connection that the VPN is using to access the local network to surf the internet.

0
 

Accepted Solution

by:
RomMod earned 0 total points
ID: 12389455
The question has been PAQ'd and the 500 points have been refunded.
RomMod
Community Support Moderator
0

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Overview Often, we set up VPN appliances where the connected clients are on a separate subnet and the company will have alternate internet connections and do not use this particular device as the gateway for certain servers or clients. In this case…
If you’re involved with your company’s wide area network (WAN), you’ve probably heard about SD-WANs. They’re the “boy wonder” of networking, ostensibly allowing companies to replace expensive MPLS lines with low-cost Internet access. But, are they …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question