Hello there,

          I have two network located in two different locations. On Network 1 I have a PIX firewall, and behind the PIX there is a Windows Server 2003 machine running a VPN server from microsoft. On Network 2 I have Linksys Router which is just port forwarding to the inside server which is running also Window Server 2003 with a VPN server. If I try to connect to Network 1 VPN server I have no trouble at all, everything goes fine. However, if I try to connect from Network 1 to Network 2 VPN server I am not able to connect to from any of the inside host behind the PIX except for one machine which is the Windows Server 2003 machine behind the PIX which is running a VPN Server. Why is it that I am able to connect from the VPN Server located in Network 1 to Network 2 VPN server, but I am not able to connect from the other inside hosts which are located also in the same LAN of the VPN Server loctated in Network 1? If you need a copy of the PIX config please just let me know.

                                                            Thank You in advance
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

if you can connect to the VPN server, I doubt its a pix issue.  Are you sure the VPN server you're connecting to is configured to be a router as well.  its just the first thing that popped into my head anyway.
vreyesiiAuthor Commented:
Thank You for the reply.

Yes the Windows Server 2003 VPN Server which is in Network 2 is behind a Linksys router which is doing port forwarding.

                                  Thank You
vreyesiiAuthor Commented:
In addition, I also noticed something. I noticed that the only way that the VPN server( behind the PIX is able to connect to the VPN server located Network 2 is if only the VPN server in Network 2 is first connected to the VPN server located Network 1 which If I try to connect from the VPN server in Network 1 to the VPN server in Network 2 I am not able to, unless the VPN server in Network 2 is connected to Network 1 VPN server first.

                                                                           Thank You
Are You Protected from Q3's Internet Threats?

Every quarter, WatchGuard's Threat Lab releases a security report that analyzes the top threat trends impacting companies around the world. For Q3, we saw that 6.8% of the top 100K websites use insecure SSL protocols. Read the full report to start protecting your business today!

i wasn't asking if the vpn server is behind the router.  In RRAS, you configured the Win2K3 server to be a VPN server.  In the RRAS, did you make the server a router as well by enabling the LAN routing option.
vreyesiiAuthor Commented:
I am sorry however, I do not know that much about Windows Server 2003, the only thing which I did was setup the VPN Server by going through New Connection Wizard and thats all.

                                    Thank You
will have to get back to you later then.  I mostly run linux now.  haven't run a windows vpn server for several years now.  I have to look it up in one of my books at home so that I know where the option is at.
vreyesiiAuthor Commented:
Hello, did you find anything out?

                                          Thank You
Dushan De SilvaTechnology ArchitectCommented:
Check your ports (incomming and outgoing) are opened as you wish via telnet from both sides.

BR Dushan

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
sorry about taking so long to get back to this.

try opening the RRAS tool, then right click on the server and click properties.
you should be on the general tab.  is the routing checkbox checked? LAN routing only should be good enough
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.