Solved

Issue with VPN clients accessing domain resources

Posted on 2006-07-07
11
384 Views
Last Modified: 2012-05-05
We are currently having an issue in which VPN clients that are domain members cannot access file shares or the exchange server but can ping them by name, yet VPN clients that are NOT domain members CAN access file shares and the exchange server.  

We are running a 2003 native AD
ISA 2004 SP2
Exchange 2003
XP clients

Any ideas would be greatly appreciated.

Thanks.
0
Comment
Question by:CMH_DS
  • 5
  • 3
11 Comments
 
LVL 25

Expert Comment

by:mikeleebrla
ID: 17059260
sounds to me like you need to check your NTFS security permissions on your folders that you have shared (that is on the security tab on the properties of any folder)

can you elaberate on what you mean they can access the exchange server?  how are they accessing it?  Outlook client? Outlook Web? POP3? etc etc

0
 

Author Comment

by:CMH_DS
ID: 17059444
We are using Outlook 2003 on the clients.  

I can use a non-domain machine via a DSL connection to VPN into the domain, I can configure Outlook 2k3 to connect, I can manually map network drives, everything works fine.. But if I join that machine to the domain, then connect via VPN I cannot map network drives and I cannot access the exchange server  with Outlook2k3..
0
 
LVL 25

Expert Comment

by:mikeleebrla
ID: 17059554
are you mapping drives via IP or via netbios names?
try doing it via IP address rather than via netbios names b/c getting netbios names to work over the VPN would be a nightmare.


how are you trying to connect to the exchange server via outlook?  MAPI, IMAP, pop3 etc?
0
 

Author Comment

by:CMH_DS
ID: 17059831
We are mapping via netbios names, which I have done at previous companies with no issues, and in this case I can map vie netbios name when connected to the VPN on a NON domain workstation.

We are connecting to exchange via outlook2k3 using the exchange service.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 25

Expert Comment

by:mikeleebrla
ID: 17059872
well,  can you connect via IP like i asked you to test?  that will narrow down the problem.

>>We are connecting to exchange via outlook2k3 using the exchange service.
That is called MAPI.
0
 

Author Comment

by:CMH_DS
ID: 17059965
We cannot map via IP address on the domain workstation.  This almost seems like an authentication issue on the domain machines via VPN.
0
 

Author Comment

by:CMH_DS
ID: 17061184
500 points
0
 
LVL 3

Accepted Solution

by:
isd503 earned 500 total points
ID: 17068052
I think your problem resides on the ISA server.  

If the VPN client works from a machine not joined to the domain, then you join the machine to the domain and it does not work, I think the VPN client would not be the problem.

VPN clients typically authorize and authenticate (or should) based upon configured (in the client software) and supplied (by the user) credentials, not on aspects of the machine from which you are connecting.

Have you tried uninstalling the VPN client from the machine and reinstalling it once you are connected to the domain just to rule it out?
0
 

Author Comment

by:CMH_DS
ID: 17083157
We've got this problem resolved, it was on the ISA server.  We had to disable IP Fragment Blocking.

This thread can be closed.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
GPO Access denied in AD 12 39
Bizarre hard disk problem 15 107
AD Replications issues 12 86
Intel Server Board SE7525GP2 Doesn't Recognize Full Hard Drive Capacity 4 83
This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …
Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now