Solved

VPN working, but they can't ping our internal network

Posted on 2006-07-14
16
819 Views
Last Modified: 2013-11-16
We have the following VPN path setup with an outside vendor:

[them]----[internet]----[our firewall]----[switch]----[domain controller, internal network, etc]

The VPN (ipsec) tunnel has been established and they can ping our firewall box, and we can ping them, but they can't ping anything past the firewall.  They're trying to ping an internal networked printer but get timed out.  I can ping to theirs just fine.

Since they can ping the firewall itself, I'm assuming something is holding it up at the domain controller level.  What do I need to check to allow them to ping internal machines?

Kevin
0
Comment
Question by:Kevin Smith
  • 3
  • 3
  • 2
  • +6
16 Comments
 
LVL 20

Accepted Solution

by:
RPPreacher earned 66 total points
ID: 17110598
You need an access list permitting traffic from the firewall to the internal network
0
 
LVL 3

Assisted Solution

by:wingspin
wingspin earned 62 total points
ID: 17110609
It could be several things.  
I'd check the default gateway setting of the remote VPN client.  The external IP address of the firewall won't do it.  It depends your setup as to what the gateway IP address should be.  You can try making their own IP address if you're stumped.

Is the VPN port NAT-ed to your domain controller?  

Are you running the Win-logon script after the VPN connects?  



0
 
LVL 2

Assisted Solution

by:just-one-it
just-one-it earned 62 total points
ID: 17110819
What type of vpn are you using?  Is the IP assigned to the vpn client in the same subnet as the printer they are trying to ping?
0
 
LVL 22

Assisted Solution

by:rickhobbs
rickhobbs earned 62 total points
ID: 17110863
What type of firewall?  What is you VPN client?
0
 
LVL 2

Expert Comment

by:just-one-it
ID: 17110887
Is there an echo in here? ;)
0
 
LVL 9

Assisted Solution

by:NYtechGuy
NYtechGuy earned 62 total points
ID: 17110921

It may also be routing:

- Is your network only one subnet, or are there other subnets/routers involved behind your firewall?  They may not have the necessary routes.
0
 
LVL 25

Assisted Solution

by:Ron M
Ron M earned 62 total points
ID: 17111507
Check my previously answered question on expertsexchange.

http://www.experts-exchange.com/Networking/Q_21774941.html

It may apply to you also.

Good luck.
0
 
LVL 77

Assisted Solution

by:Rob Williams
Rob Williams earned 62 total points
ID: 17111593
Is the "firewall box" the default gateway for the devices you are trying to ping.
i.e. is the firewall box's LAN IP the added to the printer's configuration as it's gateway?
Also, the local and remote LAN subnets need to be different for the VPN.
0
How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

 

Author Comment

by:Kevin Smith
ID: 17111605
Yes, the box is the the default gateway, but he can't ping any machine even if it is configured with the default gateway.
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 17111647
-Are the subnets different ? The 2 LAN's should be.
-Are "they" pinging the LAN or the WAN IP of the firewall ?
-perhaps as asked earlier if you could provide more information as to the VPN configuration such as hardware make and model, and the client you are using, we could better assist.
0
 
LVL 7

Assisted Solution

by:nttranbao
nttranbao earned 62 total points
ID: 17120155
from "them", open command promt and use tracert or pathping to trace the route. See whiere it stops responding.

I guess this is because of the firewall NOT allow ICMP from outside into the internal network. There would be nothing to do with routing since your internal network can ping "them" successfully.

If possible , tell us what kind of your Firewall? a computer or a cisco?
0
 
LVL 20

Expert Comment

by:RPPreacher
ID: 17120732
Did you ever add an access-list?  It was the first suggestion and a very common issue with VPN connectivity issues.
0
 

Author Comment

by:Kevin Smith
ID: 17140637
The problem "fixed itself", althought I didn't do anything (guessing it might have been something on their end after all).  I didn't use any of the answers above, but did learn some things so I'm gonna split up the points to everybody if that's cool.
0
 
LVL 20

Expert Comment

by:RPPreacher
ID: 17140643
Thanks.  Glad it resolved.
0
 
LVL 22

Expert Comment

by:rickhobbs
ID: 17141608
Glad I could be of assistance. Thanks!
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 17142005
Thanks ksmithscs,
--Rob
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now