Gateway to Gateway VPN One-Way Shared Folder Access

Posted on 2007-11-14
Last Modified: 2012-05-05
I have a gateway to gateway VPN setup using two Linksys RV042 routers. Netbios boardcast is not enabled. We used a WINS server for name resolution on the network (it's on network one).

First Network:

Second Network:

Both networks can ping each other fine.
Second network can access shared folders on first network, but first network cannot access shared folders on Second network. What's going on?
Question by:tvacc
  • 4
  • 4
LVL 28

Expert Comment

by:Michael Pfister
ID: 20278796
Can you post

ipconfig /all

from a client on each end?

Whats the WINS server's IP?
Do you have DNS on both ends? If yes, whats the IP?
LVL 77

Expert Comment

by:Rob Williams
ID: 20286325
Can you access the shared folders using the IP such as:
If not, is file and print sharing enabled on the \\192.168.5.x share ?
Is the Windows or any other software firewall enabled on the \\192.168.5.x share ?  If so, and even if there is an exception it may be limited to allowing the local network only. See the following site regarding configuring the firewall exception for computers outside the LAN. The example is for port 3389, for file shares you will need TCP 139 & 445, UDP 137 & 138:

Author Comment

ID: 20300459
Here's the requested information:

The WINS server is on network one. It has an IP of It's also the domain controller. This is the setting for every computer.

All clients on both ends have DNS first point to and then to our ISP's primary DNS.

I can't run a ipconfig /all right now. I'm not on site at either place and I'm working remotely on something at at the moment. I'm fairly certain the ip settings are correct though.

Author Comment

ID: 20300559
Oh, and no I cannot access it based on \\IP address\ShareName.

I can ping from network 2 to network 1 (and 1 to 2) using ip addresses and computer names.
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

LVL 77

Expert Comment

by:Rob Williams
ID: 20300585
Generally in a domain environment the ISP's DNS should never be added, even as a secondary. They should only be added as a forwarder in your DNS management console. Windows will not always use the server's DNS first, especially over slow connection, and it results in name resolution issues.

Just saw your second post. Above still applies but it's not a DNS or Wins issue if you cannot access shares by IP. Sounds more like a software firewall issue, or permissions.

Author Comment

ID: 20374276
I think I've started to narrow it down. I also think it's a software firewall issue somewhere. SBS2003, by default, makes clients have the windows firewall on without the ability to change that. I think that's my problem. Now I can't get group policy to allow the clients to turn off the firewall (or even just turn it off through group policy). I have searched on here and have set windows firewall disabled for all network connections, but when I log on to the client the firewall is still enabled and I cannot disable it.
LVL 77

Accepted Solution

Rob Williams earned 500 total points
ID: 20378883
Users can create exceptions in the firewall configuration if you like, but they cannot switch it off.
As mentioned the firewall creates an exception for file and print sharing when it is enabled, but only for the local LAN. If you want to go the exception route you can do so by going to control panel | windows firewall | Exceptions | highlight file and print sharing and chose edit | highlight each protocol/port ( all 4 one at a time) and chose change scope | add your remote VPN subnet or "allow all computers" | save

If you want to disable the firewall, open the group policy management console on the SBS to group policy objects, and disable (not delete) the 2 polices, by right clicking on the policy and choosing GPO status and un-check enabled:
  Small Business Server Internet Connection Firewall
  Small Business Server Windows Firewall

It can take up to 90 minutes for the policy to be applied to the workstation. You can force this almost immediately by running at a command line, on the workstation:
gpupdate /force


Author Comment

ID: 20473348
That fixed it. I didn't delete (rather, no longer enforced linked) the GPOs as I don't like to delete things. Now I can connect fine. Thanks.
LVL 77

Expert Comment

by:Rob Williams
ID: 20473551
Great Glad to hear.
Thanks tvacc.
Cheers !

Featured Post

New! My Passport Wireless Pro Wi-Fi Mobile Storage

Portable wireless storage to offload, edit, and stream anywhere.

High-capacity, wireless mobile storage designed to accompany professional photographers and videographers in the field to easily offload, edit and stream captured photos and high-definition videos.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is in response to a question ( here at Experts Exchange. The Original Poster (OP) requires a utility that will accept a list of IP addresses …
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

912 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

26 Experts available now in Live!

Get 1:1 Help Now