Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

VPN Problems after network gateway changes.

Posted on 2008-06-24
4
Medium Priority
?
207 Views
Last Modified: 2010-04-12
Hi All,

I have users coming in to my network on a ipsec vpn through a Cisco ASA 5510. They have access to one server (mail server) and use a virtual address range of 172.16 etc. The mail server gateway setting is pointing at the asa box on ip 254. We also have a router going to our head office on ip 1.

Now our head office wanted us to route all mail in and out to the head office so asked us to change the gateway settings on the mail servers network card to the .1 router instead of the .254 ASA box. All is fine except the vpn users can access the mail server , cant even ping it. So i put the gateway back to 254 and then added an extra gateway (under adv settings) for .1 which works fine.

Problem is any time i restart the mail server the vpn users are locked out again until i remove the gateway setting and put them in again. Any Ideas?

0
Comment
Question by:frontechltd
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 4

Expert Comment

by:fileinster
ID: 21861652
What email server are you running?

Does the ASA have a route to the addresses in head office via the .1 router? If so it should simply be a matter of configuring your email server to route all mail towards the IP address of the mail server in head office. If there is no upstream mail server then that is a case for policy routing. I know you can configure policy routing on the router, which would work, but no sure if this feature exists on the ASA.
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 1500 total points
ID: 21862100
Add a static route on the mail server:
C:\>route add <subnet of VPN clients> mask <submet mask> <IP of ASA.254> -p
0
 

Author Comment

by:frontechltd
ID: 21872714
In answer to both questions, fileinster: we are running lotus domino. Will check the firewall for routes.

Irmoore: tried the add route and got this:-
The route addition failed: Either the interface index is wrong or the gateway do
es not lie on the same network as the interface. Check the IP Address Table for
the machine.

Thank on you help so far
0
 
LVL 4

Expert Comment

by:fileinster
ID: 21874663
If you tried what LRMoore suggested and got that response it means you got your parameters wrong. Check the help "route /?".

His answer will solve your problem 100%, although not very elegant. But who wants elegance?
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Some of you may have heard that SonicWALL has finally released an app for iOS devices giving us long awaited connectivity for our iPhone's, iPod's, and iPad's. This guide is just a quick rundown on how to get up and running quickly using the app. …
Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses

704 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question