Solved

Pinging to Server when connected thro VPN

Posted on 2009-04-12
10
1,028 Views
Last Modified: 2013-12-05
I have configured win2000 Server (SP4) as VPN server. (XX.XX.XX.200)  When i am not in the office i connect to the server thro Winxp vpn client thro PPTP. Offlate i having this problem. I am able to connect to the vpn server smoothly (XX.XX.XX.200). i can also ping to this machine. But i am not able to ping any other server in my lan.
i,e to other servers like mail server (xx.xx.xx.51) and DB server (XX.XX.XX. 2) Hence i am not able to connect
to these servers when i am not in the office.

Is there any specific reason for this? or do i need to change any settings in my vpn server(XX.XX.Xx.200)

I request an early help in this regard
0
Comment
Question by:venkataramanaiahsr
  • 6
  • 4
10 Comments
 
LVL 3

Expert Comment

by:cubeeq
Comment Utility
The server must be configured as router as well.
0
 

Author Comment

by:venkataramanaiahsr
Comment Utility
When i configure it as vpn server (routing and remote access) , will it not be configured as router as well?
or do i need to configure it separately. if so how to do it . can you pls elobarate on this


0
 
LVL 3

Expert Comment

by:cubeeq
Comment Utility
hi this is the output of route print on server after the client has connected and acquired address 10.0.0.125:

dest            mask                           gw                   interface       metrics
10.0.0.120  255.255.255.255        127.0.0.1         127.0.0.1     50
10.0.0.125  255.255.255.255        10.0.0.120       10.0.0.120   1

It is win2k3 SBS server where the .120 host is the RAS server component. The server itself has 10.0.0.99 and you are right - it is NOT the router, only RAS. However in configuration of <server> in RAS msc there is IP routing enabled. The client has Default gateway of remote network enabled, which is the default - settings in properties of TCP/IP of VPN network connection.

0
 

Author Comment

by:venkataramanaiahsr
Comment Utility
can u explain in little bit detail about this settings. i am furnishing some more information. when i connect thro vpn to my office lan here are the vpn connection settings

PPP adapter

        Connection-specific DNS Suffix  . :
        Description . . . . . . . . . . . : WAN (PPP/SLIP) Interface
        Physical Address. . . . . . . . . : 00-53-45-00-00-00
        Dhcp Enabled. . . . . . . . . . . : No
        IP Address. . . . . . . . . . . . : 128.128.XX.B
        Subnet Mask . . . . . . . . . . . : 255.255.255.255
        Default Gateway . . . . . . . . . :
        DNS Servers . . . . . . . . . . . : 128.128.XX.A
                                                     125.22.47.125



      128.128.XX.A  is the ip address of my vpn server. 128.128.XX.B  is ip address receviced by my laptop when connected to vpn server.  i am able to ping to 128.128.XX.A without any issues.  but when i try to ping to other ipaddress in the office lan , request time out comes.

I have noticed additional  points here.

1.  when i connect thro vpn , the subnet mask received is 255.255.255.255 where as the all the systems in my   office   lan  are in the subnet mask 255.255.255.0.
2. and default gateway is blank

is it because of this reason. but then it is pinging to vpn server.  The logic is sightly going above my head.
can u pls explain the reasons for points 1 & 2. This might throw some light towards finding solution

I have unchecked the Default gateway of remote network in vpn connection settings



0
 

Author Comment

by:venkataramanaiahsr
Comment Utility
Vpn server is win2000 Server with SP4 (Advanced Server Enterprise editon)
0
Promote certifications in your email signature

Has your company recently won an award or achieved a certification? They'll no doubt want to show it off. Email signature images used to promote certifications & awards can instantly establish credibility with a recipient and provide you with numerous benefits.

 
LVL 3

Expert Comment

by:cubeeq
Comment Utility
beware 128... is public ip, you should not use it.

if you get the full mask, it means that your computer is "alone" and does not belong to any network. you can try following tips:

1. add route to "128..."/24 network: route add 128.128.XX.0 mask 255.255.255.0 128.128.XX.A
2. use tracert -d 128.128.XX.B on some computer in your lan to see what hops are used - if you don't see 128.128.XX.A - you don't have routing to your client - then you can add route to server - you can route to just one host: route add 128.128.XX.B mask 255.255.255.255 128.128.XX.A

But in ideal case you should have intranet space addresses - 192.168.X.X, 10.X.X.X (not mentioning 172.16.) and on your server there should be DHCP for LAN for lets say your 100 computers, then DHCP scope for RAS (15 addresses) and the server should have two addresses - one physical ip and one "logical" RAS ip. the physical would lie in first scope and the logical in second.

0
 

Author Comment

by:venkataramanaiahsr
Comment Utility
if you get the full mask, it means that your computer is "alone" and does not belong to any network.

What does it mean?  i am able to connect to my office lan thro vpn  (dialup internet) when i am out of office    

and i am getting the internal ip configured for office lan. i am able to ping to vpn server in the office lan

It is only i cannot ping to other servers

0
 

Author Comment

by:venkataramanaiahsr
Comment Utility
I have changed the vpn server from win2000 to win2003.  there ip routing option is checked which i suppose means it also acts as router along with RAS server. Now when i connect to RAS server thro VPN and try to ping
to other server 128.128.XX.C following is the output.

can you pls suggest is there anything i am missing by the following output


C:\Documents and Settings\venkat>ping 128.128.XX.C /t

Pinging 128.128.XX.C with 32 bytes of data:

Reply from 128.128.XX.C : bytes=32 time=371ms TTL=127
Request timed out.
Request timed out.
Request timed out.
Request timed out.
Request timed out.
Request timed out.
Request timed out.
Request timed out.
Request timed out.
Request timed out.
Request timed out.
Reply from 128.128.XX.C : bytes=32 time=426ms TTL=127
Reply from 128.128.XX.C : bytes=32 time=424ms TTL=127
Request timed out.
Request timed out.
Request timed out.
Reply from 128.128.XX.C : bytes=32 time=908ms TTL=127
Reply from 128.128.XX.C : bytes=32 time=663ms TTL=127
Request timed out.
Request timed out.
Request timed out.
Reply from 128.128.XX.C : bytes=32 time=483ms TTL=127
Reply from 128.128.XX.C : bytes=32 time=427ms TTL=127
Request timed out.

Ping statistics for 128.128.XX.C :
    Packets: Sent = 25, Received = 7, Lost = 18 (72% loss),
Approximate round trip times in milli-seconds:
    Minimum = 371ms, Maximum = 908ms, Average = 528ms
0
 
LVL 3

Accepted Solution

by:
cubeeq earned 500 total points
Comment Utility
well, it seems like very bad connection. disconnect the vpn and ping the external ip in the same way. you will see if the problem is more likely in your intranet or at your provider
0
 

Author Comment

by:venkataramanaiahsr
Comment Utility
Pls find enclosed below the ping stat when connected from my laptop outside the office to office lan thro vpn


Ping stat for vpn server

ping 128.128.XX.A         - VPN Server in my office LAN

Pinging 128.128..XX.A with 32 bytes of data:

Reply from 128.128.XX.A: bytes=32 time=625ms TTL=128
Reply from 128.128.XX.A: bytes=32 time=418ms TTL=128
Reply from 128.128.XX.A: bytes=32 time=438ms TTL=128
Reply from 128.128.XX.A: bytes=32 time=418ms TTL=128

Ping statistics for 128.128.XX.A:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 418ms, Maximum = 625ms, Average = 474ms

2. Ping stat to google

ping google.com

Pinging google.com [209.85.171.100] with 32 bytes of data:

Reply from 209.85.171.100: bytes=32 time=555ms TTL=236
Reply from 209.85.171.100: bytes=32 time=550ms TTL=236
Reply from 209.85.171.100: bytes=32 time=748ms TTL=236
Reply from 209.85.171.100: bytes=32 time=548ms TTL=236

Ping statistics for 209.85.171.100:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 548ms, Maximum = 748ms, Average = 600ms


This shows the internet connection is ok (net is connected thro datacard max 15KBPS bandwidth).
 
Since it is pinging to vpn server without any problem i feel even the vpn part is ok.  As suggested by you earlier
the vpn server may not be routing the requests to other systmes properly  though i have checked the router option in RAS. Is there anything else i can do (like say manually configure the static routes to other servers in the lan in RAS console).  Pls advise.  I need to find a solution for this as i need to configure this setup at my md's laptop.
 
  Is there any alternate easy solution  for the above requirement.




 


 

0

Featured Post

Promote certifications in your email signature

Has your company recently won an award or achieved a certification? They'll no doubt want to show it off. Email signature images used to promote certifications & awards can instantly establish credibility with a recipient and provide you with numerous benefits.

Join & Write a Comment

Welcome to my series of short tips on migrations. Whilst based on Microsoft migrations the same principles can be applied to any type of migration. My first tip Migration Tip #1 – Source Server Health can be found listed in my profile here: http:…
Have you considered what group policies are backwards and forwards compatible? Windows Active Directory servers and clients use group policy templates to deploy sets of policies within your domain. But, there is a catch to deploying policies. The…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now