Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 590
  • Last Modified:

Remote VPN clients stuck/hang at "Loading Personal Settings" after installing filtering gateway

Let me first explain how the network is set up.

Main Office: VPN Router > Switch > SBS 2003 Server (only DC)

Each of 7 Branch Offices: VPN Router > Switch > Clients (all running XP, all either SP2 or SP3)

Each of the branch offices has an ipsec vpn tunnel into the main office. The DNS setting on each of the clients points only to the SBS 2003 server at the main office. When the users log on group policy is applied and their documents/desktop/application data are redirected to storage locations at their respective branch offices.

Now, I've added a filtering machine (running Untangle in bridge mode) to the main office. It is only filtering for viruses, spam, phishing, inappropriate content based on categories. No protocol filtering or intrusion detection.

New Main Office network setup: VPN Router > Filtering Computer > Switch > SBS 2003 Server

All of a sudden when people started logging on today from the remote sites (first day with the filtering computer in the mix), they are getting stuck at "Loading your personal settings" and it will hang there.

I remove the filtering gateway and everything goes back to normal. Clients that never logged off last night had no problems during the day (exchange mail worked in Outlook, could browse shared on the SBS 2003 server, etc).

So I guess my question is, what would cause logons to fail at "loading your personal settings" in respect to the filtering computer? What is is blocking that the clients need?
0
tvacc
Asked:
tvacc
  • 4
  • 3
1 Solution
 
Rob WilliamsCommented:
I am not familiar with Untangle, but I assume it uses two network cards? If so are the 'in' and 'out' on the same subnet?

Can the remote client machines ping the SBS?
0
 
Rob WilliamsCommented:
The Untangle computer needs to be configured in "transparent bridge mode". Is this the case?
0
 
tvaccAuthor Commented:
Yes it is. Only the external address is statically configured in this mode. My clients are all set up as 192.168.4.X, 192.168.5.X, 192.168.6.X, etc The main office is set up as 192.168.3.X

I set the Untangle ip for the external interface to be 192.168.3.159/16. Still nothing. Clients at branch offices can ping the SBS 2003 server by ip address, but not by hostname.
0
Improved Protection from Phishing Attacks

WatchGuard DNSWatch reduces malware infections by detecting and blocking malicious DNS requests, improving your ability to protect employees from phishing attacks. Learn more about our newest service included in Total Security Suite today!

 
Rob WilliamsCommented:
One issue: Every site must use a different subnet (network ID). With a subnet mask of /16 (255.255.0.0) all sites are on the same subnet, it will not work. Try changing to /24 (255.255.255.0). I appreciate this may not be an easy change, but it is a basic routing requirement.
0
 
tvaccAuthor Commented:
Each site has their own subnet /24. Someone at Untangle suggested that I make the external interface of the Untangle be /16. That's the only IP that is /16.
0
 
Rob WilliamsCommented:
You will need to change that one as well. All network segments between client and server must use a different network ID (Subnet) or routing cannot take place.

However, is routing the main issue? Can users ping all resources? It is very possible they will not be able to resolve names without some tweaks. See my Blog regarding VPN client name resolution:
http://msmvps.com/blogs/robwill/archive/2008/05/10/vpn-client-name-resolution.aspx
0
 
tvaccAuthor Commented:
I am resolving this with the Untangle people. This can be closed.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now