Solved

Setting up a VPN with ISA 2006

Posted on 2009-05-07
3
1,664 Views
Last Modified: 2012-06-21
I am having real difficulties setting up a basic PPTP VPN connection through our ISA 2006 server. I wish to have external access to our network. Here is my configuration and what I have attempted. Sorry it's long.

Windows 2008 DC
Installed ISA 2006 Standard on Windows Server 2003 with all services packs , updates etc.

IP configuration on ISA:

LAN:
IP - 172.16.1.25
SUB - 255.255.0.0
<no gateway>
DNS - 172.16.1.1 & 172.16.1.4

WAN:
IP - 192.168.1.26
SUB - 255.255.255.0
GATEWAY - 192.168.1.254 (router)
DNS - 202.27.158.40 & 202.27.156.72 (external DNS for internet access)
DISABLED Client for Microsoft Networks and File and Print Sharing on this NIC

I have enabled VPN Client Access. I had to remove the external DNS entries from the WAN NIC as ISA popped up with a message stating that it could not add the ISA server to AD. Once these entries were removed, it registered OK. They are back on the NIC as I am unsure on how to set forwarders up correctly under DNS.
Address assignment method is DHCP
Authentication is MS-CHAPv2
No RADIUS server

I have created a VPN Users group in AD and added my user to this group.
Under VPN Client Properties I have set 10 VPN user limit. Added the VPN Users group. Enabled PPTP.

In the Firewall Policy, I have setup the following 2 rules:

DHCP Request (VPN to Local Host)
Allow
Protocols: DHCP (request)
From: VPN Clients
To: Local Host
All Users

DHCP Reply (Internal to VPN)
Allow
Protocols: DHCP (reply)
From: Internal
To: VPN Clients
All Users

In the Routing and Remote Access, I have setup a DHCP Relay Agent and set the IP address of our DHCP server.

I have opened port 1723 on our router and have pointed it to the external NIC IP.

I have checked to see if ISA is listening for port 1723 using netstat and it is.

When I try to connect to the VPN, ISA logs display that it sees the external connection using PPTP protocol and was successful. Then there is a DHCP request that is denied Default Rule (not sure if this is the VPN client attempting to request a DHCP address or not). At the client end I receive an Error: 721 message.

I have looked far and wide for a solution but I cannot. Can any VPN/ISA gurus help please?

0
Comment
Question by:Pete_Zed
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 5

Expert Comment

by:DTAHARLEV
ID: 24345547
I'd start by connecting another machine to the 192.168.1.x network, giving it an address and trying to VPN to 192.168.1.26. I'm assuming that because of the double translation you're going through, between MTA limits and other issues it'll have some problems. Start to see if the ISA firewall even establishes a connection. If it's an IP issue, set a static IP for the VPN connection, and see if it connects. That's a start.
0
 
LVL 8

Author Comment

by:Pete_Zed
ID: 24350642
I connected a laptop up to the 192.168.1.x network and I could connect without a problem. I can't map network drives but that will be another problem which I will look at. I can ping the IP and FQDN of the internal servers OK.

So what can I do for my off-site computers that I want to connect to our network via a VPN connection? I'm not sure what my next troubleshooting step is.
0
 
LVL 8

Accepted Solution

by:
Pete_Zed earned 0 total points
ID: 24369636
OK, I have found the answer to all my problems - well VPN problems anyway. I had a suspicion that our aging Nokia M1122 ADSl router was not allowing PPTP pass through and I was right! I have replaced the router with a Linksysy model and now I have VPN access. Yay!
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Do you have an old router lying around the house that you don’t know what to do with? Check the make and model, then refer to either of these links to see if its compatible. http://www.dd-wrt.com/site/support/router-database http://www.dd-wrt.c…
Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

690 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question