Setting up a VPN with ISA 2006

Posted on 2009-05-07
Medium Priority
Last Modified: 2012-06-21
I am having real difficulties setting up a basic PPTP VPN connection through our ISA 2006 server. I wish to have external access to our network. Here is my configuration and what I have attempted. Sorry it's long.

Windows 2008 DC
Installed ISA 2006 Standard on Windows Server 2003 with all services packs , updates etc.

IP configuration on ISA:

IP -
<no gateway>
DNS - &

IP -
GATEWAY - (router)
DNS - & (external DNS for internet access)
DISABLED Client for Microsoft Networks and File and Print Sharing on this NIC

I have enabled VPN Client Access. I had to remove the external DNS entries from the WAN NIC as ISA popped up with a message stating that it could not add the ISA server to AD. Once these entries were removed, it registered OK. They are back on the NIC as I am unsure on how to set forwarders up correctly under DNS.
Address assignment method is DHCP
Authentication is MS-CHAPv2
No RADIUS server

I have created a VPN Users group in AD and added my user to this group.
Under VPN Client Properties I have set 10 VPN user limit. Added the VPN Users group. Enabled PPTP.

In the Firewall Policy, I have setup the following 2 rules:

DHCP Request (VPN to Local Host)
Protocols: DHCP (request)
From: VPN Clients
To: Local Host
All Users

DHCP Reply (Internal to VPN)
Protocols: DHCP (reply)
From: Internal
To: VPN Clients
All Users

In the Routing and Remote Access, I have setup a DHCP Relay Agent and set the IP address of our DHCP server.

I have opened port 1723 on our router and have pointed it to the external NIC IP.

I have checked to see if ISA is listening for port 1723 using netstat and it is.

When I try to connect to the VPN, ISA logs display that it sees the external connection using PPTP protocol and was successful. Then there is a DHCP request that is denied Default Rule (not sure if this is the VPN client attempting to request a DHCP address or not). At the client end I receive an Error: 721 message.

I have looked far and wide for a solution but I cannot. Can any VPN/ISA gurus help please?

Question by:Pete_Zed
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2

Expert Comment

ID: 24345547
I'd start by connecting another machine to the 192.168.1.x network, giving it an address and trying to VPN to I'm assuming that because of the double translation you're going through, between MTA limits and other issues it'll have some problems. Start to see if the ISA firewall even establishes a connection. If it's an IP issue, set a static IP for the VPN connection, and see if it connects. That's a start.

Author Comment

ID: 24350642
I connected a laptop up to the 192.168.1.x network and I could connect without a problem. I can't map network drives but that will be another problem which I will look at. I can ping the IP and FQDN of the internal servers OK.

So what can I do for my off-site computers that I want to connect to our network via a VPN connection? I'm not sure what my next troubleshooting step is.

Accepted Solution

Pete_Zed earned 0 total points
ID: 24369636
OK, I have found the answer to all my problems - well VPN problems anyway. I had a suspicion that our aging Nokia M1122 ADSl router was not allowing PPTP pass through and I was right! I have replaced the router with a Linksysy model and now I have VPN access. Yay!

Featured Post

Enroll in August's Course of the Month

August's CompTIA IT Fundamentals course includes 19 hours of basic computer principle modules and prepares you for the certification exam. It's free for Premium Members, Team Accounts, and Qualified Experts!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I've had to do a bit of research to setup my VPN connection so that Clients can access Windows Server 2008 network shares.  I have a Cisco ASA 5510 firewall.  I found an article which was extremely useful: It had a solution if you use ASDM to config…
Using Windows 2008 RRAS, I was able to successfully VPN into the network, but I was having problems restricting my test user from accessing certain things on the network.  I used Google in order to try to find out how to stop people from accessing c…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question