?
Solved

TMG not allowing certain traffic from VPN

Posted on 2009-07-15
2
Medium Priority
?
710 Views
Last Modified: 2012-06-22
Hi,

This is my first EBS 2008 installation and my first time working with Forefront-TMG so please bear with me!

We have a number of users who use VPN to access their Outlook mailboxes. Whilst I am planning on moving them to direct connection (RPC / Outlook Anywhere etc) for the moment, it is convenient to continue like this.

I have setup rules etc as best I can and the VPN now appears to be mainly ok but I am noticing certain protocols & traffic are being blocked. I have checked the logs and from what I can tell, this traffic does not appear to be "named" as the user.

By this I mean when logging in to the VPN remotely I can ping hosts on this network, I can RDP, I can NetBIOS onto all the servers etc, but when I try and use outlook, TMG does not see my VPN username (when viewing in the log) and therefor the Outlook traffic hits the default rule and gets blocked.

I have attached both a text log of this and a screenshot as I'm finding it hard to explain! The log as the most info in and is best viewed with word wrap off, the screenshot just underlines what I'm trying to say.

I have setup the VPN to have the same addresses as the LAN and it gets these via DHCP so the IP address in these logs (192.168.0.90) is my home server connected via VPN. In the screenshot you can see all the allowed traffic in black with the domain & username listed but on the failed Outlook RPC packets it does not have the admin listed although it is still coming in via the VPN and is listed as the "VPN Clients" network (it has to be hitting via VPN or else it would not have an internal IP against it)

I am guessing I must have to add another rule or something but I am blowed if I can work out how to do this! In effect this traffic is internal to internal so I don't see how to add this.

Many thanks

Stephan
Academy Networks
Screenshot.jpg
log.txt
0
Comment
Question by:academynetworks
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
2 Comments
 

Author Comment

by:academynetworks
ID: 24867667
Anyone? :)
0
 

Accepted Solution

by:
academynetworks earned 0 total points
ID: 24868316
Ok I worked it out. I believe I had to add an allow all outbound from VPN clients to internal for this to work. I already had an allow all outbound to external so I just added to this. Anyone know if this is considered safe?...

Allow > All Networks (and localhost) + VPN Clients > External & inbound.

I am guessing it's all outbound so is ok, but a confirmation would be great.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In all versions of ISA Server and the current version of FTMG, the default https protocol uses TCP port 443 and 563 only. This cannot be changed within the ISA or FTMG GUI and must be completed from a Windows cmd prompt on the ISA Server itself. …
Forefront Threat Management Gateway 2010 or FTMG comes with some very neat troubleshooting tools built-in when trying to identify what is actually happening behind the scenes within the product when traffic is passing through its interfaces. To the …
Add bar graphs to Access queries using Unicode block characters. Graphs appear on every record in the color you want. Give life to numbers. Hopes this gives you ideas on visualizing your data in new ways ~ Create a calculated field in a query: …
Do you want to know how to make a graph with Microsoft Access? First, create a query with the data for the chart. Then make a blank form and add a chart control. This video also shows how to change what data is displayed on the graph as well as form…
Suggested Courses

800 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question