Can't RDP into servers after connecting to PPTP

We have a small business essential server.  Our security server which has RAS running on it allows PPTP connections however after you connect and get an IP you can't ping or RDP to any of the servers or workstations on the lan.  Is this a rule on the forefront management ?

LVL 1
corpdsincAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

pwindellCommented:
If the "secureity server" is a Server running TMG,...then yes, by default no traffic is allowed between VPN users and the LAN.  The only thing establishing the VPN does,...is,...establish the connection,...nothing else.

In TMG you need an access rule such as:

From: "VPN Users Network"
To: "Internal"  (or a specific Computer Object)
Protocols: <whatever is needed>
Users: <whatever is needed>

0
markdmacCommented:
My condolences on your purchase of EBS, at least you will get a free upgrade soon to break it apart and de-mystify it.  There are a number of tweaks you will want to do to make it work, have a look at my collection here: http://www.tek-tips.com/viewthread.cfm?qid=1477396&page=1

Regards,
Mark
0
pwindellCommented:
Sounds like you need a PHD in VooDoo to deploy EBS.


0
The Ultimate Tool Kit for Technolgy Solution Provi

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy for valuable how-to assets including sample agreements, checklists, flowcharts, and more!

markdmacCommented:
I was among the first 3000 people in the US to get certified in it and can tell you the product just wasn't ready for prime time.  I work for a MS Gold Certified Partner and we deployed the first production install of the RTM code worldwide and had lots of problems working with it.  My notes referenced above are from working directly with the MS product team.

The good news is that MS realized their mistake and has killed the product.  People that purchased EBS will get a free upgrade pack in the coming months (June or July I believe).  They will get standalone media that will let then break apart the servers and do away with TMG if they want.
0
pwindellCommented:
The bad news is that MS wasn't sharp enough to see those mistakes before the made them.

I think if someone dropped TMG that would be a bad thing, it is an excellent product, it just takes someone knowing what they are doing with it.  People used to ISA could probably deal with TMG with their eyes closed.

But spliting the product components into separate machines is a good thing,...a very good thing.
0
corpdsincAuthor Commented:
Thanks guys.  So...what firewall rule do I need to add to allow VPN traffic...sorry I am definitely not an Forefront expert.
0
pwindellCommented:
I gave you the Rule specs in my first post.
0
markdmacCommented:
Did you implement the TMG tweaks I pointed you to?
0
corpdsincAuthor Commented:
Thanks for all of your help with this.  I am going to make the firewall change now.  Question though, everytime I apply a new rule to Forefront TMG the entire network disconnects and the sever has to be hard / power cycled.  Is this a known issue?

thanks
0
markdmacCommented:
You should not have to power cycle the server.  When you click to apply a rule it will recycle the firewall service, that should only affect Internet traffic momentarily.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft Server OS

From novice to tech pro — start learning today.