RV042 behind Forefront TMG 2010

Currently i am having a scenario where i have setup RV042 and  which is connected to Microsoft Forefront 2010. PPTP works fine through remote site only on  rv042 subnet but i am not able to access the "internal" network of TMG.

 

RV042 (172.16.1.1) ---> TMG [external] (172.16.1.2) ---> TMG [internal] (192.168.1.1)

 

Is there any way through static route to access the TMG internal network through RV042 pptp server ?
LVL 12
ibrahim52Team LeaderAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Fred MarshallPrincipalCommented:
Well, let's see:
packets come out of the tunnel destined for the 176.16.1.0 /24 subnet.
That's how things work.
So, there's no way to traverse the TMG, or any other device, because there's no place for a follow-on destination subnet address.
I've tried this with an RV042 where the next hop on the subnet was another VPN device going to a 3rd site.  The problem is that there's no way to have the next remote subnet in the destination.  Only the VPN device can be a destination.

In this case maybe you could use port addressing.
That is, destination would be 172.16.1.2:222
And, port 222 would be translated in the TMG to go to a specific IP address and perhaps port like 192.168.1.1:80.  I've not tried doing this.
0
ibrahim52Team LeaderAuthor Commented:
But when i searched internet most of the results says that STATIC ROUTING could work but unfortunately no one has tried plus i dont have multiple boxes to give it a try by creating an IPSEC tunnel.Where i could add two remote subnets (172 & 192) but still ill wait for some more experts comments over here and meanwhile give it a try with static routing.
0
ibrahim52Team LeaderAuthor Commented:
Well after expecting experts views from so long, i took help from one of my senior where i had to make changes in NETWORK RULES of TMG by creating Internal to External & External to Internal rules for 5 PPTP ip addresses and it started working. This is how it helped.

Common troubleshooting steps :

1.  Check the IP address of TMG if it is pinging through RV042 firmware.
2.  If not pinging than create a policy to allow PING into internal network.
3.  Do the STATIC ROUTING in RV042 by keeping the IP address as TMG internal ip & gateway as TMG wan static ip.
4. Ping to confirm if you are having access through the router to TMG using PING utility of RV042.
5. Once you are able to PING than , enable PPTP and connect from the remote side and PING the WAN static ip of TMG and any of the INTERNAL ip of TMG network.
6. If you are not able to ping TMG internal network by just STATIC ROUTING from RV042
7. Than you need to create two rules under NETWORK RULES of FOREFRONT (check this option in FOREFRONT management window) , first you need to create a range of PPTP ip addresses in SUBNET category of TMG and use these range of ip addresses in the rules we are going to create.
8. Create SOURCE (PPTP IP ADDRESS RANGE) to INTERNAL and INTERNAL to (PPTP IP ADDRESS RANGE)
9. That's it , i am sure you will be able to ping it from the remote and so does access the resources of TMG network.

Please if any one have any doubts, post it here. Ill be really glad to help. Thank you.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
ibrahim52Team LeaderAuthor Commented:
After waiting for experts to put their views from so long. Thankfully, it got solved and i am sharing the same for other people who are facing a similar issue like i did.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
VPN

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.