Solved

SBS 2011 VPN issue

Posted on 2014-01-14
16
558 Views
Last Modified: 2014-01-20
Hello,

 I have a SBS 2011 server, on which I configured the VPN via the console.  When I try to connect to the server, I receive the error - see the attached file. I forwarded 1723 port to the SBS, and no luck. The user is in VPN group.

Any ideas how to troubleshoot that?

The SBS is behind a Vingor 2920, to which I have connected a BT Hub.
0
Comment
Question by:goliveuk
  • 8
  • 7
16 Comments
 
LVL 22

Expert Comment

by:David Atkin
ID: 39779196
Hello,

Have you forwarded the ports on both the Draytek and the BT Hub?

Make sure that the Draytek VPN Settings are disabled.  This has caused me issues previously.
0
 

Author Comment

by:goliveuk
ID: 39779246
I forwarded 1723 from the BTHub to the Draytek, and from the Draytek to the SBS. canyouseeme.org show 1723 as opened :)
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 39779258
Did you check that the Draytek VPN Settings where disabled in:

VPN and Remote Access> Remote Access Control.

All the options want to be unticked.
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 

Author Comment

by:goliveuk
ID: 39779283
All of them unticked.
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 39779298
Can you upload the file attachment?  It didn't upload originally
0
 

Author Comment

by:goliveuk
ID: 39779308
Uuups, Here it is :)
sbs-vpn.png
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 39779366
I've done a port test on 1723 to the location in your screenshot.  It shows it as closed.

Can you create the VPN to the IP Address instead of the name?
0
 

Author Comment

by:goliveuk
ID: 39779383
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 39779393
Your remote.oppco.co.uk record is currently pointing to:
86.182.224.134

Can you try creating the VPN connection using the IP address rather than the name.
0
 

Author Comment

by:goliveuk
ID: 39779406
Yep, I tried directly to the IP, and it is the same.

P.S. I will fix the record later.
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 39779418
No problem, just making sure we are on the same page (Y).

Can you log in using the Administrator credentials?

If possible, can you post a screen shot of the port rules in the BT Hub and Draytek - Sorry to be a pain!
0
 

Author Comment

by:goliveuk
ID: 39779449
Here both of them
Draytek.png
BTHub.png
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 39779502
Does your OWA port mapping work?

Any particular reason why you're using the BT Router still and not the DrayTek direct?

Do you get any errors in the event logs relating the VPN Connection or does nothing show?
0
 

Author Comment

by:goliveuk
ID: 39779558
OWA works like a charm.

Here is what I got just now:

A connection between the VPN server and the VPN client <ip adress> has been established, but the VPN connection cannot be completed. The most common cause for this is that a firewall or router between the VPN server and the VPN client is not configured to allow Generic Routing Encapsulation (GRE) packets (protocol 47).
0
 
LVL 22

Accepted Solution

by:
David Atkin earned 500 total points
ID: 39779648
I would probably pin this on the BT Router (Or at least start trouble shooting from there).

From researching it looks like others have also had issues with VPN's on the BT Routers.  

Any reason why you are using the BT Router and not direct to the Draytek?

The Draytek should auto forward the VPN Protocol (GRE 47) when doing a port mapping looking at this:
http://www.draytek.co.uk/archive/kb_vigor_passthrough.html
0
 
LVL 22

Expert Comment

by:Olaf De Ceuster
ID: 39780448
You need to allow GRE on the router.
(Or PPTP pass through as it is sometimes called).
Check your routers documentation.
Hope that helps,
Olaf
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
Resolve DNS query failed errors for Exchange
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question