Solved

SBS 2011 VPN issue

Posted on 2014-01-14
16
551 Views
Last Modified: 2014-01-20
Hello,

 I have a SBS 2011 server, on which I configured the VPN via the console.  When I try to connect to the server, I receive the error - see the attached file. I forwarded 1723 port to the SBS, and no luck. The user is in VPN group.

Any ideas how to troubleshoot that?

The SBS is behind a Vingor 2920, to which I have connected a BT Hub.
0
Comment
Question by:goliveuk
  • 8
  • 7
16 Comments
 
LVL 22

Expert Comment

by:David Atkin
ID: 39779196
Hello,

Have you forwarded the ports on both the Draytek and the BT Hub?

Make sure that the Draytek VPN Settings are disabled.  This has caused me issues previously.
0
 

Author Comment

by:goliveuk
ID: 39779246
I forwarded 1723 from the BTHub to the Draytek, and from the Draytek to the SBS. canyouseeme.org show 1723 as opened :)
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 39779258
Did you check that the Draytek VPN Settings where disabled in:

VPN and Remote Access> Remote Access Control.

All the options want to be unticked.
0
 

Author Comment

by:goliveuk
ID: 39779283
All of them unticked.
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 39779298
Can you upload the file attachment?  It didn't upload originally
0
 

Author Comment

by:goliveuk
ID: 39779308
Uuups, Here it is :)
sbs-vpn.png
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 39779366
I've done a port test on 1723 to the location in your screenshot.  It shows it as closed.

Can you create the VPN to the IP Address instead of the name?
0
 

Author Comment

by:goliveuk
ID: 39779383
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 22

Expert Comment

by:David Atkin
ID: 39779393
Your remote.oppco.co.uk record is currently pointing to:
86.182.224.134

Can you try creating the VPN connection using the IP address rather than the name.
0
 

Author Comment

by:goliveuk
ID: 39779406
Yep, I tried directly to the IP, and it is the same.

P.S. I will fix the record later.
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 39779418
No problem, just making sure we are on the same page (Y).

Can you log in using the Administrator credentials?

If possible, can you post a screen shot of the port rules in the BT Hub and Draytek - Sorry to be a pain!
0
 

Author Comment

by:goliveuk
ID: 39779449
Here both of them
Draytek.png
BTHub.png
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 39779502
Does your OWA port mapping work?

Any particular reason why you're using the BT Router still and not the DrayTek direct?

Do you get any errors in the event logs relating the VPN Connection or does nothing show?
0
 

Author Comment

by:goliveuk
ID: 39779558
OWA works like a charm.

Here is what I got just now:

A connection between the VPN server and the VPN client <ip adress> has been established, but the VPN connection cannot be completed. The most common cause for this is that a firewall or router between the VPN server and the VPN client is not configured to allow Generic Routing Encapsulation (GRE) packets (protocol 47).
0
 
LVL 22

Accepted Solution

by:
David Atkin earned 500 total points
ID: 39779648
I would probably pin this on the BT Router (Or at least start trouble shooting from there).

From researching it looks like others have also had issues with VPN's on the BT Routers.  

Any reason why you are using the BT Router and not direct to the Draytek?

The Draytek should auto forward the VPN Protocol (GRE 47) when doing a port mapping looking at this:
http://www.draytek.co.uk/archive/kb_vigor_passthrough.html
0
 
LVL 22

Expert Comment

by:Olaf De Ceuster
ID: 39780448
You need to allow GRE on the router.
(Or PPTP pass through as it is sometimes called).
Check your routers documentation.
Hope that helps,
Olaf
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now