Anywhere access through multiple routers
Hi there,
I set up a new Windows Server 2012 essentials rig at home for a client, and configured Anywhere access OK (manually port forwarding 80 & 443 as when I used the auto UPnP on my home router it hosed the configuration and I couldn't log into it again).
I used CACert for certification. Now this all worked OK.
I relocated the server to the clients office, and updated the DNS record to suit, and it gets through to IIS but comes up with a '500 - internal server error'. So I go to check the dashboard, and get both the 'More than one router' and 'access is blocked'
warnings.
Network topology:
External IP 80.xx.xx.xx
This is routed on a VLAN to a local IP 10.9.109.253 with all ports open
I have set up the draytek vigor 2920n with WAN IP of 10.9.109.253, and local IP of 192.168.1.1 and forwarded only ports 80 & 443 to the servers static IP.
Checking with various port tools online I can confirm that 80 & 443 are open and it returns the IP address of 80.xx.xx.xx (if I disable port forwarding I get blocked ports as expected)..
But if I try to re-run the Anywhere Access configuration it fails. As a test I enabled UPnP on the Draytek and tried to 'auto configure the router' and it seemed to detect the router OK (and the local IP 10.0.109.253) however still Anywhere Access configuration
failed...
I went back to the port forwarding route as this is what I was more comfortable with. As a test I enabled bridge mode on the Draytek, but this didn't seem to make any difference. So I am out of ideas now...
Any help would be much appreciated.
May 20th, 2013 7:08am
Hi,
It will be helpful if you try draw your network topology as a graphic to help us understand your situation:)
Free Windows Admin Tool Kit Click here and download it now
May 20th, 2013 11:38am
Hi,
It will be helpful if you try draw your network topology as a graphic to help us understand your situation:)
May 20th, 2013 11:38am
OK I am back home now, and as a test tried to connect via VPN.... and it works! So I know there is no routing issue. But still I cannot get the Anywhere Access wizard to complete...
I feel I am a step closer, but still confused...
Free Windows Admin Tool Kit Click here and download it now
May 20th, 2013 11:39am
Then you mean Remote Web Access does not work?
May 20th, 2013 11:54am
The 'Anywhere Access' wizard will not complete, so in theory both VPN and Remote Web Access should not work. However, VPN is working, but Remote Web Access is not....
Not sure if a diagram of the topology will help (any more than I have explained...)
external IP (static IP 80.xxx.xxx.xxx)
|
office VLAN IP (static IP 10.9.109.253 ALL ports open)
|
Draytek router 2920n (WAN static IP 10.9.109.253 / LAN static IP 192.168.1.1 / ports 80 & 443 forwarded to 192.168.1.50)
|
Server (LAN static IP 192.168.1.50)
The reason there is a Draytek in-between is because on the VLAN segment we have been supplied there is no hardware (or software) firewall in place.
Free Windows Admin Tool Kit Click here and download it now
May 20th, 2013 12:23pm
Is this a certificate issue as the server is now on a different external IP? I assumed updating the A record in the ISP DNS record was enough..?
May 20th, 2013 2:21pm


