Routing problem PPTP VPN (Win2003)
Hello, Im a system administrator at a medium sized company. Our server all running on Windows 2003. To let our employees connect to our network we let them use PPTP (via a Windows 2003 server). It is not the best and secure way but it worked for us fine for several years.
The problems began 1 month ago. All VPN users complained that they could not connect to the network. I investigated the problem and noticed a strange behavior:
Users could establish a VPN tunnel, but once connected they could not get access to the network. You could ping the (internal) IP of the server if you had a connection but no other server? So I expected a routing problem. It seems that the server doesnt route the traffic to the network.
First I tried to fix it my self but after a day of trail and error I contacted a support company with more experienced people than me. After 2 days they give up as well. The only solution we found was to reinstall (or enable) the routing and remote access on another server. So I just run the wizard, do the manual config (we have only 1 LAN connection), select VPN, changed the firewall to the new server and done. It worked again. And we didnt looked any further for the cause. We suspected that a security update was messing with the settings, so we disabled the automatic updates on the newly configured server.
BUT, today we experienced the same problem on the other server. Now to come up with a quick solution we tried to enable it on other servers (patched and unpatched servers). But without success, every time we configure it and test the server we can only connect but cannot access the rest of the network. You can only ping or even rdp to the VPN server itself.
Does anyone have experienced the same problem? And more important does anyone has a solution for me?
May 14th, 2009 9:15am
Hello WesleyVH,If you RDP into the VPN server, can pingtheother servers?Are you using RRAS on the VPN server or did youset up usingthe incoming connections setup wizard?On the VPN client, under advanced TCP/IP connections, is Use Default Gateway On Remote Network checked on or off?MiguelMiguel Fra
Falcon ITS
Miami, FL
Free Windows Admin Tool Kit Click here and download it now
May 14th, 2009 8:54pm
Hi, Current information is not enough; please help to collect the following information for research. 1. How did you configure assigning IP address to VPN clients? Static address pool or DHCP Server? If the static IP address pool consists of ranges of IP addresses that are for a separate subnet, then you need to either enable an IP routing protocol on the remote access server computer or add static IP routes consisting of the {IP Address, Mask} of each range to the routers of the intranet. If the routes are not added, then remote access clients cannot receive traffic from resources on the intranet. Please check the following article and let us know the detailed Network Topology and IP assignment. Configure the Way RRAS Assigns IP Addresses to VPN Clients http://technet.microsoft.com/en-us/library/dd469667(WS.10).aspx 2. When the issue occurs, collect the following information on both clients and server. a. Run "ipconfig /all >>c:\vpn.txt" b. Run "route print >>c:\vpn.txt" Please use Windows Live SkyDrive (http://www.skydrive.live.com/) to upload the files and then give us the download address. Thanks. This posting is provided "AS IS" with no warranties, and confers no rights.
May 15th, 2009 12:34pm


