Cannot access remote network via SSTP
Environment
Windows Server running RRAS configured for SSTP w/ correct static routes to non-connected networks (i.e. a network that is not on the same subnet as my SSTP server's backend network adapter).
Issue
From a Windows Vista SP1 client, I am not able to access non-connected networks (ping, http, etc.).
THIS IS NOT AN ISSUE FROM A WINDOWS 7 CLIENT. A ping request for a remote subnet IP on the internal network appears to be sent out my client network adapter's default gateway (i.e. to the internet). Enabling "use default gw on remote
network" "fixes" the issue, but this is highly undesirable due to the fact that this will cause all internet bound traffic to traverse the vpn network and cause congestion.
Any thoughts? Again, this is working for all Windows 7 clients w/o enabling the "use default gw..." setting. Is this a Vista bug? Thanks in advance!
September 8th, 2011 11:52pm
Hi,
Thanks for posting in Microsoft TechNet forums.
Please launch CMD, type route print and Enter.
Right click on the screen, choose select All and paste
the results from both Windows Vista and 7 here.
Best Regards
Magon Liu
TechNet Subscriber Support
in forum. If you have any feedback on our support, please contact
tnmff@microsoft.com
Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
September 9th, 2011 6:37am
Here are the route prints after connecting to the SSTP VPN. For some reason, it appears that Windows 7 clients create a route to the entire 10.0.0.0/8 subnet while Vista clients create one just for the RRAS server's direct connected subnet (10.1.0.0/16).
Odd.
Windows 7
===========================================================================
Interface List
26...........................VPN Connection
15...00 24 2c e5 0d 23 ......11b/g Wireless LAN Mini PCI Express Adapter III
13...00 24 7e 16 b0 6b ......Broadcom NetLink (TM) Gigabit Ethernet
1...........................Software Loopback Interface 1
14...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
16...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
11...00 00 00 00 00 00 00 e0 Microsoft Teredo Tunneling Adapter
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.208 25
10.0.0.0 255.0.0.0 10.1.9.25 10.1.3.82 26
10.1.3.82 255.255.255.255 On-link 10.1.3.82 281
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.0.0 255.255.255.0 On-link 192.168.0.208 281
192.168.0.208 255.255.255.255 On-link 192.168.0.208 281
192.168.0.255 255.255.255.255 On-link 192.168.0.208 281
208.177.107.10 255.255.255.255 192.168.0.1 192.168.0.208 26
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.0.208 281
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.0.208 281
255.255.255.255 255.255.255.255 On-link 10.1.3.82 281
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 306 ::1/128 On-link
15 281 fe80::/64 On-link
16 286 fe80::5efe:192.168.0.208/128
On-link
15 281 fe80::601b:c12d:4794:f074/128
On-link
1 306 ff00::/8 On-link
15 281 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
Windows Vista
===========================================================================
Interface List
32 ........................... connect.pavcsk12.org
16 ...00 24 7e 16 b0 6b ...... Broadcom NetLink (TM) Gigabit Ethernet #3
11 ...00 24 2c e5 0d 23 ...... 11b/g Wireless LAN Mini PCI Express Adapter III
1 ........................... Software Loopback Interface 1
25 ...00 00 00 00 00 00 00 e0 isatap.connolly.net
33 ...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
15 ...00 00 00 00 00 00 00 e0 isatap.pavcsk12.org
13 ...00 00 00 00 00 00 00 e0 6TO4 Adapter
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.208 25
10.1.0.0 255.255.0.0 On-link 10.1.4.161 26
10.1.4.161 255.255.255.255 On-link 10.1.4.161 281
10.1.255.255 255.255.255.255 On-link 10.1.4.161 281
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.0.0 255.255.255.0 On-link 192.168.0.208 281
192.168.0.208 255.255.255.255 On-link 192.168.0.208 281
192.168.0.255 255.255.255.255 On-link 192.168.0.208 281
208.177.107.10 255.255.255.255 192.168.0.1 192.168.0.208 26
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.0.208 281
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.0.208 281
255.255.255.255 255.255.255.255 On-link 10.1.4.161 281
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 306 ::1/128 On-link
11 281 fe80::/64 On-link
25 286 fe80::5efe:192.168.0.208/128
On-link
11 281 fe80::4c4f:370d:337:b737/128
On-link
1 306 ff00::/8 On-link
11 281 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
September 9th, 2011 10:27am
Hi,
As this thread has been quiet for a while, we assume that the issue has been resolved. At this time, we will mark
it as ‘Answered’ as the previous steps should be helpful for many similar scenarios. If the issue still persists, please feel free to reply this post directly so we will be notified to follow it up. You can also choose to unmark the answer
as you wish.
BTW, we’d love to hear your feedback about the solution. By sharing your experience you can help other
community members facing similar problems. Thanks for your understanding and efforts.
Best Regards
Magon Liu
TechNet Subscriber Support
in forum. If you have any feedback on our support, please contact
tnmff@microsoft.com
Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
September 25th, 2011 10:39pm