Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > VPN: Site to Site and Remote Access

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-30-2010, 03:55 PM
Junior Member
 
Join Date: Jan 2010
Posts: 2
Unhappy VPN RDP not working any more after upgrading to 7.502

Dear Forum users,

i upgraded my ASP 110 to Firmware 7.502 and since then, RDP for VPN users ist not working any more for Server 192.168.0.11.

After dial into the Astaro, a VPN user can only reach the astaro (192.168.0.1) and the DHCP server (192.168.0.10), but no other ip is reachable for the VPN users. Also, no ping for other ips is possible (printers etc)

Packet filters are set to enable ping and terminal serivces, the log says for RDPing 192.168.0.11:

Packet filter rule #3 TCP
192.168.0.40 (VPN user):61982→192.168.0.11(RDP server): 3389 [SYN] len=52 ttl=127 tos=0x00 srcmac=-------- dstmac=----

Furthermore, i am able to ping the VPN Client 192.168.0.40 from 192.168.0.10, but not from .0.11.

Does anyone have a clue about this?
Reply With Quote
  #2 (permalink)  
Old 01-31-2010, 02:52 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,391
Default

Your VPN subnet shouldn't overlap with any other net; in particular, it shouldn't overlap with 'Internal (Network)'. Prior to V7.5, a bug allowed this setup to work. Before the upgrade, you could have confirmed the problem by trying to VPN in simultaneously with two different devices under the same username - both would have been assigned the same IP by your DHCP.

The solution is to use the appropriate VPN Pool instead of the DHCP service for the devices in your 'Internal (Network)'. You likely will need to configure the 'Advanced' tab. Probably also add 'VPN Pool (PPTP/L2TP)' to 'Allowed networks' for DNS, NTP, HTTP/S and FTP Proxies. And IM/P2P. Probably add packet filter rules.

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #3 (permalink)  
Old 02-01-2010, 12:31 PM
Junior Member
 
Join Date: Jan 2010
Posts: 2
Default

Thanks for your answer!

I found out what the problem was: a missing NAT-rule for VPN-Users -> Internal Network.

Somehow this rule, if it existed before upgrading to 7.502, must have been deleted or it worked before without it. Dont know why, but now it works.
Reply With Quote
  #4 (permalink)  
Old 02-01-2010, 12:52 PM
Whity's Avatar
Senior Member
 
Join Date: May 2001
Location: Switzerland
Posts: 227
Default

Never had to create NAT rule for the VPN network myself.

That anyway has not to be NAT'ed because both nets are attached to the same Firewall (The VPN net and the internal net)
__________________
Astaro Certified Engineer - Authorized Partner - Using Astaro since 2001

Managed boxes:
1 x ASG 425 Cluster with 2 nodes
2 x ASG 320
1 x ASG 220
10 x ASG 110/120
1 x Home User
Reply With Quote
  #5 (permalink)  
Old 02-01-2010, 03:15 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,391
Default

Raimund, Apparently, you have only a very few users (ASG110), so you probably can get away with this workaround to the problem I tried to explain in my post above.

In your situation, the only downside would be that all traffic through the VPN to devices in 'Internal (Network)' will appear to originate from 'Internal (Address)' instead of from the IP assigned by your DHCP.

I wouldn't recommend this solution to anyone with a larger installation.

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #6 (permalink)  
Old 02-08-2010, 11:38 AM
Member
 
Join Date: Aug 2009
Location: Heerhugowaard,Netherlands
Posts: 50
Default

Raymund,
When you check your Internal Network devices , is their default-gateway pointing to the ASG or to a different gateway.
If the default-gateway is not pointing to the ASG, perhaps a solution is to make a static route for your VPN pool pointing to the LAN address of your ASG.

regards
__________________
Astaro V7.5 ,Home Edition
Reply With Quote
Reply

Tags
7.502, rdp, vpn

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 11:47 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.