Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > VPN: Site to Site and Remote Access

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-09-2010, 06:04 PM
Junior Member
 
Join Date: Jan 2010
Posts: 23
Default Site to Site VPN interesting issue

Hello all,

Got an interesting issue going on here.

Ok i got all the SSL, L2TP, PPTP VPN's working. I even got SSL and Ipsec site to site vpn's working too.

Now the problem at hand, is when I turn the Site to Site VPN on be it SSL or IPSEC the client remote network (client astaro) can not get to Servers that have differnt gateways.

I have an email server that is running behind an ISA 2006 firewall. Now when i connect, for example my laptop to the SSL VPN or L2TP VPN i can access the email server and all resources just fine.

Now when i connect to the remote sites network with the site to site to vpn. I can't get to any of my servers that are on a differnt gateway than the astaro box.

My local firewall servers are ISA 2006, IP is 192.168.1.1 and Astaro, IP is 192.168.1.2 and my remote firewall astaro is 172.20.20.1

The tunnel connects and works just fine. I can ping both ends if the computers are on the same gateway. But if the server is on my gateway that ISA 2006 handles. I can't access that server/computer from my remote astaro network.


Also the only other issue i am having is i can't seem to resolve names to IP's in Windows.

Any help would be greatful

thnx

And ISA is not an option to remove.

Last edited by ripzeus; 02-09-2010 at 06:07 PM.
Reply With Quote
  #2 (permalink)  
Old 02-09-2010, 10:48 PM
Junior Member
 
Join Date: Jan 2010
Posts: 23
Default

I figured it out.


If you want the answer. PM me.
Reply With Quote
  #3 (permalink)  
Old 02-10-2010, 06:38 AM
Whity's Avatar
Senior Member
 
Join Date: May 2001
Location: Switzerland
Posts: 341
Default

Please post the answer here.

There is nothing i hate more than asking a question in a forum and then not providing the answer after you could solve it.
__________________
Astaro Certified Engineer - Authorized Partner - Using Astaro since 2001

Managed boxes:
1 x ASG 425 Cluster with 2 nodes
2 x ASG 320
1 x ASG 220
10 x ASG 110/120
1 x Home User
Reply With Quote
  #4 (permalink)  
Old 02-10-2010, 02:25 PM
Junior Member
 
Join Date: Jan 2010
Posts: 23
Default

Quote:
Originally Posted by Whity View Post
Please post the answer here.

There is nothing i hate more than asking a question in a forum and then not providing the answer after you could solve it.
While I agree with you, the one thing I hate the most is that people can't find the time to post a question or a possible solution.

I will post the fix when I get home tonight.
Reply With Quote
  #5 (permalink)  
Old 02-10-2010, 09:16 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 7,014
Default

Thanks in advance, Ripzeus. Sometimes, the turn-around here is hours, and sometimes it's days. If Whity or I had seen this before you found the answer, we would have had the answer for you.

To get some tips about name resolution, google: site:astaro.org dns best practice

Welcome to Astaro!

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #6 (permalink)  
Old 02-11-2010, 02:03 PM
Junior Member
 
Join Date: Jan 2010
Posts: 23
Default

Quote:
Originally Posted by BAlfson View Post
Thanks in advance, Ripzeus. Sometimes, the turn-around here is hours, and sometimes it's days. If Whity or I had seen this before you found the answer, we would have had the answer for you.

To get some tips about name resolution, google: site:astaro.org dns best practice

Welcome to Astaro!

Cheers - Bob
I am going to have to look tonight at what i did. Sorry i didn't get a chance to post what i did to resolve the issue i had. Been busy here at work.

I will try and post the fix tonight when i get home. Yey for 12 hour shifts \o/
Reply With Quote
  #7 (permalink)  
Old 02-16-2010, 03:22 PM
Junior Member
 
Join Date: Jan 2010
Posts: 23
Default

Simple little fix.

Just add the remote network to the Allowed Networks under DNS, and in the Fowarders TAB add in your DNS servers from the internal network


I'm kinda kicking myself on how easy this is
Reply With Quote
  #8 (permalink)  
Old 02-17-2010, 04:24 PM
Junior Member
 
Join Date: Mar 2009
Posts: 7
Default

We have occasional issues with DNS resolution for our VPN users. The VPN user enters an internal domain name and it won't resolve.

I added our VPN network to the "Allowed Networks". Thanks for the tip!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 07:37 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.