[isalist] Vpn routing problem (URGENT)

  • From: "Daniel" <daniel@xxxxxxxxxxxxxxxx>
  • To: "ISAServerList" <isalist@xxxxxxxxxxxxx>
  • Date: Wed, 28 Jun 2006 10:53:11 -0300

I have a vpn gateway to gateway between a ISA server/w2k (headquarter) and a 
RRAS/w2k (branch1), my rouing
don't work. It's a very basic routing plan. I have five cases with the same 


---headquarter (ISA server/w2k)
internal-iface= mask=/24, external-iface=x.x.x.x (public ip)
. demand dial vpn iface= "dd-to-remote1", persistent, destination= (y.y.y.y see 
below), fix-ip=
  (flag initiate connection when traffic accross ENABLED)
. static route trough iface "dd-to-remote1"
. headquarter LAN default gateway is the ISA (

---remote-site-1 (MS RRAS/w2k)
internal iface: mask=/24, external-iface=y.y.y.y (public ip 
referenced above)
. demand dial iface="dd-headquarter", persistent, destination=BLANK (should no 
initiate connections)
. static route trough iface "dd-headquarter"
  (flag initiate connection when traffic accross DISABLED)
. default LAN gateway is a cisco router (
. on the cisco I have this route: destination= mask=24 
gateway= (the RRAS

I have no filters, but routing don't work.
On ISA and on the RRAS console I can ping the other end subnet (is cause they 
have logical interfaces in each
end), but from LAN machines I can not.

Tracing from a "headquarter" LAN machine( to a remote-site-1 LAN 
machine (
c:>tracert -d  (ISA int iface)  (dd-to-remote1 iface)
* * *
* * *
* * *

Tracing from a "remote-site-1" LAN machine( to a "headquarter" LAN 
machine (
c:>tracert -d   (default LAN gateway cisco router)
* * *
20.x.x.x      (than try cisco default gateway the internet)
* * *
* * *
* * *
Seems the RRAS is rejecting packets from cisco router.

Follow the last example, tracing from to, but puting 
a local route entry on,
the same route that the cisco default gateway has, than it work fine.
c:> route add mask
c:>tracert -d  (RRAS LAN iface)  (dd-headquarter iface) (headquartee LAN machine)
trace completed!

I have five gw-to-gw vpns on my headquarter ISA server, all the remote VPN 
sites have the same problem. In
remote sites the LAN default gateway is another router (cisco, linux, ...) not 
the remote RRAS server, but put
a route to the headquarter subnet trough the RRAS don't work. I know that it's 
very basic in TCP/IP, but In
need to put route entries on the some LAN machines to work!

Anyone can see a mistake in my routing plan?

Daniel Müller
Microsoft Certified Systems Engineer [MCSE + Security]
Linux Professional Institute Certified Level 2 [LPIC-2]
Master in Computer Science (network security area)
Softplan Sistems
Florianópolis, Brazil

List Archives: http://www.freelists.org/archives/isalist/  
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp 
ISA Server Articles and Tutorials: http://www.isaserver.org/articles_tutorials/ 
ISA Server Blogs: http://blogs.isaserver.org/ 
Visit TechGenix.com for more information about our other sites:
To unsubscribe visit http://www.isaserver.org/pages/isalist.asp 
Report abuse to listadmin@xxxxxxxxxxxxx 

Other related posts: