Can't communicate with RRAS VPN clients


hello,

i stumped issue i'm having in rras.  i've setup successful vpn server using l2tp.  network setup contains few different subnets:

172.16.2.0/24 - servers
172.16.3.0/24 - wired clients
172.16.4.0/24 - wireless clients

i have setup rras use static pool of 172.16.5.150 - 172.16.5.159.  ip address of rras server 172.16.2.85.  internal address of rras 172.16.5.150.  problem is, lan clients cannot communicate internal address of rras, or vpn clients.  example, if vpn client connects, , given 172.16.5.153 address, absolutely no lan clients (servers, wired, wireless,e tc) ping 172.16.5.150 or 172.16.5.153.  times out.  have ipv4 routing enabled.  also, in registry have ipenablerouter set 1.  have checked everything.  in main cisco router, have added:

ip route 172.16.5.0 255.255.255.0 172.16.2.85

i have played firewall settings on both clients , rras server.  don't know else can do.  i've searched forum after forum, , @ dead end.  basically....if vpn client obtains ip address, want able communicate it, if need remote example.

i appreciate assistance!

  if of lan subnets use cisco default gateway (which assume do), adding static route (as have done) to cisco should get traffic remotes rras router deliver them remotes. getting return traffic lan may not have  covered. default gateway of rras server? cisco? if not need static routes on rras router lan subnets cisco. there 2 steps involved - getting traffic remote client rras server, getting rras server cisco.

  if add static routes clients route lan subnets through vpn tunnel, need use ip address of rras internal interface, not lan ip target address. see kb 254231. 

    need rras router configured lan routing, not nat.

bill



Windows Server  >  Network Infrastructure Servers



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file