VPN connection to SBS 2003 network

Zucarita9000

Golden Member
Aug 24, 2001
1,590
0
0
I want to enable VPN access for our mobile users, so they can access local shares and resources while on the road.
For that, I’ve followed the steps in the Small Business Server admin guide, but I still have some problems. The configuration is as follows:

Server is Windows Small Business Server 2003. This is the Domain Controller, DHCP server, DNS server and Certificate Authority.
Server names is Serverhp, domain is EKAYMM

Problems:
1. The connection doesn’t take place. I get a timeout.
2. Don’t know how to configure VPN in OSX (10.6). I’ve already installed the User certificate, but don’t know how to request a computer certificate.

I have completed these steps:

Installed and configured IAS. Disabled MS-CHAP and enabled Strongest Encryption (128 bit)
Installed and configured Certificate Services. Enterprise root CA (EK roboter Certificate Authority)
Created a Local Computer and Current User Certificate Console (using the Certificates Snap-Ins)
Requested a Certificate for the Windows Small Business Server computer. Certificate Type: Domain Controller
Configured the Remote Access Policy to use EAP authentication.
Open ports TCP 1723 (PPTP), UDP 500 (IPSec) and UDP 1701 (L2TP), forwarding them to the server’s IP.

On the client side, I used the Certificate Console to request User and Computer certificates, which both install correctly.
The VPN connection is configured as follows:

http://emberapp.com/guille779/images/client/sizes/l.png

Here are some other screenshots from the server configuration, which might be useful:
http://emberapp.com/guille779/images/server-ek-dominio-6/sizes/l.png
http://emberapp.com/guille779/images/server-ek-dominio-5/sizes/l.png
http://emberapp.com/guille779/images/server-ek-dominio-4/sizes/l.png
http://emberapp.com/guille779/images/server-ek-dominio-3/sizes/l.png
http://emberapp.com/guille779/images/server-ek-dominio-2/sizes/l.png
http://emberapp.com/guille779/images/server-ek-dominio-1/sizes/lpng
http://emberapp.com/guille779/images/server-ek-dominio/sizes/l.png

OS X VPN configuration:
http://emberapp.com/guille779/images/user/sizes/l.png
http://emberapp.com/guille779/images/choose-an-identity/sizes/l.png
http://emberapp.com/guille779/images/computer/sizes/l.png


UPDATE: I can connect using PPTP from both Windows and OS X. L2TP still gives me problems.

UPDATE 2: L2TP works from inside the LAN, so I think it's a firewall issue. Are there any ports besides those I already forwarded that need to be enabled?
 
Last edited:

RebateMonger

Elite Member
Dec 24, 2005
11,588
0
0
Believe it or not, setting up a Windows Server 2003 VPN is really simple. Following the instructions should work fine. That's not to say that making a working VPN is always easy. Thre are definitely things that can turn it into a frustrating experience.

One thing you need to decide is what type of VPN you are creating. PPTP? L2TP? There are differences in the TCP Ports and protocols that must be forwarded through any front-end router/firewall.

If you follow MS' instructions and it won't work, the problem may be a router or firewall problem. To see if that's the problem, hook up a client PC directly in front of the SBS server, inside your network. See if the VPN works. If it works internally, but not from the Internet, then the problem is the router. If it still doesn't work, take a look at any other firewalls that are running.
 

Zucarita9000

Golden Member
Aug 24, 2001
1,590
0
0
Believe it or not, setting up a Windows Server 2003 VPN is really simple. Following the instructions should work fine. That's not to say that making a working VPN is always easy. Thre are definitely things that can turn it into a frustrating experience.

One thing you need to decide is what type of VPN you are creating. PPTP? L2TP? There are differences in the TCP Ports and protocols that must be forwarded through any front-end router/firewall.

If you follow MS' instructions and it won't work, the problem may be a router or firewall problem. To see if that's the problem, hook up a client PC directly in front of the SBS server, inside your network. See if the VPN works. If it works internally, but not from the Internet, then the problem is the router. If it still doesn't work, take a look at any other firewalls that are running.

I was able to connect via PPTP from home without problems. I'll give L2TP a second try today and see what happens. I used PPTP with EAP, User Certificates and 128-encryption. Mac and Windows PCs both connected to the network ok.

However, in the Windows PC Network Places is empty. Shouldn't it be populated by the servers and PCs in the LAN as if I'd be locally in the network? I don't see any computers in Network Places, but if I do a \\computername\share I can open it without problems.

I get an IP from the server, DNS is running... but I only see myself. Any ideas?
 

Emulex

Diamond Member
Jan 28, 2001
9,759
1
71
protocol forwarding? my router has two options for allowing vpn passthrough. i'm just going to run a vm to do vpn/firewall
 

RebateMonger

Elite Member
Dec 24, 2005
11,588
0
0
What's the client OS? Is the client joined to a Domain?

Do you have a WINS server available? I've seen WINS give name resolution across a VPN with a Vista client when DNS name resolution would fail because Vista won't remember appended DNS suffixes (XP works fine).
 

Zucarita9000

Golden Member
Aug 24, 2001
1,590
0
0
What's the client OS? Is the client joined to a Domain?

Do you have a WINS server available? I've seen WINS give name resolution across a VPN with a Vista client when DNS name resolution would fail because Vista won't remember appended DNS suffixes (XP works fine).

Windows XP. Haven't tried with Vista yet.
WINS is not configured.

It is installed, however when I try to enable it it gives an error with the code 536870911. The services won't start :S
 
Last edited:

Zucarita9000

Golden Member
Aug 24, 2001
1,590
0
0
UPDATE: I fixed WINS (reinstalled) and it's now working.
I haven't tried the VPN since I'm inside the LAN now, will try it later today.

I noticed that some Windows Vista machines still don't show up in Network Places. Is there something that I need to configure in Vista?
 

Zucarita9000

Golden Member
Aug 24, 2001
1,590
0
0
Well, apparently there's something that eludes me. I got DHCP, DNS, WINS an RRAS configured, yet still VPN client can't see the computer list in Network Places. I don't know what else to do, I've tried pretty much everything I could find. Any ideas? If you some screenshots of my configurations and options I'll be glad to post them.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |