Site-Site Router-Router VPN

Site-Site Router-Router VPN

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Site-Site Router-Router VPN Loopy via WinServerKB.com 09-01-2008
Posted by Loopy via WinServerKB.com on September 1, 2008, 9:21 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


I'm trying to set up a site-2-site vpn. Two SBS-2003-SP2 servers. Each is a
DC for its local LAN. Each has 2 NIC. One on the LAN and one on the WAN.
Each server gets to the internet via a D-Link DFL-210 router/firewall.

[LAN] -- [LAN NIC---SBS server---WAN NIC] -- [DFL-210] -- [Internet]

I can establish an IPSec tunnel between the routers and ping to the router
[DFL-210] at each end, but can't ping the server's WAN NIC. VPN *is* checked
in the "Configure Firewall" settings of the SBS-2003.

If I disable the SBS-2003 internal firewall, then I *can* ping to the WAN NIC,
but still can't ping through to the LAN NIC at each end?

Thanks.

Loopy

--
Message posted via WinServerKB.com
http://www.winserverkb.com/Uwe/Forums.aspx/windows-security/200809/1


Posted by =?Utf-8?B?QW50ZWF1cw==?= on September 9, 2008, 3:47 am
If you were  Registered and logged in, you could reply and use other advanced thread options



From what I've read of its spec, the DFL-210 includes a VPN server rather
than the VPN gateway typically found on budget routers. It sounds like you
are trying to use it as a gateway. A gateway forwards requests to a VPN
server on your LAN, but that is all, it has no 'intelligence' in itself. The
VPN server OTOH should need no other support, if configured correctly it
should link the two networks at Ethernet level without any intervention from
the SBS server. It may be a requirement that the two networks use different
IP ranges, this is often the case.

Bear in mind I've not used this model, just judging from its spec, which
indicates it to be a full VPN appliance rather than a gateway.

"Loopy via WinServerKB.com" wrote:

> I'm trying to set up a site-2-site vpn. Two SBS-2003-SP2 servers. Each is a
> DC for its local LAN. Each has 2 NIC. One on the LAN and one on the WAN.
> Each server gets to the internet via a D-Link DFL-210 router/firewall.
>
> [LAN] -- [LAN NIC---SBS server---WAN NIC] -- [DFL-210] -- [Internet]
>
> I can establish an IPSec tunnel between the routers and ping to the router
> [DFL-210] at each end, but can't ping the server's WAN NIC. VPN *is* checked
> in the "Configure Firewall" settings of the SBS-2003.
>
> If I disable the SBS-2003 internal firewall, then I *can* ping to the WAN NIC,
> but still can't ping through to the LAN NIC at each end?
>
> Thanks.
>
> Loopy
>
> --
> Message posted via WinServerKB.com
> http://www.winserverkb.com/Uwe/Forums.aspx/windows-security/200809/1
>
>


The site map in XML format XML site map

Contact Us | Privacy Policy