Windows 2016 server L2TP/IPsec VPN - two subnets

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Fireballcz
    Member
    • Oct 2016
    • 26
    • Czech Republic

    #1

    Windows 2016 server L2TP/IPsec VPN - two subnets

    Hello, please how to properly configure VPN in this environment?
    I have two subnets in two different (geographical) workplaces, connected via IPsec (thru gateway routers)
    Main subnet: 192.168.11.0/24, gateway (router IP) 192.168.11.1, Windows 2016 server (VPN, DHCP, DC etc.) 192.168.11.3
    2nd subnet : 192.168.22.0/24, gateway (router IP) 192.168.22.1 - just client computers.

    I need to allow external (home office) users connect via VPN server (192.168.11.3) to the 2nd subnet (192.168.22.0/24) to their computers (via RDP).
    I have no problems with VPN connection to the main subnet computers, but I am not able to properly configure acces to the 2nd subnet.
    I am not able to ping them.

    VPN server does not use DHCP, it has reserved addresses, which are removed from DHCP.
    I think, that this is a problem of RRAS routing configuration.

    I tried to configure RRAS routing, I was able to ping computers in the 2nd subnet and also create RDP connection.
    But there was a bad result:
    After a few days I was not able login remotely to the DC server (192.168.11.3) via Teamviewer and also home office VPN stopped to work.
    Work inside both connected subnets looked normal without problems, but I was unable to manage the DC.
    The only solution was hard reset the DC server, everything then start to work normally, but after a few days abowe mentioned problem returned...

    Any ideas?
    Thanks in advance
  • Fireballcz
    Member
    • Oct 2016
    • 26
    • Czech Republic

    #2
    Re: Windows 2016 server L2TP/IPsec VPN - two subnets

    I found the solution.
    Never run VPN at the DC (messes up the DC entries) or TS server (not recommended, but feasible). Thats all.
    Always choose another box.

    Comment

    • Per Hansson
      Super Moderator
      • Jul 2005
      • 5895
      • Sweden

      #3
      Re: Windows 2016 server L2TP/IPsec VPN - two subnets

      Thanks for coming back, just out of curiosity did you figure out exactly why it happens?
      It does on my workstation laptop, occasionally it will get a wrong IPv6 DNS server entry.
      But I'm not sure where it comes from: 2A00:77C0:FFFF:FFFF
      "The one who says it cannot be done should never interrupt the one who is doing it."

      Comment

      • Fireballcz
        Member
        • Oct 2016
        • 26
        • Czech Republic

        #4
        Re: Windows 2016 server L2TP/IPsec VPN - two subnets

        Originally posted by Per Hansson
        Thanks for coming back, just out of curiosity did you figure out exactly why it happens?
        It does on my workstation laptop, occasionally it will get a wrong IPv6 DNS server entry.
        But I'm not sure where it comes from: 2A00:77C0:FFFF:FFFF
        I have just one recommendation.
        If not necessary, avoid using IP v6.
        Are you running RRAS (VPN) on DC? If so, sorry, there is NO solution.
        I asked many networking specialists, all of them said the same: separate box for RRAS is the only option.
        Im currently running RRAS (about 10 days) at a box with SQL server/terminal server (serves RD apps to the 2nd subnet) and all is running like a charm.
        Also routing to the 2nd subnet is working OK (static routes).
        But:
        Maybe, setting DNS IP manually to the VPN connection (client computer) will help, also set metric to 1 and do not use split tunneling (security reasons).
        Last edited by Fireballcz; 08-08-2022, 02:13 PM.

        Comment

        Related Topics

        Collapse

        • omega
          Troubleshooting of redundant F750E-S0 Dell PowerEdge Server
          by omega
          Hello all,
          as a beginner electronics hobbyist, after a few years I would like to place another post on this Forum section, given that I did not succeed in finding any useful advice among the other posts.

          Over the last years, I have been using a PowerEdge Dell Server with two redundant PSUs, namely the 750W F750E-S0 ones (aka 06W2PW). Unfortunately, last summer one of them failed (perhaps owing to an overheating), and the server had for working to take into account the other one only. Of course I opened and tried to troubleshoot the failed PSU, but each cap I tested seemed to...
          02-09-2024, 03:34 PM
        • Document Archive
          LENOVO S510 + Office 2016 Home & Business i5-6400 Specification for Upgrade or Repair
          by Document Archive
          This specification for the LENOVO S510 + Office 2016 Home & Business can be useful for upgrading or repairing a desktop PC that is not working. As a community we are working through our specifications to add valuable data like the S510 + Office 2016 Home & Business boardview and S510 + Office 2016 Home & Business schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum. Please note that we...
          09-12-2024, 01:58 PM
        • Document Archive
          HP ZBook 15v G5 Mobile server 15v Specification for Upgrade or Repair
          by Document Archive
          This specification for the HP ZBook 15v G5 Mobile server can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the 15v G5 boardview and 15v G5 schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum. Please note that we offer no warranties that any specification, datasheet, or download for HP ZBook 15v...
          09-06-2024, 11:39 AM
        • harp
          Comparing FreeNAS, FTP server, SMB server, multimedia server...
          by harp
          I thinking about some central LAN file server, on where I can put some files from other devices, or access to them, and maybe play some movie without download...

          I never study this, but when I see that freenas need few gigabyte of ram to recommended working, some wiered partition, I wonder if I miss somewhat in the midletime...
          Also exist "turnkey file server", and other turnkey products that I can not distinguished what is major difference and how it perform - no experiance at all.

          What is general difference between this products, and what be most useful...
          01-04-2024, 02:44 PM
        • ratdude747
          Server Upgrade?
          by ratdude747
          I'm pushing 5 years on my current server and I'm thinking it may be time for some sort of an upgrade.

          The main issue I'm having is random ATA errors locking the system up at the most inopportune times. Probably the PATA to SATA adapter (I have a few more NOS ones on the shelf I could toss at it) but honestly I'm thinking an old "early" socket 940 board is a retro rig in 2023 and ough to be retired.

          The question for me is how much of an upgrade should I shoot for? The main issue I have to deal with is if I keep my chassis, the backplane is 16x SATA. Not SAS....
          01-31-2023, 05:49 PM
        • Loading...
        • No more items.
        Working...