Windows Server 2012 VPN route from LAN to client Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 23, 2019 at 23:30 UTC (7:30pm US/Eastern) Come Celebrate our 10 Year Anniversary!Route through site-to-site VPN not workingWindows Server 2008 R2 RRAS VPN client routingWindows 2003 vs Windows 2008 VPNNAT not working after enabling DirectAccessWindows 2008 RRAS VPN Users can resolve DNS but not ping to internet or surf internet when connectedWindows VPN server can talk to VPN clients, but won't send packets from its local network to the VPN clientsVPN Connection Causes Internal LAN Connection Loss with ServerCannot ping RRAS Client from RRAS serverserver 2012 vpn not passing trafficDNS resolution of machines connected from VPN

Resize vertical bars (absolute-value symbols)

How does light 'choose' between wave and particle behaviour?

Relating to the President and obstruction, were Mueller's conclusions preordained?

One-one communication

How to change the tick of the color bar legend to black

Moving a wrapfig vertically to encroach partially on a subsection title

What adaptations would allow standard fantasy dwarves to survive in the desert?

Putting class ranking in CV, but against dept guidelines

Asymptotics question

what is the log of the PDF for a Normal Distribution?

How many time has Arya actually used Needle?

Delete free apps from library

What initially awakened the Balrog?

Did Mueller's report provide an evidentiary basis for the claim of Russian govt election interference via social media?

Is there public access to the Meteor Crater in Arizona?

In musical terms, what properties are varied by the human voice to produce different words / syllables?

I got rid of Mac OSX and replaced it with linux but now I can't change it back to OSX or windows

Why not send Voyager 3 and 4 following up the paths taken by Voyager 1 and 2 to re-transmit signals of later as they fly away from Earth?

Constant factor of an array

Why do early math courses focus on the cross sections of a cone and not on other 3D objects?

What does Turing mean by this statement?

Should a wizard buy fine inks every time he want to copy spells into his spellbook?

Why weren't discrete x86 CPUs ever used in game hardware?

Did any compiler fully use 80-bit floating point?



Windows Server 2012 VPN route from LAN to client



Announcing the arrival of Valued Associate #679: Cesar Manara
Planned maintenance scheduled April 23, 2019 at 23:30 UTC (7:30pm US/Eastern)
Come Celebrate our 10 Year Anniversary!Route through site-to-site VPN not workingWindows Server 2008 R2 RRAS VPN client routingWindows 2003 vs Windows 2008 VPNNAT not working after enabling DirectAccessWindows 2008 RRAS VPN Users can resolve DNS but not ping to internet or surf internet when connectedWindows VPN server can talk to VPN clients, but won't send packets from its local network to the VPN clientsVPN Connection Causes Internal LAN Connection Loss with ServerCannot ping RRAS Client from RRAS serverserver 2012 vpn not passing trafficDNS resolution of machines connected from VPN



.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








0















I am trying to set up a VPN using Windows Server 2012 Standard. My network has a SonicWALL edge router, and the server in question is a DC, running DNS, DHCP and RRAS, and the subnet is 10.0.0.0/24.



I configured using the 'advanced' wizard, enabling both DirectAccess and VPN. Clients can now connect to the VPN. They receive an IP address from DHCP in the 10.0.0.0/24 subnet and can then access the VPN server using either the PPP adaptor IP or the Ethernet adaptor IP on it.



However, if they try to ping anything else, one ping reply is received and the rest disappear. The VPN is successfully routing the client's packets to the destination host - I can see this in Wireshark - but only one reply actually goes to the client; the rest go to the server. Similarly, if I ping the client from an internal host, the first packet goes to the client, and the rest act as if it is addressing the VPN server itself.



It is clear that the VPN server is routing things sent from the client to the internal network, but is only routing one packet at a time from the internal network to the client.



I can't think of a reason that the behaviour would be different for the first packet than subsequent ones. Any advice would be appreciated.










share|improve this question




























    0















    I am trying to set up a VPN using Windows Server 2012 Standard. My network has a SonicWALL edge router, and the server in question is a DC, running DNS, DHCP and RRAS, and the subnet is 10.0.0.0/24.



    I configured using the 'advanced' wizard, enabling both DirectAccess and VPN. Clients can now connect to the VPN. They receive an IP address from DHCP in the 10.0.0.0/24 subnet and can then access the VPN server using either the PPP adaptor IP or the Ethernet adaptor IP on it.



    However, if they try to ping anything else, one ping reply is received and the rest disappear. The VPN is successfully routing the client's packets to the destination host - I can see this in Wireshark - but only one reply actually goes to the client; the rest go to the server. Similarly, if I ping the client from an internal host, the first packet goes to the client, and the rest act as if it is addressing the VPN server itself.



    It is clear that the VPN server is routing things sent from the client to the internal network, but is only routing one packet at a time from the internal network to the client.



    I can't think of a reason that the behaviour would be different for the first packet than subsequent ones. Any advice would be appreciated.










    share|improve this question
























      0












      0








      0








      I am trying to set up a VPN using Windows Server 2012 Standard. My network has a SonicWALL edge router, and the server in question is a DC, running DNS, DHCP and RRAS, and the subnet is 10.0.0.0/24.



      I configured using the 'advanced' wizard, enabling both DirectAccess and VPN. Clients can now connect to the VPN. They receive an IP address from DHCP in the 10.0.0.0/24 subnet and can then access the VPN server using either the PPP adaptor IP or the Ethernet adaptor IP on it.



      However, if they try to ping anything else, one ping reply is received and the rest disappear. The VPN is successfully routing the client's packets to the destination host - I can see this in Wireshark - but only one reply actually goes to the client; the rest go to the server. Similarly, if I ping the client from an internal host, the first packet goes to the client, and the rest act as if it is addressing the VPN server itself.



      It is clear that the VPN server is routing things sent from the client to the internal network, but is only routing one packet at a time from the internal network to the client.



      I can't think of a reason that the behaviour would be different for the first packet than subsequent ones. Any advice would be appreciated.










      share|improve this question














      I am trying to set up a VPN using Windows Server 2012 Standard. My network has a SonicWALL edge router, and the server in question is a DC, running DNS, DHCP and RRAS, and the subnet is 10.0.0.0/24.



      I configured using the 'advanced' wizard, enabling both DirectAccess and VPN. Clients can now connect to the VPN. They receive an IP address from DHCP in the 10.0.0.0/24 subnet and can then access the VPN server using either the PPP adaptor IP or the Ethernet adaptor IP on it.



      However, if they try to ping anything else, one ping reply is received and the rest disappear. The VPN is successfully routing the client's packets to the destination host - I can see this in Wireshark - but only one reply actually goes to the client; the rest go to the server. Similarly, if I ping the client from an internal host, the first packet goes to the client, and the rest act as if it is addressing the VPN server itself.



      It is clear that the VPN server is routing things sent from the client to the internal network, but is only routing one packet at a time from the internal network to the client.



      I can't think of a reason that the behaviour would be different for the first packet than subsequent ones. Any advice would be appreciated.







      vpn windows-server-2012 rras






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 20 '13 at 21:09









      SunlightSunlight

      10113




      10113




















          2 Answers
          2






          active

          oldest

          votes


















          0














          I think I have found the answer, although if anyone could explain why it is this way I would be grateful.



          I checked the Network Policy Service settings, and there were packet filters enabled for IPv4 to allow only "User's network". Removing this filter allows unrestricted connection.



          I do not know why this causes the behaviour I saw, nor do I know why (if it does block VPN traffic) it is set by default... but I am glad the problem is fixed.






          share|improve this answer






























            0














            Think of NPS sort of like NAT. You would want to specify the servers that VPN traffic can get to.



            https://msdn.microsoft.com/en-us/library/cc732912.aspx?f=255&MSPPError=-2147217396






            share|improve this answer























              Your Answer








              StackExchange.ready(function()
              var channelOptions =
              tags: "".split(" "),
              id: "2"
              ;
              initTagRenderer("".split(" "), "".split(" "), channelOptions);

              StackExchange.using("externalEditor", function()
              // Have to fire editor after snippets, if snippets enabled
              if (StackExchange.settings.snippets.snippetsEnabled)
              StackExchange.using("snippets", function()
              createEditor();
              );

              else
              createEditor();

              );

              function createEditor()
              StackExchange.prepareEditor(
              heartbeatType: 'answer',
              autoActivateHeartbeat: false,
              convertImagesToLinks: true,
              noModals: true,
              showLowRepImageUploadWarning: true,
              reputationToPostImages: 10,
              bindNavPrevention: true,
              postfix: "",
              imageUploader:
              brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
              contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
              allowUrls: true
              ,
              onDemand: true,
              discardSelector: ".discard-answer"
              ,immediatelyShowMarkdownHelp:true
              );



              );













              draft saved

              draft discarded


















              StackExchange.ready(
              function ()
              StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f556373%2fwindows-server-2012-vpn-route-from-lan-to-client%23new-answer', 'question_page');

              );

              Post as a guest















              Required, but never shown

























              2 Answers
              2






              active

              oldest

              votes








              2 Answers
              2






              active

              oldest

              votes









              active

              oldest

              votes






              active

              oldest

              votes









              0














              I think I have found the answer, although if anyone could explain why it is this way I would be grateful.



              I checked the Network Policy Service settings, and there were packet filters enabled for IPv4 to allow only "User's network". Removing this filter allows unrestricted connection.



              I do not know why this causes the behaviour I saw, nor do I know why (if it does block VPN traffic) it is set by default... but I am glad the problem is fixed.






              share|improve this answer



























                0














                I think I have found the answer, although if anyone could explain why it is this way I would be grateful.



                I checked the Network Policy Service settings, and there were packet filters enabled for IPv4 to allow only "User's network". Removing this filter allows unrestricted connection.



                I do not know why this causes the behaviour I saw, nor do I know why (if it does block VPN traffic) it is set by default... but I am glad the problem is fixed.






                share|improve this answer

























                  0












                  0








                  0







                  I think I have found the answer, although if anyone could explain why it is this way I would be grateful.



                  I checked the Network Policy Service settings, and there were packet filters enabled for IPv4 to allow only "User's network". Removing this filter allows unrestricted connection.



                  I do not know why this causes the behaviour I saw, nor do I know why (if it does block VPN traffic) it is set by default... but I am glad the problem is fixed.






                  share|improve this answer













                  I think I have found the answer, although if anyone could explain why it is this way I would be grateful.



                  I checked the Network Policy Service settings, and there were packet filters enabled for IPv4 to allow only "User's network". Removing this filter allows unrestricted connection.



                  I do not know why this causes the behaviour I saw, nor do I know why (if it does block VPN traffic) it is set by default... but I am glad the problem is fixed.







                  share|improve this answer












                  share|improve this answer



                  share|improve this answer










                  answered Nov 20 '13 at 21:20









                  SunlightSunlight

                  10113




                  10113























                      0














                      Think of NPS sort of like NAT. You would want to specify the servers that VPN traffic can get to.



                      https://msdn.microsoft.com/en-us/library/cc732912.aspx?f=255&MSPPError=-2147217396






                      share|improve this answer



























                        0














                        Think of NPS sort of like NAT. You would want to specify the servers that VPN traffic can get to.



                        https://msdn.microsoft.com/en-us/library/cc732912.aspx?f=255&MSPPError=-2147217396






                        share|improve this answer

























                          0












                          0








                          0







                          Think of NPS sort of like NAT. You would want to specify the servers that VPN traffic can get to.



                          https://msdn.microsoft.com/en-us/library/cc732912.aspx?f=255&MSPPError=-2147217396






                          share|improve this answer













                          Think of NPS sort of like NAT. You would want to specify the servers that VPN traffic can get to.



                          https://msdn.microsoft.com/en-us/library/cc732912.aspx?f=255&MSPPError=-2147217396







                          share|improve this answer












                          share|improve this answer



                          share|improve this answer










                          answered Feb 16 '16 at 15:25









                          Jonathan PiccirilliJonathan Piccirilli

                          1475




                          1475



























                              draft saved

                              draft discarded
















































                              Thanks for contributing an answer to Server Fault!


                              • Please be sure to answer the question. Provide details and share your research!

                              But avoid


                              • Asking for help, clarification, or responding to other answers.

                              • Making statements based on opinion; back them up with references or personal experience.

                              To learn more, see our tips on writing great answers.




                              draft saved


                              draft discarded














                              StackExchange.ready(
                              function ()
                              StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f556373%2fwindows-server-2012-vpn-route-from-lan-to-client%23new-answer', 'question_page');

                              );

                              Post as a guest















                              Required, but never shown





















































                              Required, but never shown














                              Required, but never shown












                              Required, but never shown







                              Required, but never shown

































                              Required, but never shown














                              Required, but never shown












                              Required, but never shown







                              Required, but never shown







                              Popular posts from this blog

                              Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

                              Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

                              Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020