Click here to get back home

W2K3 & VPN blocking access to server

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
W2K3 & VPN blocking access to server riley 05-17-2006
Posted by riley on May 17, 2006, 9:10 pm
Please log in for more thread options
Hello,
We have a customer that is running Exchange 2003 (std) on a Windows Server
2003 (std) SP1 and they mistakenly ran the server configuration wizard this
morning to turn on VPN when all they needed was Terminal Services. After
they removed the VPN they could no longer connect to the server with Outlook
or see other machines in the domain from the server. Also, no other machines
could see the server in question. The server could still log on to the
domain as usual and you could get email via OWA from any client in the
domain but not with a direct Outlook connection. I cannot figure out how to
solve the problem. I'm certain a switch got turned on with the VPN
installation but I don't know which one. Also, there is SQL on the server
that we can't get to it either. Can someone help with this problem?
Riley



Posted by Steven L Umbach on May 17, 2006, 9:59 pm
Please log in for more thread options
Did they disable RRAS? You can check by going into the Remote Access
Management Console. If the server still shows a green up arrow then it is
enabled and probably what has happened is that configuring VPN enabled
input/output filters on the network adapter and I believe disabling Remote
Access will remove them or you could do it manually [see first link below]
if you need to leave Remote Access enabled for some reason. Also check the
Windows Firewall to see if it is enabled and if it is and should be that it
has the proper exemptions. Another thing to look at is to see if someone
configured an ipsec policy on the server that is restricting what ports can
be used. You can go into Local Security Policy to see if an ipsec policy is
assigned and also examine the properties of the ipsec policy such as the
filter lists to see how traffic is restricted. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;324262

> Hello,
> We have a customer that is running Exchange 2003 (std) on a Windows Server
> 2003 (std) SP1 and they mistakenly ran the server configuration wizard
> this
> morning to turn on VPN when all they needed was Terminal Services. After
> they removed the VPN they could no longer connect to the server with
> Outlook
> or see other machines in the domain from the server. Also, no other
> machines
> could see the server in question. The server could still log on to the
> domain as usual and you could get email via OWA from any client in the
> domain but not with a direct Outlook connection. I cannot figure out how
> to
> solve the problem. I'm certain a switch got turned on with the VPN
> installation but I don't know which one. Also, there is SQL on the server
> that we can't get to it either. Can someone help with this problem?
> Riley
>
>



Posted by riley on May 17, 2006, 10:21 pm
Please log in for more thread options
Thank you very much Steven for the quick response. I don't have access to
the customer's location right now but I'm trying to get my homework done
before tomorrow morning. This customer is not familiar with many of the
issues you discussed below. He was trying to help me out this morning by
giving me remote access through a MS VPN to his SQL/Exchange server. I was
busy with another customer and couldn't get back to him to stop everything
(not that I've been much help the rest of the day). He used the "Configure
Your Server Wizard" in Win2003. I'm certain he didn't do anything but launch
the wizard and follow the clicks. According to him when it didn't work he
just reversed the process and uninstalled the VPN. When he called this
afternoon saying Outlook would not connect to the Exchange Server 2003 I
went over thinking it was an Exchange problem. After looking around in the
network I realized you could not see the server in question from anywhere on
the network and from the sever you could not see any other machines. I can
ping the machine. I can get into AD and look at the properties of the
machine. Just cannot connect to it. We can get to Exchange via OWA and I
assume that's because OWA is web based on the local machine. I'll have to
wait until tomorrow morning to get into RRAS. When you run the wizard to
install a VPN does it open/turn on RRAS? He had installed Terminal Services
on that same machine this past Friday. Does that have anything to do with
this problem/VPN? I don't think he configured anything in the VPN area
except to take the defaults. Anyway, I hope this additional information
helps a little more. Thanks again for the help.
Riley


> Did they disable RRAS? You can check by going into the Remote Access
> Management Console. If the server still shows a green up arrow then it is
> enabled and probably what has happened is that configuring VPN enabled
> input/output filters on the network adapter and I believe disabling Remote
> Access will remove them or you could do it manually [see first link below]
> if you need to leave Remote Access enabled for some reason. Also check the
> Windows Firewall to see if it is enabled and if it is and should be that
it
> has the proper exemptions. Another thing to look at is to see if someone
> configured an ipsec policy on the server that is restricting what ports
can
> be used. You can go into Local Security Policy to see if an ipsec policy
is
> assigned and also examine the properties of the ipsec policy such as the
> filter lists to see how traffic is restricted. --- Steve
>
> http://support.microsoft.com/default.aspx?scid=kb;en-us;324262
>
> > Hello,
> > We have a customer that is running Exchange 2003 (std) on a Windows
Server
> > 2003 (std) SP1 and they mistakenly ran the server configuration wizard
> > this
> > morning to turn on VPN when all they needed was Terminal Services. After
> > they removed the VPN they could no longer connect to the server with
> > Outlook
> > or see other machines in the domain from the server. Also, no other
> > machines
> > could see the server in question. The server could still log on to the
> > domain as usual and you could get email via OWA from any client in the
> > domain but not with a direct Outlook connection. I cannot figure out how
> > to
> > solve the problem. I'm certain a switch got turned on with the VPN
> > installation but I don't know which one. Also, there is SQL on the
server
> > that we can't get to it either. Can someone help with this problem?
> > Riley
> >
> >
>
>



Posted by riley on May 17, 2006, 10:42 pm
Please log in for more thread options
Steven,
That appears to have solved the problem. I was able to get into another
server that we have access to and then get into AD. From there I went to the
machine and started the RRAS service and everything started coming up. The
web sites that have connections to SQL are now working and I can see shares
on the hard drives when I drill into the machine. It doesn't show up in
network places yet but I'm sure it will before am. We'll have to wait on
Outlook but I'm sure it's working. Thanks again for the help.
Riley

> Thank you very much Steven for the quick response. I don't have access to
> the customer's location right now but I'm trying to get my homework done
> before tomorrow morning. This customer is not familiar with many of the
> issues you discussed below. He was trying to help me out this morning by
> giving me remote access through a MS VPN to his SQL/Exchange server. I was
> busy with another customer and couldn't get back to him to stop everything
> (not that I've been much help the rest of the day). He used the "Configure
> Your Server Wizard" in Win2003. I'm certain he didn't do anything but
launch
> the wizard and follow the clicks. According to him when it didn't work he
> just reversed the process and uninstalled the VPN. When he called this
> afternoon saying Outlook would not connect to the Exchange Server 2003 I
> went over thinking it was an Exchange problem. After looking around in the
> network I realized you could not see the server in question from anywhere
on
> the network and from the sever you could not see any other machines. I can
> ping the machine. I can get into AD and look at the properties of the
> machine. Just cannot connect to it. We can get to Exchange via OWA and I
> assume that's because OWA is web based on the local machine. I'll have to
> wait until tomorrow morning to get into RRAS. When you run the wizard to
> install a VPN does it open/turn on RRAS? He had installed Terminal
Services
> on that same machine this past Friday. Does that have anything to do with
> this problem/VPN? I don't think he configured anything in the VPN area
> except to take the defaults. Anyway, I hope this additional information
> helps a little more. Thanks again for the help.
> Riley
>
>
> > Did they disable RRAS? You can check by going into the Remote Access
> > Management Console. If the server still shows a green up arrow then it
is
> > enabled and probably what has happened is that configuring VPN enabled
> > input/output filters on the network adapter and I believe disabling
Remote
> > Access will remove them or you could do it manually [see first link
below]
> > if you need to leave Remote Access enabled for some reason. Also check
the
> > Windows Firewall to see if it is enabled and if it is and should be that
> it
> > has the proper exemptions. Another thing to look at is to see if someone
> > configured an ipsec policy on the server that is restricting what ports
> can
> > be used. You can go into Local Security Policy to see if an ipsec policy
> is
> > assigned and also examine the properties of the ipsec policy such as the
> > filter lists to see how traffic is restricted. --- Steve
> >
> > http://support.microsoft.com/default.aspx?scid=kb;en-us;324262
> >
> > > Hello,
> > > We have a customer that is running Exchange 2003 (std) on a Windows
> Server
> > > 2003 (std) SP1 and they mistakenly ran the server configuration wizard
> > > this
> > > morning to turn on VPN when all they needed was Terminal Services.
After
> > > they removed the VPN they could no longer connect to the server with
> > > Outlook
> > > or see other machines in the domain from the server. Also, no other
> > > machines
> > > could see the server in question. The server could still log on to the
> > > domain as usual and you could get email via OWA from any client in the
> > > domain but not with a direct Outlook connection. I cannot figure out
how
> > > to
> > > solve the problem. I'm certain a switch got turned on with the VPN
> > > installation but I don't know which one. Also, there is SQL on the
> server
> > > that we can't get to it either. Can someone help with this problem?
> > > Riley
> > >
> > >
> >
> >
>
>



Posted by Steven L Umbach on May 17, 2006, 10:52 pm
Please log in for more thread options
I am not familiar in what the wizard does but I would open the Remote Access
Management Console and see if it shows that the server is active. If it is
you can right click and select disable routing and remote access. I don't
think installing Terminal Services would cause an access problem if that is
all that was done. Running netstat -anp tcp should show that ports 139 TCP
and 445 TCP are listening [or connected] if file and print sharing is
enabled and running and a user on a computer with proper network
connectivity to the computer could verify that with telnet. For instance
from your computer if you entered the command telent xxx.xxx.xxx.xxx 445
where xxx.xxx.xxx.xxx is the actual IP address of the destination computer
you should get a blank command prompt screen with a blinking cursor if the
port is open to your computer. Try telnet localhost 445 on your computer
[assuming fps is enabled] to see how it works. You can also use the free
Microsoft tool portqry to do a command line port scan of a remote computer
to see what ports are open on it to the source computer. It sounds as if
file and print sharing became disabled [or the server service is stopped] or
access to those ports is blocked somehow - Windows Firewall, ipsec policy,
rras filtering, tcp/ip filtering [which does not stop ping], etc. Question
the customer further to see if he can remember doing ANY other configuration
change on the server. --- Steve

http://support.microsoft.com/default.aspx?kbid=832919 --- portqry info


> Thank you very much Steven for the quick response. I don't have access to
> the customer's location right now but I'm trying to get my homework done
> before tomorrow morning. This customer is not familiar with many of the
> issues you discussed below. He was trying to help me out this morning by
> giving me remote access through a MS VPN to his SQL/Exchange server. I was
> busy with another customer and couldn't get back to him to stop everything
> (not that I've been much help the rest of the day). He used the "Configure
> Your Server Wizard" in Win2003. I'm certain he didn't do anything but
> launch
> the wizard and follow the clicks. According to him when it didn't work he
> just reversed the process and uninstalled the VPN. When he called this
> afternoon saying Outlook would not connect to the Exchange Server 2003 I
> went over thinking it was an Exchange problem. After looking around in the
> network I realized you could not see the server in question from anywhere
> on
> the network and from the sever you could not see any other machines. I can
> ping the machine. I can get into AD and look at the properties of the
> machine. Just cannot connect to it. We can get to Exchange via OWA and I
> assume that's because OWA is web based on the local machine. I'll have to
> wait until tomorrow morning to get into RRAS. When you run the wizard to
> install a VPN does it open/turn on RRAS? He had installed Terminal
> Services
> on that same machine this past Friday. Does that have anything to do with
> this problem/VPN? I don't think he configured anything in the VPN area
> except to take the defaults. Anyway, I hope this additional information
> helps a little more. Thanks again for the help.
> Riley
>
>
>> Did they disable RRAS? You can check by going into the Remote Access
>> Management Console. If the server still shows a green up arrow then it is
>> enabled and probably what has happened is that configuring VPN enabled
>> input/output filters on the network adapter and I believe disabling
>> Remote
>> Access will remove them or you could do it manually [see first link
>> below]
>> if you need to leave Remote Access enabled for some reason. Also check
>> the
>> Windows Firewall to see if it is enabled and if it is and should be that
> it
>> has the proper exemptions. Another thing to look at is to see if someone
>> configured an ipsec policy on the server that is restricting what ports
> can
>> be used. You can go into Local Security Policy to see if an ipsec policy
> is
>> assigned and also examine the properties of the ipsec policy such as the
>> filter lists to see how traffic is restricted. --- Steve
>>
>> http://support.microsoft.com/default.aspx?scid=kb;en-us;324262
>>
>> > Hello,
>> > We have a customer that is running Exchange 2003 (std) on a Windows
> Server
>> > 2003 (std) SP1 and they mistakenly ran the server configuration wizard
>> > this
>> > morning to turn on VPN when all they needed was Terminal Services.
>> > After
>> > they removed the VPN they could no longer connect to the server with
>> > Outlook
>> > or see other machines in the domain from the server. Also, no other
>> > machines
>> > could see the server in question. The server could still log on to the
>> > domain as usual and you could get email via OWA from any client in the
>> > domain but not with a direct Outlook connection. I cannot figure out
>> > how
>> > to
>> > solve the problem. I'm certain a switch got turned on with the VPN
>> > installation but I don't know which one. Also, there is SQL on the
> server
>> > that we can't get to it either. Can someone help with this problem?
>> > Riley
>> >
>> >
>>
>>
>
>



Similar ThreadsPosted
at job versus windows service on a w2k3 server February 22, 2006, 3:31 am
W2K3 Server File Deletion From Windows Service August 11, 2006, 4:20 pm
W2K3 Member Server unable to resolve domain SIDs October 12, 2006, 11:56 am
Blocking IP Addresses-Tagged server June 15, 2008, 9:21 pm
Issuing of server/client authentication certs from an Ent. CA running on W2k3 Standard Edition May 14, 2007, 2:43 am
AzMan & W2k3 SP1 problem... June 30, 2005, 7:42 am
Kerberos/ASP/Delegation/W2K3 July 19, 2005, 2:24 pm
IPSEC, W2k3, Client-to-DC August 8, 2005, 10:36 am
NTLM issue with W2K3 April 28, 2006, 10:47 am
Backing up roaming profiles on W2K3 January 11, 2006, 1:37 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap