VPN not routing correctly
hi,
i have setup windows 2008r2 sp1 vpn access, works fine execpt when uncheck (in client side) use remote gateway "split-tunneling".
the problem comes out nwetroks started in 192.x.x.x, strange reason client tries route default gateway instead of remote. (the route configured in ras server).
for other networks client uses routes configured in ther server.
thanks
mariano
after considerable research, i found out rras server not hand out routes rras clients. you will need use dhcp option 121 or 249 (depending on dhcp server version running), or use cmak create vpn connectoid has routes built in.
i hope find info helpful , answers questions , concerns.
================================
================================
windows vpn split tunneling
windows xp dhcp client can use dhcp option 249 "classless static routes."
windows vista , newer uses dhcp option 121
windows server 2008 , newer, uses available dhcp option 121 "classless static routes." (option 249 not availalbe)
windows server 2003 uses available dhcp option 249 (option 121 not available)
using dhcp assign static routes « richard hicks' blogjan 8, 2009
"you can add static route configuring dhcp option 249 on windows server 2003 dhcp servers, or option 121 on windows server 2008 ..."
"note: dhcp option 121 ignored dhcp clients prior windows server 2008 , windows vista. may not work if using windows server 2008 dhcp server assign networking configuration these clients. windows vista , windows server 2008 dhcp clients use both option 121 , option 249."
http://tmgblog.richardhicks.com/2009/01/08/using-dhcp-to-assign-static-routes/
split tunneling concurrent access internet , intranet
http://technet.microsoft.com/en-us/library/bb878117.aspx
split tunneling cmak
windows 2003 dhcp server option 249 "classless static routes" option (for xp dhcp clients split tunneling option)
http://www.vistax64.com/vista-security/106544-split-tunneling-cmak.html
thread: "assigning routes pptp client?"
http://forum.mikrotik.com/viewtopic.php?f=8&t=10405
================================
================================
ace
ace fekay
mvp, mct, mcitp ea, mcts windows 2008 & exchange 2007 & exchange 2010, exchange 2010 enterprise administrator, mcse & mcsa 2003/2000, mcsa messaging 2003
microsoft certified trainer
microsoft mvp - directory services
complete list of technical blogs: http://www.delawarecountycomputerconsulting.com/technicalblogs.php
this posting provided as-is no warranties or guarantees , confers no rights.
Windows Server > Network Infrastructure Servers
Comments
Post a Comment