Networking Forums

Networking Forums > Computer Networking > Windows Networking > Unable to create PPTP tunnel between two DCs

Reply
Thread Tools Display Modes

Unable to create PPTP tunnel between two DCs

 
 
Sune T. Tougaard
Guest
Posts: n/a

 
      03-26-2006, 05:15 PM
Hi all,

Could really need some help here.
I realize that this probably isn't a "supported" way of doing it, but
here goes:

First a little background:
Two domain controllers (win2k3 std.) in the same domain was synched,
and prepared for long-time disconnection.
One of them was shut down and moved to a remote location, being a
couple of months underway, while the other server was still being
worked on.
Now the shipped server has been powered back on, and i'd like the two
servers to see each other and start replicating again. When this is
done, the server still at my location, will be shut down at moved to
the same place.

The two sites are connected by a VPN tunnel (Cisco routers), where they
can reach each other by their NAT address. No trafic restrictions
between the two servers.

Now i'd like to create a PPTP tunnel between the two servers (using the
NAT addresses), so they can reach each other on their real addresses.

Have created a couple of test-setups similar to the above, and here i'm
having no problems creating the PPTP tunnel with RRAS and letting them
talk over that.

This fails miserably, when being implemented on the "real" servers,
though. I'm getting the error that i'm using invalid username/password
on the domain. The answering server logs an event, that the user isn't
allowed to log on to that computer with logon type 3 (logon from
network). This user right, however, has been granted (and using the
domain admin account doesn't work either).
Have been trying exisiting users, new users created manually, new users
created from the RRAS wizard, nothing seems to work.
Have also tried using Radius (IAS) authentication on a single server,
to authenticate users on both the servers. Still no luck.

The user(s) that i've created are able to log on the servers both
locally and remote. Logging in to one server, gives me full access to
the other with an explorer and other computer management (using the NAT
address, at that...).

Trying to have the IAS to not authenticate users, but just accept the
connection instead, gives me an error, that the identity of the server
couldn't be verified.

There has been quite a lot of changes made to group policies, that has
to do with security. These changes, however, i have exported from the
real servers and imported them into the test-setups, so i can't see
that the tightened security could be the issue.

The only thing that i can think of that isn't the same in the
test-setup, is the period of time the servers has been disconnected.

Was thinking that perhaps a machine account has been changed in the
meantime (the server that has been shipped), that the other server
isn't aware of, but i don't know if it's allowed to do that "on its
own". The server here at my location holds all FSMO roles, but i guess
that perhaps the remote server, being a DC, might change "something"
anyways.

Is there anyone out there with similar experiences or ideas to what i
can do to get the machines to talk to each other again?!

Thanks.

--
/Sune

 
Reply With Quote
 
 
 
 
Petro
Guest
Posts: n/a

 
      03-27-2006, 05:21 PM
I'm not sure I follow you, if the two machines are connected via a VPN,
then they should be on the same network, and you shouldn't need to make
a PPTP tunnel, that's a second layer of protocol. Is your VPN on a
different subnet than your private LAN? Can you ping any servers
connected by VPN?

 
Reply With Quote
 
Sune T. Tougaard
Guest
Posts: n/a

 
      03-27-2006, 08:01 PM
Hi Petro,

I'll see if i can explain it (english is not my native).

This is not the real setup, but to give an idea of what it looks like.

The sites:
Site A:
10.10.10.0/24

Site B:
10.10.10.0/24

The two servers (that was standing next to each other to begin with):
Server A:
10.10.10.10
Server B:
10.10.10.11

Now server A has been moved to site B.

A VPN tunnel between the two sites doing NAT:
Site A can reach site B by using:
172.16.1.0/24

Site B can reach site A by using:
172.16.2.0/24

That is:
Server A can ping Server B by using 172.16.2.11
Server B can ping Server A by using 172.16.1.10

The PPTP tunnel i'd like to create:
Server A:
Peer with 172.16.2.11 with a static route: 10.10.10.11/32

Server B:
Peer with 172.16.1.10 with a static route: 10.10.10.10/32

As this is just a more or less temporary solution, as Server A
eventually will be moved to Site B as well, i don't care much if this
is the most optimal/efficient/pretty solution or not.
"Just" want to get these servers in sync, transfer FSMO roles, clean up
a bit and then shut down Server A for shipment.

And i don't like the fact that it works in the test-setup but not in
"real life".

Hope my explanation makes sense.
Thanks.

--
/Sune

 
Reply With Quote
 
Sune T. Tougaard
Guest
Posts: n/a

 
      03-30-2006, 08:44 AM
I managed to create the tunnel by using an IAS server on a member
server, and the using a local account on that server (as in: not a
domain account).
Dislike that i have to use a "workaround" like that, so i guess that
there are other issues with the two DCs that i have to look into.

Thanks.

--
/Sune

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
A PPTP VPN tunnel and a LAN Clark Smith Linux Networking 1 03-19-2011 07:40 AM
Create L2TP tunnel without IPSEC Andy Windows Networking 0 12-13-2007 07:17 PM
VPN (PPtP) tunnel through D-Link DSA3200? Michael Network Routers 1 08-10-2006 09:06 PM
create inbound tunnel through firewall. Unruh Linux Networking 12 06-20-2005 04:25 PM
How to create a VPN-tunnel between a ZyWall 10 and NetScreen 25 Jens Vejmand & Holger Danske Network Routers 0 06-11-2005 01:21 PM



1 2 3 4 5 6 7 8 9 10 11