Thomas Shinder Blog RSS

All Blogs  »  Thomas Shinder Blog  »  ISA Central  »  Blog article: Site to Site IPsec Tunnel Mode VPN Troubleshooting - Traffic cannot be routed from the ISA Server computer to the remote VPN site

Site to Site IPsec Tunnel Mode VPN Troubleshooting - Traffic cannot be routed from the ISA Server computer to the remote VPN site

As you might know, the ISA firewall supports site to site VPN connections between other ISA firewalls, as well as third party firewalls, using the IPsec tunnel mode protocol. IPsec tunnel mode support was added to enable the ISA firewall administrator to use IPsec tunnel mode to connect to other, non-ISA firewall VPN gateways. However, in your test environment, you might find that traffic isn’t routed from one network to another. Why?

Cause: The network adapter that listens for site-to-site VPN connections from the remote site network (usually the External network) does not have a default gateway configured.

Solution: To correct this error, define a default gateway that is not a local address for the network adapter that listens for site-to-site VPN connections. Note that ISA Server does not support multiple default gateways. Set a default gateway on only one of the network adapters associated with ISA Server networks, and do not configure more than one default gateway on that adapter.

Yep. Even if the external interfaces of both ends of the site to site IPsec tunnel mode connection are on the same network ID, you still need to have both ends configured with a default gateway.

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING documentation | integration | virtualization
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Solution Center