issue with browsing accross IP Sec tunnel

G

Guest

I support a remote site lets call it site B. At site B we use sonicwall IP
Sec tunnels to connect 25 or so pcs and 3 servers (2 of which are 2000 DC's),
to site A. The client machines and servers use this tunnel from a Site B
(192.168.44.0) to connect Site A (192.168.1.0) which contains additional DC's
and our primary and only exchange server.

Up until about a month ago everything worked fine between the sites and we
could replicate DNS etc client pcs could browse files on both sides using unc
names or unc ip mappings. Then it basically stopped working, our tunnel is
up and connected and we can pint by name and IP address but are unable to go
beyond that.

The critical issue is that our exchange server (Site A) is not at site B and
now outlook clients cannot connect to exchange internally at Site B thus no
email. DNS replication is also failing as they sites cannot connect using AD
synch either, so now AD is also not able to replicate changes from site to
site.
Site B geographically is 2000 miles from Site A so we are trying to get this
done remotely. We do have remote access in using IP mapping.

At this point we have spent countless hours on phone getting no good
response from MS support as we are also a MS partner. Additionally we have
replaced the soncicwall appliance at site B, added host files on all pcs and
several other steps with no good result. We have basically hit the wall and
have no idea what would be causing this issue. If anyone has any suggestion
or has experienced this before it would greatly help us if any suggestions
could be made. I actually think it could be something very simple but we are
so far in we may not just see it.

We are stumped on this so any suggestions would be great!

Thanks
Mike
 
E

Eve

Hi Mike

You don't mention what service you are using to these remote locations.
Is it dsl?

What version Sonicwalls are you using?

I use Sonicwalls to create VPN hardware tunnels over dsl - a Pro3060
at the network side, and TZ150s and TZ170s at the remote side. I have
come across a possibly related problem - IKE packets will pass fine,
and allow the tunnel to be successfully negotiated. IPSEC packets will
fail over time, meaning that tunnel appears up, but won't pass
encrypted traffic.

The only workaround I have thus far come up with is to power off and
then on the dsl modem, which I have to think is a dsl problem. I think
the Pro3060 is implicated in some way, though, because this problem
started when I upgraded my Pro200 to the Pro3060. I can't get Sonicwall
to help me. I am considering changing dsl providers.

- Eve
IT Manager, Teton County Government
 
N

Nicolae Mihai

Take a look at your mss on your ipsec addapter(ethernet or whatever that
is) (try using a smaller value like 1200-1300)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top