Site-to-Site VPN


Y

Yasser Abbass

Hi all

I'm trying to setup a site-to-site vpn between two ISA2000 servers one at
mainoffice with windows 2003
behind PIX 515E
and the other is on remote office with windows 2000.

I used local and remote VPN wizard i followed the instruction found on
ISAserver.org site
http://www.isaserver.org/img/upl/vpnkitbeta2/g2g-betab.htm
everything worked fine and connection is established but i can't ping from
the remote office to main office
although i can ping from main office the remote isa server.

the internal ip of the remote isa is 192.168.4.1

the routing table on the remote isa is as follow

Network Destination Netmask Gateway
Interface Metric
0.0.0.0 0.0.0.0 163.xxx.xxx.xx
163.xxx.xxx.xx 1
62.xxx.xx.xx 255.255.255.255 163.xxx.xxx.xx
163.xxx.xxx.xx 1
127.0.0.0 255.0.0.0 127.0.0.1
127.0.0.1 1
163.xxx.xxx.xx 255.255.255.240 163.xxx.xxx.xx
163.xxx.xxx.xx 1
163.xxx.xxx.xx 255.255.255.255 127.0.0.1
127.0.0.1 1
163.xx.255.255 255.255.255.255 163.xxx.xxx.xx
163.xxx.xxx.xx 1
192.168.1.0 255.255.255.0 192.168.4.202
192.168.1.203 1
192.168.1.203 255.255.255.255 127.0.0.1
127.0.0.1 1
192.168.1.255 255.255.255.255 192.168.1.203
192.168.1.203 1
192.168.4.0 255.255.255.0 192.168.4.1
192.168.4.1 1
192.168.4.1 255.255.255.255 127.0.0.1
127.0.0.1 1
192.168.4.201 255.255.255.255 127.0.0.1
127.0.0.1 1
192.168.4.202 255.255.255.255 192.168.1.203
192.168.1.203 1
192.168.4.255 255.255.255.255 192.168.4.1 192.168.
4.1 1
224.0.0.0 224.0.0.0 163.xxx.xxx.xx
163.xxx.xxx.xx 1
224.0.0.0 224.0.0.0 192.168.1.203
192.168.1.203 1
224.0.0.0 224.0.0.0 192.168.4.1
192.168.4.1 1
255.255.255.255 255.255.255.255 192.168.4.1 192.168.4.1
1
Default Gateway: 163.xxx.xxx.xx
===========================================================================
Persistent Routes:
None

the routing table on the local isa is as follow
the internal ip of the mainoffice isa is 192.168.1.4

Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.2.16 192.168.2.4 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
163.xxx.xxx.xx 255.255.255.255 192.168.2.16 192.168.2.4 20
192.168.1.0 255.255.255.0 192.168.1.4 192.168.1.4 20
192.168.1.4 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.1.201 255.255.255.255 127.0.0.1 127.0.0.1 50
192.168.1.203 255.255.255.255 192.168.4.202 192.168.4.202 1
192.168.1.255 255.255.255.255 192.168.1.4 192.168.1.4 20
192.168.2.0 255.255.255.0 192.168.2.4 192.168.2.4 20
192.168.2.4 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.2.6 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.2.7 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.2.9 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.2.255 255.255.255.255 192.168.2.4 192.168.2.4 20
192.168.4.0 255.255.255.0 192.168.1.203 192.168.4.202 1
192.168.4.202 255.255.255.255 127.0.0.1 127.0.0.1 50
192.168.4.255 255.255.255.255 192.168.4.202 192.168.4.202 50
224.0.0.0 240.0.0.0 192.168.1.4 192.168.1.4 20
224.0.0.0 240.0.0.0 192.168.2.4 192.168.2.4 20
224.0.0.0 240.0.0.0 192.168.4.202 192.168.4.202 50
255.255.255.255 255.255.255.255 192.168.1.4 192.168.1.4 1
255.255.255.255 255.255.255.255 192.168.2.4 192.168.2.4 1
255.255.255.255 255.255.255.255 192.168.4.202 192.168.4.202 1
Default Gateway: 192.168.2.16
===========================================================================
Persistent Routes:
None

i think it's a routing problem since i can ping from one side only


can anybody help

many thanks
 
Ad

Advertisements


Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top