How to make Forefront TMG build VPN site-to-site tunnel with reduced subnet

I am trying to implement a Site-to-Site VPN tunnel with a supplier. We are using Forefront TMG 2010 SP2 (Site A) and they are using Cisco ASA (Site B)
I have complete access to SITE A, but no access to Site B (suppliers end)
We have set up the VPN tunnel, but it will only come up if it is initiated from the Site B end. We know this is because there is a mismatch in the expected network size. Site B fits within Site A, but not the other way round.
The tunnel is set up at Site A with an allowed route of 10.0.2.60/30 and matched with a configuration at the other end. This configuration is If I look at the "Site-to-site" summary on TMG.
However, my counterpart at site B tells me that when the TMG actually tries to build the tunning, it is not specifying 10.0.2.60/30 but 10.0.2.0/24
I should also mention that TMG internal ip is 10.0.2.6 ,that we only 10.0.2.61 and 10.0.2.62 should be allowed through the tunnel, and that due to existing VPNs on the supplier site, they cannot increase the size of the network on their side to match the 10.0.2.0/24
range
I am a at a bit of a loss why this is happening. Does any one have any guidance, I don't really even know what terminology to use to effectively search for an answer

Hi,
Which VPN protocol you have used?
What is the network addresses you have configure in Create Site-to-Site Connection Wizard? Did you mean that the IP range changed on site B after you created the VPN connection?Please make sure that the ranges match the internal ranges at the site B.
In addition, I am quite sure of your IP ranges for both sites, I would appreciate it if you can tell the IP range for TMG server internal network and the site B.
Beside, you can refer to the link below:
Test Lab Guide: Demonstrate Site to Site VPN with Threat Management Gateway 2010 (Part 1) (Note: Microsoft
is providing this information as a convenience to you. Please make sure that you completely understand the risk before retrieving any suggestions from the above link.)
Best regards,
Susie

Similar Messages

  • How to make a good referencing for my web site

    hi. i start with muse and would like to know how to make a good referencing for my web site; thanks for your answers...

    Google and search the forum for: SEO or Search Engine Optimisation

  • Every time i go to a site or and extension of a site i use a lot it asks me if it can you adobe flash I want to know how to make it so it just allows all site

    Every time i go to a site or and extension of a site i use a lot it asks me if it can you adobe flash I want to know how to make it so it just allows all site to just start it. I only go to mainstream sites so its not a security issue. I have gone into the adobe settings in my control panel and allow sites to store info on my PC so any other suggestions? thank you to anyone who can help.

    Have you tried the Reset Safari... in the pull down menu under Safari?
    Allan

  • RVS4000 to Forefront TMG IPSec VPN

    Hello,
    We configured a site-to-site VPN using a Cisco RVS4000 at one end and TMG at the other.  When we initiate (PING) communication from a client on the TMG LAN, the link is UP and traffic flows both ways.  However, if we start the communication from the Cisco LAN, the PINGs time-out and the link stays DOWN.  Cisco's VPN log file is enclosed.
    We verified that the IPSec settings at each end match and also tried updating the firmware to 2.0.2.7.  Each side of thje tunnel uses a public IP address with no NAT devices in between.
    Any ideas or suggestions appreciated.
    Ian

    Here's a section of the router's log: Jan 6 22:44:36 - [VPN Log]: "HO_VPN" #1: message ignored because it contains an unknown or unexpected payload type (ISAKMP_NEXT_NAT-D) at the outermost level Jan 6 22:44:36 - [VPN Log]: "HO_VPN" #1: sending notification INVALID_PAYLOAD_TYPE to PUBLIC_IP.145.18:500 Jan 6 22:44:56 - [VPN Log]: "HO_VPN" #1: message ignored because it contains an unknown or unexpected payload type (ISAKMP_NEXT_NAT-D) at the outermost level Jan 6 22:44:56 - [VPN Log]: "HO_VPN" #1: sending notification INVALID_PAYLOAD_TYPE to PUBLIC_IP.145.18:500 Any ideas most welcome, Ian

  • How to make Adobe LiveCycle Designer ES 8.2 file compatiable with Adobe Reader X

    Adobe Reader X sporadically is unable to save or print a file created in Adobe LiveCycle Designer ES 8.2. Does anyone have any suggestions on how to make it compatiable/stable with reader X? We want to deploy reader X with Win7 32 bit

    I am not aware of any issues in that area ...can you provide more information as to when it is happening?
    Paul

  • How to make Vista partition on the HDD as first one with Recovery CD

    Hello,
    i want to format and recover the information to my "Vista" (C://) partition, which is the first. But when i choose the option "Format and recover to an existing first partition on your hard disk(without RE)" the computer began to recover to "Partition Type: windows NT NTFS (ID: 07)" which size is only 1.50 GB.
    In the middle of the process it shows "not enough space on a disk"
    Question: how to make "vista" partition the first one? What is "the first partition" in the second option of formating and recovering the system?
    Thank You for Your answers

    Hi
    You can obtain from your friends (I am sure someone has it) Microsoft WXP installations CD and install OS on C partition. On Toshiba download page you will find chipset and all necessary drivers to make WXP running properly. When finished connect external HDD or USB memory stick and copy all your data there. you can also install Nero demo version and create data CD or DVD. It is lot of work but if you have time you can do this without any problems.
    Other way connect your HDD as external one to other PC and copy all your important data. Sorry but I do not see other solution.

  • How to make a video file page on my site popup as an external page

    i have alot of demos on my site and everytime you click on one of my demos it loads that page.I made the page the size of just the video file size too.so, how can i get it to open as an external window above my website and also the size of just the video playing? i have looked in the html code and can't find any
    all the code is css and js. here is my site www.mattmosher.com
    any suggestions would be a great help.

    OK, on this page:
    http://homepage.mac.com/mcmphoto/cinematography.html
    Look for this code (click the link, its a screenshot):
    http://homepage.mac.com/varkgirl/code.png
    (See highlighted section for example)
    Change
    href="blahblah.mov"
    to
    target="_blank" href="blahblah.mov"
    (In other words, put target="_blank" before href)
    Message was edited by: varkgirl to say, I have to ask, WHY do you have your pages created by iWeb on your homepage.mac.com address? Why not just publish directly to .Mac???

  • How to make 1 spry menu for the entire site? but not on each page

    i have a website that i wish to have multiple pages available all form the same menu and late and probably at regular intervals add more tabs to the menu
    is there a way to create a spry menu speratley that the page some how references, something like a frameset but without using framesets?
    im sort of new to webdesigning and unsure of the correct terminology, so i am finding it difficult to look up stuff that i don't know the name for, but will gladly go read someting if you point me in the right direction.
    regards
    for now
    wayne

    You can do this with PHP or ColdFusion
    These are "server side" scripting languages so you will have to test your website after you upload to you web hosting account.
    Or if you set up a local server. Without the local server you will get errors when you open them in firefox.
    To use the following what you do is "Cut" the part you want to be on all pages out, "Paste" it into a seperate document and in its place on your page you put one of the following suitable tags.
    You will also have to rename your main file to .php or .cfm as opposed to .html
    Again, whatever page you put one of these tags on, their extention must change match the type of tag used.
    First Method (PHP):
    PHP is the more common method -
    <?php @ require_once ("yourMenu.html"); ?>
    Require_once is basically a safeguard so that you don't add the menu twice onto a page.
    This will only work for PHP 4+
    This method would work for older versions of php too -
    <?php @ include("yourMenu.html"); ?>
    Second Method (ColdFusion):
    This will only work if your host has ColdFusion installled -
    <cfinclude template="bla.html">
    eg index.html
    <html>
    <head>
    <title>Stuff</title>
    <head>
    <body>
    <?php @ require_once("SpryMenu.html"); ?>
    </body>
    </html>
    SpryMenu.html
    <ul id="menubar1" class="MenuBarHorizontal">
        <li><a class="MenuBarItemSubmenu" href="#">Item 1</a>
            <ul>
                <li><a href="#">Item 1.1</a></li>
    </ul>

  • How to make a rasterized word look like it was written with dirt?

    Im trying to make an image where this word looks like it is written in dirt on the sidewalk.  Iv' already taken a pile of dirt and created a clip mask out of it but it doesnt look natural enough.  How do I do this so it looks realistic? And this is a graphic not font and I am using photoshop cs6. Thank you.

    I'll just add a little footnote to the above, while I'm thinking about it.  One problem with layer styles - especially complex ones like Bevel & Emboss, is that you have limited control of the different aspects of the effect.  I didn't use Bevel & Emboss in the above example because the highlights were too strong, and made it look wrong.
    A way round this is to right click the effect and choose 'Create layers'.  This breaks up the effect into one or more layers, so you can reduce, say, the highlight without effecting the shadow.
    I think if I was trying to do a stand out job, I'd use a finer font, so it looked like it had been drawn with a stick, and I'd use a combination of Bevel and Emboss layer style to get the depth, but I'd also use JJ's idea of a displacement map clipped to the text layer, to roughen the edges realistically, and add texture to the bottom of the indented text.
    An alternative is to find a suitable texture, and save it as a Pattern.  That would make it available to use as a 'Texture' in the Bevel Emboss sub options. The beauty of this is that the texture works very much like a Displacement map with depth and lighting effects.  In fact, I think that might be the easiest way to go about it.

  • How to use single ant build script to package the application with and without native extensions

    Hi,
    I am using iOS native extensions for Adobe air. For this I am listing the extensions in the application descriptor file. Since the package with native extensions are meant to run only on device, I want my build script to work without native extensions too to be able to run on simulator. Is this manadatory that I need two separate application descriptors/basically two build scripts to compile and package them? Please suggest and let me know if more explanation is needed.
    Thanks,
    Swathi.

    Hi
    This is a known issue addressed by CR205204
    As you said, IBM actually does not have rt.jar in its JDK - they have moved contents of rt.jar into various jars.
    IBM is not using org/apache/crimson/tree/ in their JDK at all.So the error shows up in the end of build even if it succeeds
    You may need to add crimson.jar to wlwBuild classpath, since it is not part of IBMs JDK.
    Note: the build will work even w/o crimson.jar giving a non build related IDE exception in the very end.
    Thanks
    Vimala

  • How to make Hibernate's Open Session In View Pattern work with Portal?

    I have a need to implement Hibernate's "Open Session In View" pattern in Portal's Page Flow and its JSP (View).
    Traditionaly, this can be done via a servlet filter, have the filter open the session and close the session, all the Page Flow action and JSP are inside the window between session open and close. For non-portal env, a single HttpRequest maps to only one Page Flow, this approach works.
    But for WebLogic Portal, a HttpRequest might trigger a Portal page to render multiple Portlets, each Portlet has its own Page Flow. Using this filter approach might force all Page Flow to share one open Hibernate Session, not we desired.
    So in WebLogic Portal, how can I manage the Hibernate Session life cycle so that Page Flow action and JSP can share one opened Hibernate Session?
    JZ

    Nevermind. Did a little searching and someone else explained that you have to add these items like they are toolbar buttons. Only then is there anything to drag. Someone please tell the developers at FF that they are idiots and to please fix the status bar before everyone jumps ship on them. This is ridiculous.

  • How to make spry menubar top level only appear for browsers with java turned off

    I was under the impression that just the top level of the horizontal spry menubar appears when someone with Java turned off views it...now I see that the entire unordered list appears vertically and takes up the whole page....is there a way to make just the top level menubar items appear when java is turned off in viewers browser?
    Thank you in advance for any insight you can provide.
    Lois

    When you disable Javascript in your browser...and it is Javascript not Java... if your menubar is properly constructed, the submenus do not appear, only the top level menu items.
    It sounds to me as if you are turning off style rendering in Dreamweaver itself, or have not properly linked your CSS stylesheet to your page.
    When CSS is linked properly, the submenus are "hidden" with left: -10000px; (a BIG distance) offscreen to the left of the Viewport. They stay there unless Javascript is turned on. It is Javascript that "calls them back" onto the Viewport.
    Give me a link, Lois, and I'll check into your page for you...
    Beth

  • How to make bonjour working on windows 7 to discover devices with ipv6 only?

    I am working on a project with Windows 7 which discovers some devices with both ipv4 and ipv6. I have tried bonjour sdk which is very convenient, however I don't know if that support ipv6 as I see nothing ipv6 mdns request from wireshark. Does anyone know how to configure it to let it work?

    >   * explorer.exe is blocked already, but users are able to enter the
    >     Windows Explorer by clicking on the name which is visible on the
    >     Start Menu.
    You cannot block explorer.exe when you do not replace the shell - the
    desktop you see effectively IS explorer.exe...
    Your requirement sounds like you need a custom shell:
    http://gpsearch.azurewebsites.net/#2812
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • How to make change in Issue list across all project sites?

    Hi,
    We all have issue list in our project sites. We need to add some values to some of the columns in that issue list. The requirement is we need these changes to reflect in all the new sites. Also how to make these changes reflect in current existing sites.
    Can anybody suggest a way to achieve this. One thing that i am aware of is creating a new project site template and associating it with EPT but that still not solves the issue for preexisting sites.
    Please help asap.
    Thanks in advance.

    Hi SpWrk
    If you have already created some sites. You would need to apply these changes either Programetically (Powershell or C#) or Manually.
    However, you can take the following approach to avoid this problem in future. (i.e. Your "future" changes will appear in existing sites too). I am writing the procedure breifly but let me know if you need more details on this
    1) Create a content type (e.g. "Project issues" at PWA level)
    2) Associate this content type with the Issues List in your site template as well any existing project sites. Make it a default content type for Issue lists. save your site template
    3) Create all your custom columns in this new Content type (changing OOB issue columns can break your reporting)
    4) Your changes to content type should reflect in future sites as well as existing sites (whereever the content type was appiled)
    Regards
    Hammad Arif EPM Advice Blog

  • How to make a call  to service from site studio templates?

    Hi,
    May be this is very basic but I am not able to figure out how to make a call to a service from site studio templates (hcsp). I have seen one example of service call in the dynamic list fragment. It makes a call to SS_GET_SEARCH_RESULTS service using executeService() method. But it doesn't take any parameters and also not very how returned results are captured.
    I want to execute WCM_PLACEHOLDER service. It takes 2 main parameters dataFileDocName and templateDocName. The returned result is typically a html response.
    The service typically is executed using http request and the url would be something like this
    http://hd-pratapm/ucm/idcplg?IdcService=WCM_PLACEHOLDER&dataFileDocName=VIRTUSAINC&templateDocName=DETAILS_REGION_TEMPLATE
    I think SS_GET_SEARCH_RESULTS service works in the similar fashion. I want to execute WCM_PLACEHOLDER service too using executeService() method. How to work with this? How can we pass parameters and capture returned results?
    Regards,
    Pratap

    Hey Pratap,
    If you are on a standard Site Studio template (page or subtemplate) you should be able to call the wcmPlaceholder idoc function directly. In fact calling the idoc function provides a lot more functionality then the service call (they locked down a few things in the service call since it is designed to be called from an external application).
    The idoc call would look something like: <!--$wcmPlaceholder("Sales", "placeholderDefinitionDocName=placedef_salescontact")--> (taken from page 208 in this doc: http://download.oracle.com/docs/cd/E10316_01/SiteStudio/10gr4/Pdf/Site_Studio_10gR4_Designer_Guide.pdf)
    As a general note when you are in idoc script and want to execute a service you call <$executeService()$> as you saw in the dynamic list. The parameters that the service runs on are in the data binder of the current request. To set parameters for an execute service you simply set idoc variables on the page before it. Example:
    <!--$QueryText="dDocType <matches> `Document`" -->
    <!--$executeService("GET_SEARCH_RESULTS")-->
    As for the response when you execute an idoc function, like wcmPlaceholder, that returns a String the response is immediately output to the page in the location you called the function. This would be similar in concept to a jsp scriptlet that outputs a string <%=myResponseString%>
    Hope that helps,
    Andy Weaver - Senior Software Consultant
    Fishbowl Solutions < http://www.fishbowlsolutions.com?WT.mc_id=L_Oracle_Consulting_amw_OTN_ECM >
    Edited by: Andy Weaver on Jul 7, 2010 7:59 AM
    Added response detail.

Maybe you are looking for

  • Why final cut express wont read my avi file?

    Hi all. I am currently expreience some problem. Few days ago, i was shooting a video project with my D3s. My D3s shoots in AVI format. yet i dont know why the final cut express and the quick time only able to play and edit the avi file with sound? an

  • Output to P2 cards on Panasonic HVX 200

    When I print to video using the DVC Pro HD Firewire to a Panasonic HVX 200, the audio goes into mono mode, even though the original file is in stereo. I have a big presentation to more than 400 on Friday. Any thoughts about how to fix this? Here's wh

  • Archive log mode

    Hi i m using oracle 10gR2 after installation i enable the archive log mode. 1) How can i determine the size of archive log? 2)When i enable the archive log mode after switch it genrate the second archive (01_MF_1_2_43.ARC) instead of first (01_MF_1_1

  • Is it possible to do best fit line in chart in numbers

    is it possible to do best fit line in chart in numbers

  • Placing files from Photoshop and Illustrator to InDesign

    I made a box in Illustrator and Extruded and Beveled it. When I placed it to InDesgin it had lines all around the outside of the box. I also made some circuit looking lines in Illustrator then opened it in Photoshop and Beveled and Embossed it, when