RRAS between 2 servers

Hey
we have 2 VPS servers with a single WAN NIC. (each server has its own public ip)
DC01 is the domain controller
TS01 is a terminal server currently working in a workgroup
i installed the RRAS server on both of the devices and created a new domain user with dial in permissions.
configured the ipv4 settings on dc01
on the TS01 i created a new connection and for the start i choose PPTP
when i create a connection from the network and sharing center everything works fine 
however when i use the RRAS console with exact the same settings i got a error
Server side >
Log Name:      System
Source:        RemoteAccess
Date:          12/23/2014 10:20:55 PM
Event ID:      20253
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      DC01.Domain.com
Description:
RoutingDomainID- {00000000-0000-0000-0000-000000000000}: CoId={3XXXXXXX64}: The user DOMAIN\user connected to port VPN3-126 has been disconnected because no network protocols were successfully negotiated.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="RemoteAccess" />
    <EventID Qualifiers="0">20253</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-12-23T21:20:55.000000000Z" />
    <EventRecordID>15381</EventRecordID>
    <Channel>System</Channel>
    <Computer>dc01.DOMAIN</Computer>
    <Security />
  </System>
  <EventData>
    <Data></Data>
    <Data></Data>
    <Data>DOMAIN\USER</Data>
    <Data>VPN3-126</Data>
  </EventData>
</Event>
ON the client
The user SYSTEM dialed a connection named DC01 which has failed. The error code returned on failure is 720.
how is it possible that the network and sharing center vpn works and the RRAS client not?

I had some time to install a testlab
I use vmware (but it should be exact the same on HyperV)
First i created a new virtual switch with no connections at all
Then i create 2 servers and attach them to the virtual switch
TestL1
IP: 1.1.1.1
Windows server 2012 evaluation version
remote access>RAS & Routing
Secure connection betwean two private networks
Demand dail > Yes
Ip > specific pool
10.0.0.1 - 10.0.0.100
Error opening ports in firewall
disable the windows firewall
New connection wizzard appears
Connection name TestL2
Type: VPN
ip: 1.1.1.2
VPN:PPTP
Route IP package to this interface
10.0.1.0 255.255.255.0 Metric 5
Dial-out credentials: administrator (no domain)
Reboot
TestL2
IP: 1.1.1.2
Windows server 2012 evaluation version
remote access>RAS & Routing
Secure connection betwean two private networks
Demand dail > Yes
Ip > specific pool
10.0.1.1 - 10.0.1.100
Error opening ports in firewall
disable the windows firewall
New connection wizzard appears
Connection name TestL1
Type: VPN
ip: 1.1.1.1
VPN:PPTP
Route IP package to this interface
10.0.0.0 255.255.255.0 Metric 5
Dial-out credentials: administrator (no domain)
Reboot
After the reboot i noticed that non of the servers accept the RAS connection
Go to settings and check IPv4 Remote access server
goto ports > pptp >check Remote access connection (inbound only)
This are brand new installations without any group policy's and not joined to the domain
the only software installed is vmware tools

Similar Messages

  • Communication between servers on different FIs

    Just want to verify communication between UCS servers on same chassis but having active vNICs on different FIs (Diagram attached). I suppose all commuication between server-A & server-B will happen through Layer 2 switch as server-A will generate an ARP request for Server-B, that will be passed over to FI-A and then to L2 switch down to FI-B, where server-B will respond back with it's MAC that will then be passed to Server-A via FI-B to L2 switch to FI-A.I don't expect any traffic between servers A & B be routed via firewall? Is there anything I need to be careful about in this design? Going forward we will have multiple subinterfaces on the firewall for different VLANs and all servers will use Firewall as default gateway.

    you may want to look at the throughput of your firewall for server-server traffic in different VLANs. If your L2 switch is 10G but your firewall is only 1G then you could have a potential bottle neck.

  • Copy file between servers, passing on firewall

    I'm try copy a file between servers with Windows NT. I mapping the target server to drive X and test copying a file in windows explorer and command window and the files copy is OK. But if I try with a java class don't.
    I'm try with FileInputStream (read) and FileOutputStream (write) but don't. I have use the Runtime.exec() for execute a DOS command but don't("cmd.exe /c copy c:\myfile.txt x:\"). this second showme a message "username incorrect or bad password", but the same sentence I run in a command window and the copy is OK!
    What can I do?

    Hi,
    try to use HTTP for the transfer between
    the two servers. Normally You can pass the
    firewall using HTTP (like browsers do).
    Therefor use classes in the java.net packages.
    CU,
    Mathias

  • Distributed File System Replication between servers with different performance

    If Distributed File System Replication is set between servers with different performance. What will happen with the performance of the fastest server? Will the performance decrease to match the performance of the
    slowest server in the chain? I mean, will the source slow down (processor speed) if the recipients can't keep up? 

    Hi,
    If you mix different performance server for DFS replication, most of improvements on the fastest server are disabled for backwards compatibility and the performance decrease to match the performance of the slowest server.
    For more detailed information, please refer to the article below:
    Tuning replication performance in DFSR (especially on Win2008 R2)
    http://blogs.technet.com/b/askds/archive/2010/03/31/tuning-replication-performance-in-dfsr-especially-on-win2008-r2.aspx
    Best Regards,
    Mandy 
    If you have any feedback on our support, please click
    here .
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Message between servers

    Hi,
    I am new to this JMS, after reading online and a sample application I got an idea how to configure JMS with resin and Jboss.
    My question now is, how to send and receive messages between servers ? I have created some sample applications and just sent and received messages within the same server.
    How can we achieve sending messages across servers ?
    Thanks in advance.
    ~ SK

    Hi Elad,
    We did XI-XI communictions a bit different, we approached it as a B2B scenario. We defined a Party for the sending XI system and we created an abstract interface with the Idoc messagetype (because you need on both sides the same interface name/namespace and we use naming conventions).
    In the receiver agreement of the sending XI system you have to replace the party and service name with the ones you have did setup on the receiving XI.
    I hope this helps you in the right directions
    Cheers,
    Frank

  • Fire walls between servers..

    Hi All,
    1. Is there any way to find firewalls (i.e. number of firewalls and their name or any other identification) between two servers.
    2. How to find ports whether the are opened in the fire wall. Telnet is disabled for our servers. Is there any way to find this.
    Thanks in advance,
    DJ.

    telnet: connect to address 10.4.149.241: Connection refused
    Can I conclude the port is not opened from the above result ?Possible conclusions:
    1. There is no service running on pser2j.bts.org at 55000 port number
    2. FW1 returns connection refused (blocking connection)
    2. FW2 returns connection refused (blocking connection)
    Is there any way to find which firewall is creating the problem?Of course there is.
    1. Clean, quick and best: ask the FW administrator whether connection is allowed (also FW administrator could check FW logs for all information about connection)
    2. Only for users with good understanding of TCP/IP: you could compare TTL of SYN packet with TTL of RST packet (firewall decrements TTL)
    Note this method is not alwas usefull and in such case you need use other methods.

  • Inability to questioning CUBE when you move it between servers.

    Hello everyone ,
    I  having a problem in the transition between given source cube questioning about USER and ADMIN , and my backup cube to which I refer clients while
    that I make the process of the original cube . In switching between user settings ( impersonate ) to ADMIN I can not make multiple choice questioning of the cube . However on another server I can retrieve data and perform multiple selection at the level of
    sub-category . Cube has been copied from the server where I could drill it to the server has problems making multiple selection mode impersonate . The difference between the servers is mainly at the level of the update , this is where a problem is the level
    of update 10.50.4000.0 (SP2 ) . And a server without a problem level of the update is 10.50.2789.0 . Servers are 2008R2 servers . I think this involves different authorizations at the grand, Does anyone have a different direction or idea what to do, To allow
    my clients to continue working at the same level of questioning without restrictions . Thank's Doron

    Thank's a lot!
    The only difference is the transition from the server to the server, basically it's the same cube of the same customer during all weekend passes to backup to another server .
    So far not been a problem as well as during all started a week all customers move to the BKP cubes until we Process the new cubes and current customers.
    The test was opening two windows of Visual Studio 2008 and trying to slice the data at the level of sub-category, the same cube which is server A and server B for that matter (the cube
    was duplicated using a process of BKP & RESTORE and made the experience of SCRIPT CREATE) server A can perform impersonate with details using a random customer and making the slice and get the data.
    Replication of the cube, case B we get the data only when we connect the cube as ADMIN, the version of the build server B is 10.50.4000.0.
    It is important to note the attempt to 've run on a third server C for with characteristics identical as well as same build version ( 10.50.2789.0 ) was again possible to drill with
    Multiple selection  at all sub Category disorder when done impersonate .
    In light of all the above tests , we assumed that there is a different permission level server settings or something that is not related to the structure and definitions cube itself
    as the third server as a control we had no problem despite simulation the case accurately.
    It is important to note that the customers are querying the cube through an additional server configured as PAMORAMA , when we got back we realized slowly disappearing weekly data interrogation
    at customers moving into cubes backup .
    Throughout all the process was not an error As if we did not make multiple selection data were presented in every case and in every server.

  • Copy appsets between servers

    Hi guys,
    I will shortly have to copy an appset between two servers, and the data also.
    Please could someone give me a definitive list (Warning: newbie alert!) of what exactly I need to move?
    I know I need to backup the appset using Server Manager from the original machine, and Restore it using Server Manager on the new machine, but what if the drive mappings are different between my old (dev) server and my new (live) one?
    Presumably, I can backup, move and restore my database too? Or is it not that easy??
    Like I said, this is new to me, so I just want to make 100% I don't forget anything!
    Thanks folks, I appreciate your help.
    Best wishes,
    Jason

    Dear Jason Maidment,
    It's only way to copy appset between server using Server Manager. You right to backup Appset from original machine and restore in new machine. If you restore Appset using Server Manager, SAP BPC will automaticlly restore files, database, and OLAP. I've tried to restore Appset in new machine which the drive mapping is different from original machine and I never get something error.
    I hope my information can uses for you.
    Thanks,
    Wandi

  • Migrating MW between servers?

    Hi,
    does anyone have any experience of cloning an instance of Maintenance Wizard?
    I wish to move my MW between two servers and wanted to know what steps I would need to follow in addition to the usual ones involved in cloning a a database?
    Many Thanks.

    From the setup.sh script under the config directory there is the section of the script that has the line
    ${ORACLE_HOME}/bin/sqlplus -s /nolog << EOT >> ./replace_xdb_homepage$$.log
    I ran just this bit of the shell script to change the hostname.
    Also because my oracle home was different I had to change a number of directories in the database. See dba_directories And grant java permissions on the different directories, see dba_java_policy

  • Correct tool for my purpose of data movement between servers

    Hello All,
    I am in the process of trying to copying over data from source sql server table to destination sql server table. The requirements being, only the new or updated data needs to be migrated to destination table, once a week. Our source table has 23 million
    rows and growing. 
    I researched two different solutions and would like to know if anyone has feedback on these. 
    1. Merge - used to sync data between source and destination table using SSIS packahe. But the problem for this according to my research, with the amount of data in consideration, the transactional log will grow by leaps and bounds. Not the way.
    2. Replication - I have started my research in this matter. Would this be an ideal solution? 
    Many thanks.

    Transactional replication is the best fit here. You should be able to get near real time synchronizations between your source and destination servers IF you have a pk on the table you are replicating.
    If your skill set is with SSIS the merge component will also work.
    If you backup your tlog every 20 minutes or so, your tlog will be maintained and you should not see explosive growth.
    Note that both the SSIS merge component and transactional replication will lead to large tlog growths unless you maintain your tlog.
    looking for a book on SQL Server 2008 Administration?
    http://www.amazon.com/Microsoft-Server-2008-Management-Administration/dp/067233044X looking for a book on SQL Server 2008 Full-Text Search?
    http://www.amazon.com/Pro-Full-Text-Search-Server-2008/dp/1430215941

  • How to Communicate between servers and Overwrite the file

    Hi,
    I have this application where in a config file is modified as per the data entered by the user through some jsps.
    Also, this application is also loaded on other server which may act as backup when the primary goes down.
    Now,my issue is:
    As soon as the file is modified i want to overwrite all the backup files on other backup servers, so that sync is maintained between all the files on all servers.
    i guess the communication between primary & backup servers could be done using RMI.
    I have gone through RMI tutorial & few examples on RMI but i'm not very clear where exactly the interface,impl and client program goes.
    i mean how does this actually work in a real time.
    Please could anybody shed some light on this.I would really appreciate.
    Thanks!

    Hi all can some one please give a solution ...Any suggestions would be greatly appreciated

  • Replicating the Cubes between servers without partitioning

    Guys,
    Anyone has any ideas on how to automate the replcation of the cubes between 2 servers. I am planning to Export the data (size is 2 GB) from one server and import it another server which is straight forward. But how can I replciate the Outline too. Partitioning will not work for us as the servers have 2 diferent versions of Essbase
    Any suggestions are appreciated.
    Thanks,
    Mikki

    Hi Mikki,
    It sounds like you are comparing the index/page file size to the size of an export.
    If the export is not a binary export and is human readable it will be quite a bit larger than your index/page file size due to several reasons:
    1) No compression
    2) Each member name is explicitly spelled out. When the data is in the cube the member names will be binary data and even though a new cell is added the overhead of the name of the member is a part of what the cube gives you as a part of it's design by Oracle.
    Now if you compress the output you will see that zip or other archive formats will make that 40 GB quite a bit smaller.
    Regards,
    John A. Booth
    http://www.metavero.com

  • Connections between servers using CSS VIP?

    In our new pre-production environment we have several servers connected to a 3750 switch, which is then connected to a CSS 11503. Upstream the CSS is then connected to an ASA firewall pair. The CSS VIPs are 10.22.1.0/24 on the "outside" and the servers have 10.21.1.0/24 addresses on the inside. The CSS inside & server 3750 switchports are all on the same VLAN. There is no PAT/NAT configured (except for the VIP being translated to a chosen server IP I suppose).
    Whilst the clients will connect to the servers via the VIPs what we want is for each server to also be able to talk to other servers via a VIP. This is because some of the servers provide a service (LDAP actually) that we would like to be load balanced.
    Now, what is curious, is that *this works* in our production environment where the servers are *directly* attached to the 8 port switch module in the CSS. However in this new environment, where the 3750 is between the servers and the CSS, it doesn't (actually you can ping the VIP sucessfully but nothing else works).
    I have seen other postings on NetPro where people are trying similar things, like: http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Networking%20Solutions&topic=Application%20Networking&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1dd81312 and http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Emerging%20Technologies&topic=Content%20Networking&CommCmd=MB?cmd=display_location&location=.1dd72fd0
    The relevant CSS config I think (there are lots more services etc but they are all similar) is:
    circuit VLAN1
    ip address 10.21.1.100 255.255.255.0
    circuit VLAN2
    ip address 10.22.1.1 255.255.255.0
    keep alive ssokeepalive
    type http
    keepalive port 7777
    uri "/sso/status"
    keepalive frequency 10
    keepalive maxfailure 2
    tcp-close fin
    active
    service pulpldp001sso
    ip address 10.21.1.6
    keepalive type named ssokeepalive
    active
    content SSO
    vip address 10.22.1.12
    protocol tcp
    port 7777
    application http
    url "/*"
    advanced-balance cookie
    add service pulldp001
    active
    i.e. VIP 10.22.1.12 will be directed to the server 10.21.1.6 (only the one shown above).
    Q1) My first question is: is server to server communication via an outside VIP possible?!
    Q2) Given that this seems to work our production environment without the 3750s any idea what areas of config could be wrong on the 3750 or the servers? (we've tried default routes of both the 3750 and the ISS inside address but that hasn't worked). Note the ping from a server works but when we try, say, "telnet 10.22.1.12 7777" that doesn't connect.
    Q3) Let's assume that the servers run more than one service, e.g. an HTTP and an LDAP service. If a server can communicate with another server using its VIP, will it work from one server up to the CSS/VIP and back to itself? (of course it may or may not actually return to itself depending on the load etc)
    I can provide full configs on Monday if required.
    Hope these aren't dumb questions! Many thanks!
    Simon
    PS. the CSS is running 7.50 at the moment but could upgrade to 8.2 if required

    Thank you Adedayo - that appears to have done the trick! I can't believe it: one little keyword!
    I have to say, even once you told me the answer I still didn't find the Cisco content config manual very helpful on this point (perhaps I'm looking in the wrong place?).
    Note: we're not currently doing any PAT on the CSS so don't have any source groups set up - perhaps most people do and so don't have the same problem.
    I'll get chance to report back on some proper testing next week and promise to update this conversation.
    Adedayo: sorry, I wanted to flag your post as solving my problem once I was sure next week but now the tick box has gone - if you reply again I'll flag that! I appreciate you taking the trouble to post.
    One final question: do you have a situation where you use a VIP from a server to potentially connect back to itself? If so, does it work OK? (e.g. if you have a webserver can you connect to the content VIP that it belongs to?)
    Simon

  • Crossover cable between Servers - routing traffic

    Can someone help me out please.
    I have two servers of which oracle is on one and colfusion on
    the other. Data cf requests is coming from a public network. Each
    is part of a workgroup. I want the traffic to be routed through a
    crossover cable which is not the primary connection.
    Server1 - Coldfusion 7 installed. CF Application installed.
    Server2 - Oracle database installed. CF Application accessing
    this server.
    Server 1 and 2 have a LAN connection and also a crossover
    cable.
    The ip addresses are as follows:
    Server2: Oracle Public 111.1.1.1
    Server2: Cross-Over 222.22.22.3
    Server1:Coldfusion: Public 111.1.1.2
    Server1: Cross-Over 222.22.22.4
    There is an Oracle CF data source pointing to Server2
    How do I get coldfusion to route its' requests from server2
    via the crossover cable.
    Currently the LAN public connection is the primary route
    between both servers althought the cross over cable has been
    connected.
    Is what I am asking possible?
    JIM

    Oracle, which is on server2 is binded with the ip address of
    Server2: Oracle Public 111.1.1.1
    when creating the tns service name.
    I create the system dsn using the ODBC Data source
    Administrator and this picks the tns service name which is binded
    with the ip address Oracle Public 111.1.1.1.
    When creating the coldfusion data source traffic is directed
    through the public route because Oracle is binded with the server
    ip address.
    If there was a way I could get Oracle to bind the service
    name with the crossover ip then my problem would be solved I think.
    Would anyone have any ideas?
    There is no

  • Best practices for sharing a SAN-attached tape loader between servers.

    When configuring zones to allow a tape loader to be shared by multiple servers, is there a preferred zoning method?
    For instance, I have my primary fabric configured so that the zone for each data server using a LUN on my array consists of the primary port of the HBA on the server and the primary port of the HBA for each controller on my array.
    My backup server does not use any LUNs on the array, so its zone consists solely of its primary HBA port and the HBA port of the tape loader.
    If I want give my data servers access to the tape loader, should I add the tape loader's port to the zone of each server, or should I add the port of each server to the zone that currently consists of only the backup server and the tape loader?
    Or does it matter?
    The network is small:
    One Windows server dedicated to backup, three NetWare servers handling data storage and 12 other VM servers running a mixture of Linux, NetWare, and Windows that handle various services but don't contain any significant amounts of data.
    My intent is to give the 3 data servers access to the tape loader directly, so that their backup streams don't involve the LAN.
    The remaining servers are small enough that backing them up over the LAN is not an issue.
    I doubt that it matters for this, but the SAN switches are MDS9124's and the SAN array is an HDS AMS2100 with active/active controllers.
    All server HBA's are dual port, as are the HBA's on each array controller.
    In addition to the primary zone, each server and the array controllers are attached to a failover zone via the 2nd port of the HBA's.
    Unfortunately, my backup software doesn't support NDMP, so I can't back up the array LUN's directly to the tape loader.

    NDMP is for backing up NAS platforms.
    Does your backup software support "LAN-Free" backup ? Typically enterprise backup software like Netbackup, TSM, Networker require a special license/agent that gets loaded on server where you are going to implement LAN-Free backups. Without that software/license servers will be fighting for tape resources and it will be a mess (if it works at all). Also you want to use dedicated HBA or port on dual HBA for tape traffic, do not mix tape and disk traffic on the same HBA/port. In big shops people configure dedicated "tape" VSANs but that would be an overkill for your current environment.
    @dynamoxxx

Maybe you are looking for

  • How can I count the total number of keyframes in a project in After effects?

    I would just like to know how to get the quantity of how many keyframes I have in my project. I've always thought counting keyframes is pretty interesting xD

  • Connecting Apple AE to a Dell D600 laptop

    How do we connect an Apple Airport Express (AE) to a Dell D600 (laptop)?? After spending 2 frustrating hours trying to set it up, nothing but a blinking amber light!! We just want to connect it so we can listen to iTunes on our stereo. The Airport Ut

  • Storage space question

    I am recieving messages that my storage space is maxed out.  I bought an external hard drive and connected that to the My Mac, and copied the files. What should I do next?

  • Can't set WEP security, why?

    I have a Belkin 54mb Airport Card (seen in Profiler as Airport Extreme) in my Mac running OSX 10.4.8. The card works fine with my Netgear DG834G modem/router but I can't set the security option. I set the password in the 'Wireless Settings' page re-s

  • Is there or will there soon be the ability for iPad to password protect email app

    Is there or will there soon be the ability for iPad to password protect email app?  When I share my iPad with my kids, I have to simply trust they don't use my email.  When will Apple program the standard email app to be password protected?  This is