<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Unable to ping the tunnel address of a Demand Dial Connection on Windows Server 2008 RRAS</title><link>http://blogs.technet.com/b/networking/archive/2008/11/07/unable-to-ping-the-tunnel-address-of-a-demand-dial-connection-on-windows-server-2008-rras.aspx</link><description>Problem Description When a demand dial connection is setup between two RRAS servers each server receives an address from the pool of available addresses located on the server it is connecting to. When Server 2003 servers are used on both ends of the demand</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Unable to ping the tunnel address of a Demand Dial Connection on Windows Server 2008 RRAS</title><link>http://blogs.technet.com/b/networking/archive/2008/11/07/unable-to-ping-the-tunnel-address-of-a-demand-dial-connection-on-windows-server-2008-rras.aspx#3309482</link><pubDate>Sat, 30 Jan 2010 05:23:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3309482</guid><dc:creator>Ben Benson</dc:creator><description>&lt;p&gt;Thank you very much for the solution. It is the only one I have found. We have 12 Windows 2003 vpn servers and there is a need to upgrade the hardware as well as the OS. This solution will allow us to do that within our budget.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3309482" width="1" height="1"&gt;</description></item><item><title>re: Unable to ping the tunnel address of a Demand Dial Connection on Windows Server 2008 RRAS</title><link>http://blogs.technet.com/b/networking/archive/2008/11/07/unable-to-ping-the-tunnel-address-of-a-demand-dial-connection-on-windows-server-2008-rras.aspx#3297128</link><pubDate>Mon, 30 Nov 2009 09:51:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3297128</guid><dc:creator>Jon Redwood</dc:creator><description>&lt;p&gt;SBS setup wizard disables the second NIC as an unsupport senario, How's that for logic!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3297128" width="1" height="1"&gt;</description></item><item><title>re: Unable to ping the tunnel address of a Demand Dial Connection on Windows Server 2008 RRAS</title><link>http://blogs.technet.com/b/networking/archive/2008/11/07/unable-to-ping-the-tunnel-address-of-a-demand-dial-connection-on-windows-server-2008-rras.aspx#3194025</link><pubDate>Thu, 29 Jan 2009 02:43:44 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3194025</guid><dc:creator>peterdoo</dc:creator><description>&lt;p&gt;The explanation for the reason why the route should not be added automatically by Windows 2008 (security) is completelly wrong here.&lt;/p&gt;
&lt;p&gt;Using 2 or 1 NICs does not change anything. The problem is not that anybody from corp9.local would like to access the resources on the RRAS1 server (normally nobody even knows the IP that RRAS2 assigns to RRAS1).&lt;/p&gt;
&lt;p&gt;The real problem is that RRAS1 Server itself has to access resources inside corp9.local behind the server RRAS2 (either it has to contact AD servers there, deliver e-mail by SMTP, replicate DFS folder, RDP,...). As soon as that is necessary RRAS1 will always initiate the IP connection to corp9.local subnet using as source IP its IP from corp9.local subnet that was assigned to it by RRAS2. However as RRAS2 has not added the route to that IP nobody from corp9.local can reply to RRAS1. So RRAS1 is not able to contact corp9.local subnet even though it has a route to there available.&lt;/p&gt;
&lt;p&gt;So the &amp;quot;feature&amp;quot; that should prevent using resources on RRAS1 from the other side actually prevents RRAS1 of accessing resources on the other side. What was intended to be prevented is however still possible. Anybody from the other side of DoD connection can access resources on RRAS1 using its normal fixed IP inside of the corp1.local subnet (192.168.1.30 in the example above).&lt;/p&gt;
&lt;p&gt;No security improvement at all but many problems caused.&lt;/p&gt;
&lt;p&gt;This is like saying that nobody will enter into my house through the garden door so I will make the door in the way it will not be possible to enter there. OK, but I like to go out to the garden through that door. Now that the door is shut down for entry, as soon as I go out I can not return into my house anymore.&lt;/p&gt;
&lt;p&gt;I hope that the automatic addition of route can be implemented again. Alternativelly Windows 2008 could be teached to never use the IP assigned by another RRAS server as source IP in TCP/IP communications.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3194025" width="1" height="1"&gt;</description></item><item><title>BlogMS Weekly Articles Published – 3rd November 2008 to 9th November 2008</title><link>http://blogs.technet.com/b/networking/archive/2008/11/07/unable-to-ping-the-tunnel-address-of-a-demand-dial-connection-on-windows-server-2008-rras.aspx#3150348</link><pubDate>Mon, 10 Nov 2008 12:45:46 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3150348</guid><dc:creator>BlogMS - Official Microsoft Team Blogs</dc:creator><description>&lt;p&gt;203 Microsoft Team blogs searched, 88 blogs have new articles in the past 7 days. 252 new articles found&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3150348" width="1" height="1"&gt;</description></item><item><title>Unable to ping the tunnel address of a Demand Dial Connection on Windows Server 2008 RRAS | MS Tech News</title><link>http://blogs.technet.com/b/networking/archive/2008/11/07/unable-to-ping-the-tunnel-address-of-a-demand-dial-connection-on-windows-server-2008-rras.aspx#3149279</link><pubDate>Fri, 07 Nov 2008 20:51:25 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3149279</guid><dc:creator>Unable to ping the tunnel address of a Demand Dial Connection on Windows Server 2008 RRAS | MS Tech News</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://mstechnews.info/2008/11/unable-to-ping-the-tunnel-address-of-a-demand-dial-connection-on-windows-server-2008-rras/"&gt;http://mstechnews.info/2008/11/unable-to-ping-the-tunnel-address-of-a-demand-dial-connection-on-windows-server-2008-rras/&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3149279" width="1" height="1"&gt;</description></item></channel></rss>