VPN connectivity strange issue



I hope that this is the right group for this question. It really has
me baffled. I have 13 or so sites and a central site running hardware
based VPNs. The central site is a CISCO 1800 series router and each
remote site has a 871 series router. Each site is running EIGRP is
running centrally so that we can hit any IP address from any other
site. It has been primarily set up in order to allow centralized
monitoring and accounting as well as easing printing capabilities for
Terminal Service clients. This architecture will probably stay in
place for another year while we move from standard T1 circuits to a
full MPLS network provided by the host of our central site. The
problem I am having involves 3 of these remote sites. One has a
database application running on Win 2K server. It is also acting as
the terminal server, license server and print server for a single user
at each of the other 2 sites (and 8 local users). The site with the
server (192.168.129.xxx) has printers mapped to each of the other 2
sites (192.168.3.xxx and 192.168.9.xxx) so that they can print from
RDP session. The problem is that everything will be running great and
then just out of the blue, sometimes 4 times a week, a single IP
address becomes unreachable. If I change the IP address workstation
the user can RDP to the private address of the server. If I change
the IP address of the user's printer and the printer port on the
server to reflect that communication is restored. Also, if I put a
static NAT translation (public to private) in place and change the RDP
info to hit the public address the workstation can connect. This
doesn't work when the printer communication is failed though for
obvious reasons.

Example: User 1 with IP address of 192.168.3.33 is connecting through
terminal services to server with IP address of 192.168.129.6 which is
mapped to printer with IP address of 192.168.3.21. Suddenly the
connection to the server will drop and nothing on the 192.168.129.xxx
network (or any other remote site network) can ping 192.168.3.33
address. IP scan turns up dead host on that network as well.
However, if I log into any device on the 192.168.3.xxx network I can
ping 192.168.3.33 address. If I change the IP address of the
192.168.3.33 host to any other address (Assigned DHCP or Statically)
all communication comes up as before. Also, if the user leaves for
the day and comes back in the morning all communication is up as
usual.
.



Relevant Pages

  • RE: Build Solution from network share in VS2005 wont work - please he
    ... So the problem seems due to the file share communication between your WIN ... 2003 server and WIN XP work station (dev box). ... Build Solution from network share in VS2005 won't work - please ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Network transactions not allowed
    ... "No Authentication Required" means that the MSDTC communication on the ... Microsoft Online Partner Support ... Subject: Network transactions not allowed ... The computer with SQL Server 2005 is running in domain A, ...
    (microsoft.public.sqlserver.connect)
  • Re: The Future of Backing Up & Drobo-like Technologies
    ... I can't imagine returning to a wired network. ... When we moved in a couple years ago we had to have a lot of work done, so I hired an electrician to run CAT6 throughout the house with everything going to a closet (that had been a wet bar. ... The other is a server for everything else on the internal network, but it's not doing file serving, though I have plans for it being a MySQL or Postgres server and also a web and chat proxy when my daughter gets old enough that I'll want to openly snoop on her activity.Anyway, I've got these two servers. ... That is, I'm only interested in the two way communication, so I would like her to feel free to visit and read websites free from me or my wife snooping. ...
    (comp.sys.mac.system)
  • C4 Security Advisory - ABB PCU400 4.4-4.6 Remote Buffer Overflow
    ... Process Communication Unit 400 forms the communication interface to the network of remote terminal units together with the RCS Application Software located in the application server of a Network Manager SCADA system. ... The description of the vulnerability is intentionally limited as this software controls critical national infrastructure. ...
    (Bugtraq)
  • Re: Satellite Branch Office Woes
    ... point of a "satellite branch office" is to provide Directory and all other ... services from the central site, "eliminating the need for costly server ... DNS and DHCP. ... If no server at the site, can you get a T1 to the site instead of a DSL? ...
    (microsoft.public.windows.server.active_directory)