Cannot reach/ping second 2019 server via Site-to-Site VPN, all other computers can be reached

%3CLINGO-SUB%20id%3D%22lingo-sub-1868066%22%20slang%3D%22en-US%22%3ECannot%20reach%2Fping%20second%202019%20server%20via%20Site-to-Site%20VPN%2C%20all%20other%20computers%20can%20be%20reached%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1868066%22%20slang%3D%22en-US%22%3E%3CP%3EHi!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20REALLY%20need%20help%20on%20this%20issue!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMain%20office%20has%3A%3C%2FP%3E%3CP%3E192.168.%3CSTRONG%3E1%3C%2FSTRONG%3E.0%2F24%3C%2FP%3E%3CP%3EBranch%20office%3A%3C%2FP%3E%3CP%3E192.168.%3CSTRONG%3E2%3C%2FSTRONG%3E.0%2F24%3C%2FP%3E%3CP%3Ei.e.%20two%20different%20subnets.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDHCP%20is%20configured%20in%20the%20routers%20on%20each%20side%3B%20main%2Fbranch%20(i.e.%20no%20DHCP%20configured%20in%20the%20server).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMain%20office%20has%20two%20Windows%20Server%202019%3A%3C%2FP%3E%3CP%3E1.%20%3CSTRONG%3EMain%20server%3C%2FSTRONG%3E%20with%20AD%2C%20DNS%2C%20DC%3C%2FP%3E%3CP%3E2.%20%3CSTRONG%3EApplication%20server%3C%2FSTRONG%3E%20that%20is%20joined%20to%20domain%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eand%20there%20are%20also%20clients%20in%20the%20main%20office%3A%3C%2FP%3E%3CP%3E3.%20%3CSTRONG%3ENormal%20domain%20connected%20clients%20(Win10%20and%20Win8)%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can%20ping%20forth%20and%20back%20between%20all%20computers%20but%20when%20I%20try%20to%20ping%20from%20Branch%20to%20Main%20office%20towards%20the%20%22%3CSTRONG%3E2.%20Application%20Server%3C%2FSTRONG%3E%22%20I%20don't%20get%20through.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20no%20probem%20to%20ping%20from%20Branch%20to%20%3CSTRONG%3E%221.%20Main%20server%22%3C%2FSTRONG%3E%20or%20towards%20%3CSTRONG%3Enormal%20clients%3C%2FSTRONG%3E%20in%20the%20%22main%20network%22.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20I%20ping%20%22%3CSTRONG%3E2.%20Application%20server%3C%2FSTRONG%3E%22%20from%20any%20local%20computer%20on%20the%20Main%20office%20side%2C%20the%20server%20responds.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CFONT%20color%3D%22%23FF0000%22%3EBasic%20fault%20tracing%20tells%20me%20it's%20a%20server%20configuration%20thing%20versus%20the%20Branch%20network%2C%20something%20in%20the%20%222.%20Application%20server%22%20stops%20the%20calls%2C%20right%3F%3C%2FFONT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20checked%20the%20server's%20firewall%20(incoming%20ping)%20and%20also%20temporarely%26nbsp%3B%20turned%20off%20the%20firewall%2C%20but%20no%20success.%20So%20firewall%20seems%20to%20be%20out%20of%20the%20question.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20also%20added%20the%20branch's%20subnet%20in%20%221.%20Main%20server%22%20under%20AD%20Services%20and%20Sites%2C%20no%20success.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20really%20can't%20understand%20this%20magic%20going%20on%20in%20the%20second%20server%2C%20why%20doesn't%20it%20respond%20to%20calls%20from%20the%20Branch%20side%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20help!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ebr%3C%2FP%3E%3CP%3E%2FMarcus%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1868066%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Eping%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Esite-to-site%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Esubnet%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Evpn%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ewindows%20server%202019%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1868546%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20reach%2Fping%20second%202019%20server%20via%20Site-to-Site%20VPN%2C%20all%20other%20computers%20can%20be%20reached%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1868546%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eit%20is%20really%20interesting.%26nbsp%3BWhat%20was%20the%20error%20message%20during%20the%20ping%20from%20Branch%20office%3F%3C%2FP%3E%3CP%3EWhat%20is%20the%20result%2C%20when%20you%20start%20a%20ping%20from%20App%20server%20to%20Branc%20office%3F%3C%2FP%3E%3CP%3EDid%20you%20add%20static%20route%20rule%20to%20windows%20route%20table%20before%20(maybe%20it%20try%20to%20send%20respond%20on%20wrong%20gateway)%3F%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20mentioned%20already%20tried%20without%20firewall.%20Did%20you%20disabled%20all%20three%20firewall%20profile%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1869173%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20reach%2Fping%20second%202019%20server%20via%20Site-to-Site%20VPN%2C%20all%20other%20computers%20can%20be%20reached%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1869173%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F861813%22%20target%3D%22_blank%22%3E%40TamasKosarszki%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EWhat%20was%20the%20error%20message%20during%20the%20ping%20from%20Branch%20office%3F%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%22Request%20timed%20out.%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EWhat%20is%20the%20result%2C%20when%20you%20start%20a%20ping%20from%20App%20server%20to%20Branc%20office%3F%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EHmm%2C%20I%20might%20have%20missed%20that%20test%20case%20...%20actually%20I%20get%20%22Request%20timed%20out%22%20from%20App%20server%20towards%20Branch%20computer.%3C%2FP%3E%3CP%3EMain%20server%20and%20Win10%20client%20is%20ok%20towards%20Branch%20computer.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EDid%20you%20add%20static%20route%20rule%20to%20windows%20route%20table%20before%20(maybe%20it%20try%20to%20send%20respond%20on%20wrong%20gateway)%3F%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EI%20do%20have%20basic%20skills%20in%20network%2C%20but%20when%20it%20comes%20to%20%22static%20route%20rule%22%2C%20I'm%20kind%20of%20lost.%3C%2FP%3E%3CP%3EI%20really%20don't%20get%20why%20the%20Main%20server%20and%20clients%20works%20but%20this%20single%20server%20don't.%3C%2FP%3E%3CP%3EOne%20finding%20here%20(thanks%20to%20you)%20is%20that%20the%20App%20server%20seems%20to%20be%20dead%20in%20both%20directions%3A%3C%2FP%3E%3CP%3E-%20From%20Branch%20to%20App%20Server%3C%2FP%3E%3CP%3E-%20From%20App%20Server%20to%20Branch%3C%2FP%3E%3CP%3E%22Static%20Route%20rule%22%20can%20you%20guide%20me%20on%20where%20to%20add%20that%3F%3C%2FP%3E%3CP%3EI%20really%20don't%20get%20why%20this%20server%20should%20be%20different%20from%20the%20other%20WS2019%20(Main)%20server%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EYou%20mentioned%20already%20tried%20without%20firewall.%20Did%20you%20disabled%20all%20three%20firewall%20profile%3F%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EYes.%20Tried%20it%20ones%20more%20now.%20Doesn't%20help.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20really%20appreciate%20your%20feedback%20and%20help!%20By%20asking%20questions%20and%20challange%20we%2FI%20might%20find%20the%20issue.%20Right%20now%20I%20have%20Googled%20all%20Internet%20and%20have%20no%20more%20ideas.%20Very%20frustrating%2C%20I%20need%20to%20get%20it%20fixed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3ESummary%3A%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E-%20Site-to-Site%20IPSEC%20VPN%20with%20two%20subnets.%3C%2FP%3E%3CP%3E-%20Branch%20computer%20is%20not%20domain%20connected%2C%20it%20can%20still%20ping%20other%20computers%20in%20Main%20office.%3C%2FP%3E%3CP%3E-%20Branch%20computer%20can%20ping%20both%20Main%20server%20and%20Win%2010%20client...%3C%2FP%3E%3CP%3E-%20...but%20not%20the%20App%20server.%3C%2FP%3E%3CP%3E-%20App%20server%20can%20not%20ping%20Branch%20computer.%3C%2FP%3E%3CP%3E-%20App%20server%20can%20be%20pinged%20locally%20within%20Main%20office%2C%20no%20issues%20as%20long%20as%20the%20VPN%20tunnel%20isn't%20involved.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBig%20thanks%20for%20all%20help%20I%20can%20get!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EEDIT%3A%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EFrom%20Branch%20computer%20I%20can%20ping%20Main%20office%20router%20(LAN%20IP).%3C%2FP%3E%3CP%3EFrom%20App%20server%20I%20%3CU%3Ecannot%3C%2FU%3E%20ping%20router%20(LAN%20IP)%20on%20Branch%20side!%3C%2FP%3E%3CP%3EFrom%20other%20computer%20within%20Main%20office%2C%20I%20can%20ping%20Branch%20router%20(LAN%20IP).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ebr%3C%2FP%3E%3CP%3E%2FMH%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hi!

 

I REALLY need help on this issue!

 

Main office has:

192.168.1.0/24

Branch office:

192.168.2.0/24

i.e. two different subnets.

 

DHCP is configured in the routers on each side; main/branch (i.e. no DHCP configured in the server).

 

Main office has two Windows Server 2019:

1. Main server with AD, DNS, DC

2. Application server that is joined to domain

 

and there are also clients in the main office:

3. Normal domain connected clients (Win10 and Win8)

 

I can ping forth and back between all computers but when I try to ping from Branch to Main office towards the "2. Application Server" I don't get through.

 

I have no probem to ping from Branch to "1. Main server" or towards normal clients in the "main network".

 

If I ping "2. Application server" from any local computer on the Main office side, the server responds.

 

Basic fault tracing tells me it's a server configuration thing versus the Branch network, something in the "2. Application server" stops the calls, right?

 

I have checked the server's firewall (incoming ping) and also temporarely  turned off the firewall, but no success. So firewall seems to be out of the question.

 

I also added the branch's subnet in "1. Main server" under AD Services and Sites, no success.

 

I really can't understand this magic going on in the second server, why doesn't it respond to calls from the Branch side?

 

Please help!

 

br

/Marcus

 

 

 

 

2 Replies
Highlighted

Hello,

 

it is really interesting. 

- What was the error message during the ping from Branch office?

- What is the result, when you start a ping from App server to Branch office?

- I think App server has static IP.. Is the gateway surely right in the App server NIC? 

-Did you add static route rule to windows route table before? (maybe server has wrong gateway to branch subnet)

- You mentioned already tried without firewall. Did you disabled all three firewall profile? 

 

Highlighted

@TamasKosarszki 

What was the error message during the ping from Branch office?

"Request timed out."

 

What is the result, when you start a ping from App server to Branc office?

Hmm, I might have missed that test case ... actually I get "Request timed out" from App server towards Branch computer.

Main server and Win10 client is ok towards Branch computer.

 

Did you add static route rule to windows route table before (maybe it try to send respond on wrong gateway)? 

I do have basic skills in network, but when it comes to "static route rule", I'm kind of lost.

I really don't get why the Main server and clients works but this single server don't.

One finding here (thanks to you) is that the App server seems to be dead in both directions:

- From Branch to App Server

- From App Server to Branch

"Static Route rule" can you guide me on where to add that?

I really don't get why this server should be different from the other WS2019 (Main) server?

 

You mentioned already tried without firewall. Did you disabled all three firewall profile? 

Yes. Tried it ones more now. Doesn't help.

 

I really appreciate your feedback and help! By asking questions and challange we/I might find the issue. Right now I have Googled all Internet and have no more ideas. Very frustrating, I need to get it fixed.

 

Summary:

- Site-to-Site IPSEC VPN with two subnets.

- Branch computer is not domain connected, it can still ping other computers in Main office.

- Branch computer can ping both Main server and Win 10 client...

- ...but not the App server.

- App server can not ping Branch computer.

- App server can be pinged locally within Main office, no issues as long as the VPN tunnel isn't involved.

 

Big thanks for all help I can get!

 

EDIT:

From Branch computer I can ping Main office router (LAN IP).

From App server I cannot ping router (LAN IP) on Branch side!

From other computer within Main office, I can ping Branch router (LAN IP).

 

br

/MH