Consider the following scenarios.
In these scenarios, the establishment of the client's PPTP connection may be unsuccessful because Forefront TMG 2010 drops the PPTP server's Generic Routing Encapsulation (GRE) packets.
Scenario 1
- A server that is running Microsoft Forefront Threat Management Gateway 2010 is configured for a VPN site-to-site connection and uses IPsec Tunnel mode.
- The Forefront TMG 2010 server is also configured to use network address translation (NAT) between two networks such as an internal network and an external network.
- Clients on the internal network try to access a Point-to-Point Tunneling Protocol (PPTP) virtual private network (VPN) server on the external network.
Scenario 2
- A server that is running Microsoft Forefront Threat Management Gateway (TMG) 2010 is configured for a VPN site-to-site connection and uses IPsec Tunnel mode.
- The Forefront TMG 2010 server is also configured to publish a Point-to-Point Tunneling Protocol (PPTP) virtual private network (VPN) server.
- Clients try to access the PPTP VPN server through the Forefront TMG 2010 server.
In these scenarios, the establishment of the client's PPTP connection may be unsuccessful because Forefront TMG 2010 drops the PPTP server's Generic Routing Encapsulation (GRE) packets.