To work around this problem, configure the Demand Dial interfaces and user names so the interfaces are associated and only one PPTP tunnel is used. You can do this manually, as explained in this procedure, or you can use the ISA Server VPN Configuration Wizard if both ends are running ISA. The ISA Server VPN Configuration Wizard correctly configures the demand-dial interface names and user credentials.
To configure the demand-dial interfaces manually follow the instructions below. Replace the names
SiteA and
SiteB with the location of each site.
On SiteA
- Open the Routing and Remote Access MMC, and then expand Server.
- Right-click Routing Interfaces, and then click New Demand-Dial Interface.
- Click Next to start the wizard.
- In the Interface Name dialog box, use the interface name SiteA_SiteB, and then click Next.
- In the Connection Type dialog box, click Connect using virtual private networking (VPN), and then click Next.
- In the VPN Type dialog box, click Point To Point Tunneling Protocol (PPTP), and then click Next.
- In the Destination Address dialog box, type the IP address or the DNS name of the destination VPN server, and then click Next.
- In the Protocols and Security dialog box, leave the default settings, and then click Next.
- In the Dial Out Credentials dialog box, use SiteB_SiteA as the user name, type the domain name and password, click Next, and then click Finish.
- Right-click the newly-created demand-dial interface, and then click Properties.
- On the Options tab, change Connection Type to Persistent Connection, and then click OK.
- Expand IP Routing, and then click Static Routes.
- Right-click Static Routes, and then click New Static Route.
- In the Interface list, click the newly-created interface SiteA_SiteB.
- In the Destination field, type the network destination for SiteB.
- In the Network Mask field, type the subnet mask for SiteB, and then click OK.
On SiteB
- Open the Routing and Remote Access MMC, and then expand Server.
- Right-click Routing Interfaces, and then click New Demand-Dial Interface.
- Click Next to start the Wizard.
- In the Interface Name dialog box, use the interface name SiteB_SiteA, and then click Next.
- In the Connection Type dialog box, click Connect using virtual private networking (VPN), and then click Next.
- In the VPN Type dialog box, click Point To Point Tunneling Protocol (PPTP), and then click Next.
- In the Destination Address dialog box, type the IP address or the DNS name of the destination VPN server, and then click Next.
- In the Protocols and Security dialog box, leave the default settings, and then click Next.
- In the Dial Out Credentials dialog box, use SiteA_SiteB as the user name, type the domain name and password, click Next, and then click Finish.
- Right-click the newly-created demand-dial interface, and then click Properties.
- On the Options tab, change Connection Type to Demand dial, change Idle time before hanging up to Never, and then click OK.
- Expand IP Routing, and then click Static Routes.
- Right-click Static Routes, and then click New Static Route.
- In the Interface list, click the newly created interface SiteB_SiteA.
- In the Destination field, type the network destination for SiteA.
- In the Network Mask field, type the subnet mask for SiteA, and then click OK.