• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Certain subnets not connecting to Exchange!

Master Blaster

[H]ard|Gawd
Joined
Nov 23, 2006
Messages
1,442
Hi All,

I recently resubnetted our current network to expand IP address ranges at our remote location. I have now have the following addresses:
x.x.28.x
x.x.29.x
x.x.30.x (original network)
x.x.31.x

The issue I am having is that for any computer not on the x.30 network cannot connect to the Exchange server (located across the country, and on a different network).

I'm not sure if the ACL/routing table needs updating, as I believe all incoming IPs to Exchange should be incoming as a x.30 network.

I'm wracking my brain on this. pinged both DNS name and IP, tracert to no avail, updated the host file, and tried to setup IP forwarding on the Domain Controller. Any tips on how to find a solution would be great!

Thank you.
 
post your config. sounds like you aren't doing Layer 3 routing somewhere.
 
Yup, looks like a L3 issue. What are you using for the gateways?
 
Exchange:
x.x.50.51/24
x.x.50.1

DC (my local)---this guy can connect and ping fine since of course, it's on the x.30. Handing out DHCP on the addresses from my previous post.
x.x.30.50/22
x.x.30.1
 
where does a trace route die?
you just say "tracert to no avail" which doesn't exactly provide much info :p
 
where does a trace route die?
you just say "tracert to no avail" which doesn't exactly provide much info :p

Ha, yeah. So if I trace route the non-functional connections, it receives the Request Time Out. until I stop the command; last one I did was 20 RTO.

Also, just additional information, we are using an ASA firewall. All interfaces on the ASA updated accordingly when I made the network adjustment. It could be possible the ACL is on the old mask of /24. Would that be enough to stop the connection to Exchange though all machines have internet access?
 
oh hold on there is a VPN involved here? If so then you will need to change the VPNS to include the new subnets
 
Agreed, have your firewall guys modify the cryptomaps and nat exemptions for the new subnets.
 
Are you using sites and services with AD, have you added these new subnets to the proper AD sites? If this is just clients not connecting though, it shouldn't have an effect, just if exchange servers aren't talking.
 
Alright guys. I jumped into our ASA to run a few test, trace route, ping, etc. It's not connecting whatsoever so I believe that indeed it's the NAT or the ACL setup. I'm going to dig in and see if any update I make correct my issue.
And yes Jay_oasis, we do have VPN session. Let me run through vpn-sessions to check over that then. I didn't set it up, so it very well could be different than it needs to be.
 
Last edited:
Back
Top