SharePoint access from internal clients not in VS subnet

0

Hi guys,

I'm testing the FLB as a replacement of WNLB and TMG, we're using one armed setup.

Network info:

  • My network flow from/to internet is the following: Internet <-> TMG <-> FLB <-> SP Farm (the default gateway of the SP farm and RS/VS is the TMG LB internal IP, they all are in teh same subnet)
  • Internal Client access is like this: client subnet <-> local router <-> remote router <-> VS/RS subnet (no TMG involved here as clients have the router as default gateway).

 

Clients from Internet can access the SP sites just fine, I had issues though when trying to access from a different subnet than the VS/RS. I'm using non-transparent rules and tried the suggestions I've found in the forum (used this suggestion https://support.kemptechnologies.com/hc/en-us/community/posts/206775386-Virtual-services-remote-access-not-working).

More info (none of these worked so far): 

  • I've recreated the rules with and without the use of templates.
  • I've tried to setup new rules using different IP and a default gateway specific for internal clients.
  • I've setup static routes in the FLB to the client subnet.
What I want is that the clients in our subnets to access the RS through the routers using split DNS for SP sites
Can you help me?
 
Thanks in advance.

3 comments

Avatar
0
Mark Deegan

Hello,

I think you might need to enable Subnet originating requests on the VIP after disabling transparency. once done you can specify a different router for your VIP by going to advanced properties and inputting the default gateway there. You will also need to enable "Use Default route Only" found under network options on the LM.

regards

Mark

Avatar
0
ITAdmins

Hi Mark, thanks for replying.

Do you mean I should make those changes in a separate rule right? Should I have 2 separate rules for Internet and internal clients?

Thanks again.

Avatar
0
Mark Deegan

Hi 

Indeed a separate VIP for internal and external clients would be best as it can simplify the network configuration of the VIP.

regards

Mark