Windows Server 2022 -- Always On VPN

Hello Everyone,

I have been fighting DirectAccess for a while. It works but is easily flustered by Windows Enterprise subscription issues and other quirks. I’ve decided to begin the move to Always On VPN.

I have followed Richard Hicks’ book for a dual NIC server and I am able to connect and access resources on the corporate network. But I’m unable to route “through” the default gateway on the VPN server to the internet. I have put DNS on the internal NIC with no default gateway, unbound all but IPV4 and IPV6 protocols from the DMZ NIC and put the default gateway (my firewall) there. I’m almost positive I’m going to be using split tunneling but it bothers me that I can’t use forced tunneling.

Troubleshooting is complicated by the fact that with RRAS service started, I can’t ping to to 8.8.8.8 or even the default gateway on the DMZ NIC, I get a GENERAL FAILURE error. If I stop RRAS I can ping both.

I’m sure I’m missing something but am at a loss. Any thoughts?