Re: RPC Publishing and Internal Network routing.



"Ricus" <Ricus@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C69CFD47-5BCC-4070-A8F6-41F4882D0464@xxxxxxxxxxxxxxxx

Just more info about the routing the vpn is not setup by isa but is
seperate.
But I also want to route to another internal network(vlan) on my internal
network and I feel if I can get this working then since the vpn is another
network internal to isa I should be able to get that running too once I
get
isa to route to my other internal subnet(vlan).

Ok, so,..from the ISA's perspective the VPN just simply does not exist,...it
is nothing more than an additional Subnet runing behind the ISA. The fact
that it is a VPN or not is just irrelevant.

So there is two steps to that:

1. Take the IP Range of *all* your LAN Segments and also the IP Range of the
network on the other end of the VPN and add them to the Internal Network
Definition under tha Addresses Tab

2. Pick one LAN Router (you have to have one somewhere if you have another
Segment). This LAN Router should "smart" enough to know how to get to all
Segments, including the VPN segment. Then you create a static route in the
OS's Routing Table on the ISA that tells it to use this LAN Router for the
path to the other LAN Segments (which includes the VPN). If you cannot
make it that simple than you can use more than one static route, and just
add another static route that tells ISA to use the VPN Device as the path to
the addresses of the Segment on the other end of the VPN.


--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Technet Library
ISA2004
http://technet.microsoft.com/en-us/library/cc302436(TechNet.10).aspx
ISA2006
http://technet.microsoft.com/en-us/library/bb898433(TechNet.10).aspx

Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.mspx

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------


.



Relevant Pages

  • RE: Configuring ISA 2004 for outbound MS VPN access
    ... internal users to connect to an external VPN server through Microsoft ... Internet Security and Acceleration (ISA) Server 2004. ... remote VPN network is not in the local ISA server's LAT (for ISA 2004, ... Joining Networks over the Internet with a Gateway to Gateway VPN: ...
    (microsoft.public.windows.server.sbs)
  • Re: weird gateway to gateway vpn issue
    ... but then the vpn ... web sites from site B I have to disconnect the gateway to gateway ... has a domain controller that connects over the internet through ... to the internet through their local ISA server at any one time. ...
    (microsoft.public.isa.vpn)
  • Re: Site2Site VPN - Web page requests returns FWX_E_TERMINATING
    ... You have to separate in you mind the concept of the VPN -vs- the Internet ... Internet Locations and it will *blindly* send them to the proxy if IE ... Understanding the ISA 2004 Access Rule Processing ...
    (microsoft.public.isa.vpn)
  • Re: weird gateway to gateway vpn issue
    ... Could you give more infos about the ISA Nics config? ... works fine if the vpn link is broken. ... get to web sites from site B I have to disconnect the gateway ... Does both site got a DNS for internet name resolution? ...
    (microsoft.public.isa.vpn)
  • Re: Using a Linksys router, should I also use Zonealarm? Internet Acceptable Use Policy
    ... depending on your VPN client when you connect to VPN server client will ... As soon as you connect to VPN server that will be default route. ... other network address. ... I created new default route for my internet traffic that points to my ISP. ...
    (microsoft.public.security)