Re: ISA2004 - VPN Server Issue

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Thomas W Shinder [MVP] (tshinder_at_hotmail.com)
Date: 04/14/04

  • Next message: Z D: "found a workaround = more confusion"
    Date: Wed, 14 Apr 2004 04:45:30 -0500
    
    

    Hi ZD,

    Same answer as that provided on the ISAserver.org message boards.

    HTH,

    --
    Tom
    www.isaserver.org/shinder
    ISA Server and Beyond: http://tinyurl.com/1jq1
    Configuring ISA Server: http://tinyurl.com/1llp
    ISA Server and Beyond Seminars - http://tinyurl.com/9sce
    MVP -- ISA Server 2000
    "Z D" <NOSPAM@NOSPAM.com> wrote in message
    news:eGMQk#aIEHA.3528@TK2MSFTNGP09.phx.gbl...
    : Hi,
    :
    : Here's the situation:
    :
    : My ISA server (2004, beta2) has MULTIPLE internet IP addresses assigned to
    1
    : NIC.
    : It also has a single IP address assigned to a 2nd internal NIC (private
    : LAN).
    :
    :
    : When configuring the VPN settings, I noticed that it is NOT possible to
    : choose the specific IP address that I want the ISA server to listen on for
    : VPN connections, I am only able to choose a whole network! (usually when
    : publishing servers it lets you choose a specfific IP within a network).
    :
    : This means that, as it currently stands, a client could VPN to ANY of the
    : external IP addresses assigned to my ISA server and the call would be
    : satesfied!
    :
    :
    : If I SHOW system policy rules then I note that there is indeed a default
    : "Allow VPN Clients to Firewall" policy that's causing this problem.
    :
    : HOWEVER: I am UNABLE to edit this one! When I try to edit it it brings up
    : the special sys. polciy edit box but there is nowhere that mentions
    anything
    : about VPN!! It just defaults to the first DHCP box.
    :
    :
    :
    : SO - my question is: If my isa server is also the VPN server, how do I
    limit
    : the IP addresses that it listens on?
    :
    : Thanks!
    : -ZD
    :
    :
    :
    :
    

  • Next message: Z D: "found a workaround = more confusion"

    Relevant Pages

    • Re: Remote Desktop from LAN not working
      ... the ISA Server policies that are created by the SBS ... I think your outbound VPN connection is not established properly ... On the Add Network Entities page, expand Networks, select Internal, ...
      (microsoft.public.windows.server.sbs)
    • RE: Remote Access
      ... offices to connect to head office and access head office resource. ... Site to Site VPN ... The Site to Site VPN request ISA server, so please ensure whether your SBS ...
      (microsoft.public.windows.server.sbs)
    • RE: Quick Mode SA fails because of ISA Server proposal
      ... The Address from my VPN Gate. ... You should get in tough with SAP and get your VPN connection working up to ... presents the entire IP-range of your internal network. ... Everytime you restart your ISA Server or the IPsec service, ...
      (microsoft.public.isa.vpn)
    • RE: Quick Mode SA fails because of ISA Server proposal
      ... The Address from my VPN Gate. ... You should get in tough with SAP and get your VPN connection working up to ... presents the entire IP-range of your internal network. ... Everytime you restart your ISA Server or the IPsec service, ...
      (microsoft.public.isa.vpn)
    • Re: Site-to-site
      ... I have a site-to-Site VPN (as ... LANs must not use the same IP Range, ... Sonic OS 3.1 Enhanced and Microsoft ISA Server 2004 ... Configuring IPSec Tunnel Mode VPN Between ISA Server 2004 and SmoothWall ...
      (microsoft.public.isaserver)