Re: VPN between 2 routers Cisco
- From: "Phillip Windell" <philwindell@xxxxxxxxxxx>
- Date: Thu, 2 Aug 2007 13:53:17 -0500
"Piertonio" <piertonio@xxxxxxxxx> wrote in message
news:OKYbfrS1HHA.4816@xxxxxxxxxxxxxxxxxxxxxxx
Hello All
I've the following scenario:
Internal network-->(SBS2003+ISA2004)---->Cisco--Internet--Cisco---clients
XP Pro.
Between 2 Cisco routers there is a VPN tunnel.
Wich firewall policy should I setup in the ISA2004 to allow to the remote
clients to logon on the SBS2003 server ?
You don't.
By the way you built this you have created a Back-to-Back DMZ between the
ISA and the Cisco box. When the user connects they aren't VPN'ing into the
LAN,...they are VPN'ing into the DMZ and becoming part of the DMZ which is
no different than the Internet as far as the ISA is concerned,...and so is
completely useless.
Your options are:
Option #1
Configure the Cisco box to be a Router/NAT Firewall/VPN Server all at the
same time. Remove ISA from the SBS box. Remove the second Nic from the SBS
box and run it as a normal single-nic server. LAN topology design and IP
addressing scheme are critical.
Option #2
Setup the VPN between the ISA and the remote-side Cisco box.
Option #3
Use a Cisco VPN box side-by-side with the ISA. LAN topology design and IP
addressing scheme are critical.
All three of these options depend on the assumption that the same design
flaw does not also exist at the opposite end of the VPN.
--
Phillip Windell
www.wandtv.com
The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html
Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc
Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.asp
Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------
.
- References:
- VPN between 2 routers Cisco
- From: Piertonio
- VPN between 2 routers Cisco
- Prev by Date: VPN between 2 routers Cisco
- Next by Date: Re: Routing between branch office Site 3 site vpns
- Previous by thread: VPN between 2 routers Cisco
- Next by thread: Re: Routing between branch office Site 3 site vpns
- Index(es):
Relevant Pages
|
Loading