Re: OpenVPN and ISA 2004



On Nov 11, 10:58 am, "Phillip Windell" <philwind...@xxxxxxxxxxx>
wrote:
I don't know what the port 1194 is for,....

If this is VPN, then they need the PPTP or L2TP protocol. If this Open VPN
uses something "odd-ball" then the Open VPN isn't very "Open".

The Access Rule needs to allow PPTP (or L2TP) outbound and must be anonymous
(All Users).

They have to disable the Firewall Client while using it.

Right click on the FWC icon by the clock,...choose Disable
Do the VPN thing
When done with the VPN thing right click on the FWC icon by the
clock,...choose Enable

--
Phillip Windellwww.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processinghttp://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-...

Microsoft Internet Security & Acceleration Server: Partnershttp://www.microsoft.com/isaserver/partners/default.asp

Microsoft ISA Server Partners: Partner Hardware Solutionshttp://www.microsoft.com/forefront/edgesecurity/partners/hardwarepart...
-----------------------------------------------------

"Serge" <ser...@xxxxxxxxx> wrote in message

news:1194362131.059169.100080@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Hi all. I would appreciate any help on the following issue:
I have a client that needs to connect from an internal machine to a
client's server that uses OpenVPN. We have ISA 2004 installed w/ SBS,
and the firewall seems to be blocking the outgoing OpenVPN connection.
I have already opened up port UDP 1194 outbound.

Can anyone successfully openvpn out of internal network?

Thank you.

Thanks for the response Philip!

This is taken directly from their site: http://openvpn.net/
OpenVPN implements OSI layer 2 or 3 secure network extension using the
industry standard SSL/TLS protocol, supports flexible client
authentication methods based on certificates, smart cards, and/or 2-
factor authentication, and allows user or group-specific access
control policies using firewall rules applied to the VPN virtual
interface. OpenVPN is not a web application proxy and does not operate
through a web browser.

Does OpenVPN support IPSec or PPTP?
There are three major families of VPN implementations in wide usage
today: SSL, IPSec, and PPTP. OpenVPN is an SSL VPN and as such is not
compatible with IPSec, L2TP, or PPTP.

I actually did try opening port 1194 for SSL (using the ISAtpre tool)
but it still did not work. Do you have any other ideas?

.



Relevant Pages

  • Re: Connecting to Microsoft VPN with Linux?
    ... > * can Linux VPN support Microsoft VPN? ... Don't use MS PPTP if you don't need to. ... than on Fedora, because Fedora kernel is missing the module bsd_comp.o. ... OpenVPN is available for Win32, ...
    (Fedora)
  • Re: [SLE] PPTP Client Set Problems conneting to a VPN in SuSE 9.3
    ... Seems like OpenVPN does not support connecting via PPTP. ... >> I am using PPTP Client to connect to a VPN. ...
    (SuSE)
  • VPN from win to Linux server: PPTP or OpenVPN or..?
    ... Well, the office network has the sarge machine behind a ADSL router, ... I then turned my attention to openVPN as they state they run the VPN ... would like to know if someone had experince with PPTP in this cenario... ...
    (Debian-User)
  • Re: [SLE] PPTP Client Set Problems conneting to a VPN in SuSE 9.3
    ... > Seems like OpenVPN does not support connecting via PPTP. ... However, you asked if anyone had used a VPN, not specifically ... Check the headers for your unsubscription address For additional commands send e-mail to suse-linux-e-help@suse.com Also check the archives at http://lists.suse.com Please read the FAQs: suse-linux-e-faq@suse.com ...
    (SuSE)
  • Re: VPN PPTP problem
    ... Why the PPTP and GRE packets receive the SBS but the PPTP ... VPN cannot establish? ...
    (microsoft.public.windows.server.sbs)

Loading