RE: VPN and ISA server

From: Benjamin D. Goldman (bgoldman@kipany.com)
Date: 04/09/03

  • Next message: Michael Turner: "RE: VPN and ISA server"
    Date: Wed, 9 Apr 2003 11:22:19 -0400
    From: "Benjamin D. Goldman" <bgoldman@kipany.com>
    To: "Joseph Burton" <joseph_burton1970@hotmail.com>, <focus-ms@securityfocus.com>
    

    put a second machine on the network border - with 2 Network cards in it.

    1 internal
    1 external

    build your tunnels to that machine.

    turn off all other services, and put up strict TCPIP filter policies on
    that machine on both interfaces.

    your best practice would be to put this at your external perimiter, and
    have a second perimiter behind it as well.

    Im sure someone else will contribute more detail.

    -----Original Message-----
    From: Joseph Burton [mailto:joseph_burton1970@hotmail.com]
    Sent: Wednesday, April 09, 2003 10:33 AM
    To: focus-ms@securityfocus.com
    Subject: VPN and ISA server

    Hello all,

    Does anyone know if Microsoft ISA server can handle IPSec in
    "tunnel-mode"?
    I've heard that only "transport-mode" works so that you may only
    establish a
    secure communication between two nodes, but not access the network
    behind
    the nodes.

    To put it a different way, I want to use ISA server for roaming users to

    access the office LAN. Is this possible (I know I could use PPTP but
    that is
    not an option in this case)? And if this works, do I need a VPN client
    or
    can I use the native Win 2000/XP IPSec support?

    Thanks in advance,

    //Joe

    _________________________________________________________________
    Hitta rätt på nätet med MSN Sök http://search.msn.se/

    ----------------------------------------------------------------------
    Block Spam, Smut & Viruses
    SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers
    of
    technology including filtering embedded and attached file content. Rid
    your
    enterprise of unwanted content.
    http://www.securityfocus.com/SurfControl-focus-ms2
    Download your free fully functional trial, complete with 30-days of free
    technical support.
    ----------------------------------------------------------------------

    ----------------------------------------------------------------------
    Block Spam, Smut & Viruses
    SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers of
    technology including filtering embedded and attached file content. Rid your
    enterprise of unwanted content.
    http://www.securityfocus.com/SurfControl-focus-ms2
    Download your free fully functional trial, complete with 30-days of free
    technical support.
    ----------------------------------------------------------------------


  • Next message: Michael Turner: "RE: VPN and ISA server"

    Relevant Pages

    • RE: bandwidth monitoring for baystacks
      ... Watch your real network but limit the more powerful tools to 60 seconds. ... SurfControl E-mail Filter puts the brakes on spam, ... IMail Server has scanned this e-mail for viruses using Declude Virus from ...
      (Security-Basics)
    • Re: Possibility of routing through internet with private IP address
      ... > VPN tunnels from the WAN side end at the netscreen. ... and have the packets routed back to them properly? ... Better Management for Network Security ...
      (Security-Basics)
    • explorer.exe using memory uncontrollably
      ... >I was having trouble setting up internet connection ... second machine). ... Pretty sure that I didn't need the network ... out of virtual memory and crashed. ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: One remote network - two VPN tunnels.???
      ... to have traffic from one network routed across two ... different tunnels to two different, ... When two peers connect to each other, they negotiate a "isakmp phase 1" ... a different Security Association is built for each ...
      (comp.dcom.sys.cisco)
    • Suggested Number of Active Directory Site Links For a Small Network
      ... All 5 sites are interconnected by VPN ... tunnels in a mesh topology (meaning each site has a direct VPN tunnel ... separate site links. ... How much bandwidth can replication eat up on a small network like ...
      (microsoft.public.windows.server.active_directory)