Registered users    
MembershipMembership:
Latest New UserLatest:jenisa villarin
New TodayNew Today:12
New YesterdayNew Yesterday:10
User CountOverall:23322

Private messaging    
You must be logged in to use this module.
Top 10 posters    
NamePosts
Mariette Knap12893
Marina Roos12507
Eriq Neale2114
Stan Guinn1913
Michael Patrick1912
Robert Pearman1771
Nick Pieters1425
Stewart Brown616
william warren598
Kevin D.579
Welcome unauthorized visitor    
If you want to join us in the discussions on this forum you need to register first. Registration is free! If you are already a registered user please login to join the forum.
Small Business Server Support Forum    
Subject: ISA 2004 and Cisco 3002 VPN Hardware Client
Prev Next
You are not authorized to post a reply.

Author Messages
Doug Abney User is Offline
United States
Member since
5/12/2006

Registered Users
Posts: 9

3/26/2007 10:39 PM  
Had this working fine in ISA 2000 with a static route, but am drawing a blank in ISA 2004.       
 
SBS 2003 Prem w/ISA 2004 SP2 is 10.0.0.2, Cisco 3002 has internal interface 10.0.0.45 and external 65.123.x.x. that is plugged directly into router.
 
I have created a persistent static route, route add -p 206.44.x.x  MASK 255.255.255.255 10.0.0.45 METRIC 1, which was all I needed to get it to work in ISA 2000. I have attempted to create new network with 206.44.x.x, a new computer as 206.44.x.x, created new network rules to route traffic between networks and between conmputers, and created new access rules all to no avail.
 
Anyone gotten one of these to work with ISA 2004?
 
Thanks,
 
Doug
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12507

8/08/2007 01:14 AM  
Hi Doug,
 
Did you figure this out yet?

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Doug Abney User is Offline
United States
Member since
5/12/2006

Registered Users
Posts: 9

8/20/2007 07:54 PM  
No Marina, I have not figured this out yet.
 
I've resorted to using the Cisco VPN client on laptops that are running on a separate DSL circuit, completely bypassing SBS2003 and ISA2004 SP2.
 
If anyone has any insight at all I'd be most grateful.
 
Thanks,
 
Doug
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12507

8/21/2007 03:38 AM  
Hi Doug,
 
Why do you need the Cisco VPN client?
Please, post an ipconfig /all from the server and a workstation. Open a command prompt by opening Start -> Run from the Start Menu and type cmd. From the command prompt type ipconfig /all >ip.txt. Attach this file to your answer.

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Doug Abney User is Offline
United States
Member since
5/12/2006

Registered Users
Posts: 9

9/13/2007 07:28 PM  
Marina,
 
Using the Cisco client as a workaround to this problem. I cannot get the Cisco 3002 or the Cisco VPN client to get past ISA 2004 so I'm using the Cisco VPN client on a separate DSL circuit that does not traverse SBS or ISA.
 
Attached files as requested: ipconfigserver.txt is SBS2003 and ipconfigws.txt is a workstation
 
Appreciate any help you can offer,
 
Doug

Attachment: 1913285165671.txt
Attachment: 1913285165654.txt

Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12507

12/10/2007 06:22 PM  
Hi Doug,
 
Ipconfigs are looking good, although you can delete the WINS on the external server nic. I don't understand your setup with the other DSL, nor why you would need to add a static route. If you have run the RRAS wizard and forwarded 1723 and GRE protocol 47 from the router, you should be able to use VPN.

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Doug Abney User is Offline
United States
Member since
5/12/2006

Registered Users
Posts: 9

12/10/2007 07:02 PM  
Marina,
 
Actually forgot that this was still open. I consulted with Amy Babinchak, an ISA guru, back in mid October and while she got me looking in the right direction it turned out NOT to be an ISA issue at all.
 
We are not originating or terminating the VPN at the SBS box. The Cisco 3002 does that all by it self. It has an external NIC (216.xxx.xxx.2) to get to the client network and an internal NIC (10.0.0.45) for us to get from our network to the 3002 and then on to the client network.
 
The solution was a persistent static route on the workstations that needed to get out through the Cisco 3002 (10.0.0.45) to the client server(216.xxx.xxx.3) AND an entry for the destination server(216.xxx.xxx.3) on the other end of the VPN in the workstations localLAT.txt to bypass the Firewall Client for ISA which I found here. Nothing touches the ISA Server in or out.
 
The DSL circuit is outside and completely separate from our SBS network. Using it with the Cisco VPN client was the only way we could get our work done until we came up with this fix.
 
Thanks for continuing to look at this, but I believe we can call this one solved-Doug
You are not authorized to post a reply.
Forums > Microsoft Small Business Server 2003 & 2000 > ISA Server 2004 > ISA 2004 and Cisco 3002 VPN Hardware Client



ActiveForums 3.7
Forum policy    
These Discussion Forums are dedicated to the discussion of the Small Business Server and related server and client software. For the benefit of the community please observe the following posting guidelines:
  1. No Advertising. This includes promotion of commercial products and non-commercial products which are not directly related to Small Business Server and related server and client software.
  2. No Flaming or Trolling.
  3. No Profanity, Racism, or Prejudice.
  4. Site Moderators have the final word on approving/removing a thread or post or comment.