Registered users    
MembershipMembership:
Latest New UserLatest:Michael Battaglia
New TodayNew Today:11
New YesterdayNew Yesterday:11
User CountOverall:23326

Private messaging    
You must be logged in to use this module.
Top 10 posters    
NamePosts
Mariette Knap12894
Marina Roos12507
Eriq Neale2114
Stan Guinn1913
Michael Patrick1912
Robert Pearman1771
Nick Pieters1425
Stewart Brown616
william warren601
Kevin D.579
Welcome unauthorized visitor    
If you want to join us in the discussions on this forum you need to register first. Registration is free! If you are already a registered user please login to join the forum.
Small Business Server Support Forum    
Subject: SBS, ISA and VPN
Prev Next
You are not authorized to post a reply.

Author Messages
Danny L User is Offline
Israel
Member since
4/12/2007

Registered Users
Posts: 1

4/12/2007 07:52 PM  
Hi,
 
I have a simple SBS 2003 Premium setup scenario with 2 NICs, ISA and a router.
The internal NIC is assigned an internal IP: 192.168.16.2 (internal subnet is 192.168.16.0 / 24)
The external NIC is assigned an external static IP: 212.199.11.242
 
I need to set up a site-to-site IPSec VPN tunnel with a remote site (192.168.10.0 / 24). Keeping in mind that ISA can do IPSEC vpn tunnels, I went ahead with the approach of having ISA doing the VPN (the remote site is using an IPSEC VPN router device).
 
Now all this was working fine when access is needed between clients in the internal network and remote clients.
But...it makes perfect sense that the SBS server would have access to the remote site as well, doesn't it? But here lies the problem with running ISA on the same machine as your DC and Exchange server. Why is it a problem? Because when the SBS tries to reach a computer on the remote subnet (192.168.10.0) it uses the external NIC, which then invalidates the source address of the VPN tunnel (the external NIC is used because there is no gateway set on the internal NIC). Now the remote site VPN router is expecting VPN traffic from an IP in the subnet of 192.168.16.0 but it's now receiving packets from an external IP address (212.199.11.242) and so they are being dropped.
 
Is there any solution to this problem?
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12507

8/08/2007 02:02 AM  
Hi Danny,
 
Did you figure this out yet?

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
You are not authorized to post a reply.



ActiveForums 3.7
Forum policy    
These Discussion Forums are dedicated to the discussion of the Small Business Server and related server and client software. For the benefit of the community please observe the following posting guidelines:
  1. No Advertising. This includes promotion of commercial products and non-commercial products which are not directly related to Small Business Server and related server and client software.
  2. No Flaming or Trolling.
  3. No Profanity, Racism, or Prejudice.
  4. Site Moderators have the final word on approving/removing a thread or post or comment.