XP_2600
Posts: 13
Joined: 5.Apr.2005
From: Egypt
Status: offline
|
Guys, i need your help so much please, i needed to establish site to site VPN, between our branch in Egypt and in Saudia, anyway i started by these steps and you please correct me: ISA server is installed in both domains (egyptian one and Saudian one), ISA is member of a domain, External interface in each site have a static IP, i set a VPN site to site account in each machine, in local users, i name each account with the same name of the Account, and set password for it and configued each account in each site with the other server account and set the domain as the ISA server name,as long as these accounts are local accounts, and i gave them the dial in allow dial option, and i set a network rule to allow routing between Source network the VPN connection and the internal network, and the distination is VPN connection and the internal connection, i set access policy and allowed all outbound traffic from the internal to vpn and vise versa, and i set a network contain both of the VPN and Internal, i put the range of other network in each VPN connection, now each ISA server can ping the internal ip of the other network, and i see the connection established in the site to site vpn, each ISA server can ping the internal range of ips of the other network, but it cannot open services there, and the other machines which is memeber of the isa cannot ping the others i mean if i have Network A and B and they are conncted via site to site, the isa server in A can ping any internal IP in B and isa in B can ping any internal IP in A, but cant open shares for instance, and A clients which use isa firewall client to access the internet cannot ping any internal IP of B and B clients cannot ping A internal IPs, please help me im really lost here.
|