Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

VPN-remote site clients cannot access ISA-published Website

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Firewall] >> VPN >> VPN-remote site clients cannot access ISA-published Website Page: [1]
Login
Message << Older Topic   Newer Topic >>
VPN-remote site clients cannot access ISA-published Web... - 29.Dec.2006 3:10:24 PM   
aumayrwe

 

Posts: 3
Joined: 29.Dec.2006
Status: offline
Following configuration:

ISAServer2006  published web site
VPN site to site connection  (local ISA-Server - remote site IPsec Netgear Router) VPN traffic goes fine. Website can be reached from the outside world.
But:
Clients in remote VPN site cannot reach Website by public-name, since the NAT-Public IP Address of  remote site is contained in the VPN networks - thus a spoofing attack is identified by ISA-Server and traffic is denied.

How to cope with this without disabling spoofing filter??

Regards Werner.
Post #: 1
RE: VPN-remote site clients cannot access ISA-published... - 2.Jan.2007 1:00:01 PM   
tshinder

 

Posts: 47439
Joined: 10.Jan.2001
From: Texas
Status: offline
The remote site network clients are essentially internal clients, so you'll need to configure your split DNS infrastructure to support them.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to aumayrwe)
Post #: 2
RE: VPN-remote site clients cannot access ISA-published... - 28.Feb.2007 11:48:55 AM   
patos

 

Posts: 31
Joined: 13.Oct.2006
Status: offline
Just to be sure, you are NAT'ing the addresses between the two sites? If not,  you can remove the ISA public IP from the Network addresses in your VPN object, and the requests for your public sites will not go through the tunnel.

(in reply to aumayrwe)
Post #: 3

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Firewall] >> VPN >> VPN-remote site clients cannot access ISA-published Website Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts