Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

VPN Site to Site with preshared key

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> VPN >> VPN Site to Site with preshared key Page: [1]
Login
Message << Older Topic   Newer Topic >>
VPN Site to Site with preshared key - 8.Mar.2004 5:48:00 PM   
Guest
Hello,

at the moment i am connecting a ISA 2004 on a w2k3 Server with a ISA 2000 on w2k.
In early VPN deployments with two ISA 2000 i was necessary to define a IPSec Policy in conjunction with a Preshared Key where the crypto algorithms where defined. (Phase1,Phase2 and so on).On w2k3 it is quite simply to configure this because the Preshared Key can be set on the interface itself (RRAS). Now my question: What security negotiation will be used when ISA 2004 is connecting to ISA 2000 ? Is he simply trying everything since he gets negotiated ? Can i interact to chose what to use ?

Greetings
Neppoz
  Post #: 1
RE: VPN Site to Site with preshared key - 8.Mar.2004 7:46:00 PM   
tshinder

 

Posts: 47439
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Neppoz,

ISA 2000 does not support IPSec tunnel mode for site to site connections.

HTH,
Tom

(in reply to Guest)
Post #: 2
RE: VPN Site to Site with preshared key - 9.Mar.2004 2:59:00 PM   
Guest
Hi Tom,

Sorry,i can not understand.
I saw your Article where you are making an example of how to connect 2 ISA Servers with an certificate and a L2TP/IPSec connection.

We made exact the same in our net with one exception that we used a preshared key instead.
(Defined in the L2TP Security Policy of the ISA Server)

(in reply to Guest)
  Post #: 3
RE: VPN Site to Site with preshared key - 10.Mar.2004 11:34:00 AM   
tshinder

 

Posts: 47439
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Neppoz,

Oh! OK, I understand now. You want to use a pre-shared key for L2TP/IPSec, not IPSec tunnel mode [Smile]

There is a small bug in the ISA 2004 VPN code, which should be fixed before release. You need to go into the RRAS console, right click on the server name and click Properties. Click the Security tab and set the same pre-shared key there.

HTH,
Tom

(in reply to Guest)
Post #: 4

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> VPN >> VPN Site to Site with preshared key Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts