Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

VPN clients IP assignment dilema

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Firewall] >> VPN >> VPN clients IP assignment dilema Page: [1]
Login
Message << Older Topic   Newer Topic >>
VPN clients IP assignment dilema - 18.Jun.2008 11:36:28 AM   
zoro

 

Posts: 6
Joined: 3.Jun.2008
Status: offline
Hi, I am going to implement Front End Hardware Firewall and ISA is going to be Back End Firewall.
So far, VPN client connections were terminating at ISA (so I was getting IPs from internal DHCP through assigned chunks 10 of them through RRAS), but from now on, they will terminate on front end firewall. I have already setup LDAP communication with AD from Front End Firewall and all is working OK in test lab.
Since I am going to have DMZ between HW Firewall and ISA and since VPN clients will be terminating at Front End Firewall, how I am going to assign IPs to VPN clients when they log in?
I don't want to have /24 subnet mask (IF POSSIBLE) in that DMZ, but only very few IP's for WEB/FTP server and OWA e.g. (/29 subnet mask).
Do I really need to have /24 subnet in that DMZ and DHCP enabled on Front End Router, so that the clients get internal IPs from Front End Router, or I can go with static setup?
Least but not last, there is going to be Route relationship between DMZ and Internal LAN.
If anyone has an experience doing this, I would appreciate quick answer, or if there is link on the Internet that explains this process.
Zoro
Post #: 1
RE: VPN clients IP assignment dilema - 1.Jul.2008 8:30:39 AM   
tshinder

 

Posts: 47439
Joined: 10.Jan.2001
From: Texas
Status: offline
Why not just assign off-subnet addresses to the DMZ VPN clients? What's the problem with a private /24 network ID?

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to zoro)
Post #: 2

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Firewall] >> VPN >> VPN clients IP assignment dilema Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts