Turan
Posts: 13
Joined: 25.Mar.2002
Status: offline
|
Hi all,
Our company has 25 sites connected by various wan connections excluding internet. One of our site has internet connection, and due some security reasons all these sites connected with vpn connection, also all sites connect to internet over one site. For now we use Astaro Linux FW on all sites.
I'd like to use ISA 2004 and made a test platform. Here is my test platform diagram:

I'd like to be identifying access policies between two sites, connect two sites via vpn, and also make available internet for "Site B" over "Site A".
I have "External", "internal", "local host" predefined network definitions on "Site A", identified correctly, and clients can connect to internet over "Site A".
To establish vpn over two sites and make a full connection over two sites without any restrictions, I did the following on "Site A"
1. Define a network connection as "vpn b" defined as "VPN Site-to-Site Network", select "IPSec Tunnel Mode", as remote VPN gateway 10.1.2.5, and as Local VPN Gateway 10.1.1.5. Enter a shared key, and specify network address range as 172.16.2.0-172.16.2.255.
2. Define a network rule as "Site B Connection" defined as source "internal", destination "vpn b" and define network relationship as "route"
3. Define a Firewall policy as "Full access to site B" (for now, it will not be full finally), "internal" as source, "vpn b" as destination, without any restrictions.
4. Make same configurations on "Site A" using the same vpn shared key.
5. And try to connect from "site a" to "site b", i couldn't be able to ping, or anything like that.
Let me say that there's no static routing or identified w2k3 routing&remote access rule on any isa server. Also there's no definition for wan network, 10.X.X.X.
From clients, when i try to ping, i get message "request time out", from isa server, "negotiating ip security" but never a successful ping reply
What should be the problem? Am i missing something?
Thanks in advance.. [ February 06, 2004, 09:58 AM: Message edited by: Turan ]
|