• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

VPN over back-to-back firewall

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 Firewall] >> VPN >> VPN over back-to-back firewall Page: [1]
Login
Message << Older Topic   Newer Topic >>
VPN over back-to-back firewall - 2.Jul.2002 9:54:00 AM   
SimonBowles

 

Posts: 19
Joined: 5.May2002
From: Hertfordshire, UK
Status: offline
Does anyone know of any articles on setting up VPN access to the DMZ from the Internal network.

I can successfully create a connection to the DMZ from the Internal network and I am assigned a IP address for the DMZ, but I am unable to ping any systems or access any resources on the DMZ.

Is there anything I am missing?

Thanks in advance!
Post #: 1
RE: VPN over back-to-back firewall - 4.Jul.2002 4:08:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Crash,

Can you give details about the IP subnet of your internal network and your DMZ segment?

Also, how is the VPN client configured?

How is the VPN server configured?

It should be easy to replicate the environment with this information.

Thanks!

Tom

(in reply to SimonBowles)
Post #: 2
RE: VPN over back-to-back firewall - 5.Jul.2002 10:19:00 PM   
SimonBowles

 

Posts: 19
Joined: 5.May2002
From: Hertfordshire, UK
Status: offline
Internal network: 172.16.0.0 255.255.0.0
DMZ: 192.168.1.0 255.255.255.0

My internal firewall has the IP address 172.16.1.103, I configure the VPN client to connect to this address, it is then assigned a static IP from the address range (192.168.1.10-20)

The VPN server was setup from the ISA console, and apart from the address range above, I have not made any changes. I assume that ISA server will setup the VPN service correctly.

When I open a CMD prompt on the client computer, I can ping servers on the DMZ, but as soon as I open the VPN connection, the ping request is lost.

The VPN server I connect to is also the the default gateway on the client system. The client and the server or both running Win2k Server.

Many thanks Tom!

[ July 06, 2002, 01:39 AM: Message edited by: Crash ]

(in reply to SimonBowles)
Post #: 3
RE: VPN over back-to-back firewall - 7.Jul.2002 7:38:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Crash,

Whoa! I think we're getting confused on the nomenclature here. [Big Grin]

You said that you want to connect to a VPN server on the DMZ segment from an internal network client. Correct?

If that is the case, you do not need to configure the VPN server on the ISA Server. You just need to configure the ISA Server to allow PPTP passthrough. The actual VPN server configuration would need to be done on the DMZ host computer.

Your IP configuration looks good for the DMZ and the internal network. I was concerned that maybe the internal network and the DMZ were on the same network ID [Razz]

Thanks!

Tom

(in reply to SimonBowles)
Post #: 4
RE: VPN over back-to-back firewall - 8.Jul.2002 8:57:00 AM   
SimonBowles

 

Posts: 19
Joined: 5.May2002
From: Hertfordshire, UK
Status: offline
lol!

Sorry...

I wish to connect to the DMZ network from the internal LAN. That way, I can connect to network shares on a number of systems on the DMZ network.

I don't require any VPN access for external users.

I wanted the ISA server itself to be the VPN server, or is this a bad idea?

Should the VPN server be the internal ISA server or the ISA server at the each of the DMZ?

Thanks again Tom!

(in reply to SimonBowles)
Post #: 5
RE: VPN over back-to-back firewall - 10.Jul.2002 8:08:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Crash,

Interesting problem! The reason why its interesting is that you want to make the ISA Server a VPN server that will allow you access to the DMZ network. This issue here is that if you VPN into the DMZ via the ISA/VPN server, the internal interface of the ISA/VPN server (the LAT network interface) is actually the EXTERNAL interface for the VPN! I don't know if that would work, as I haven't tested it, but it certainly has the potential for confusion.

As for accessing shares on the DMZ, bastion host computers should never has the Server service enabled *EVER*. Well, I shouldn't say that, because if you aren't concerned about them getting broken into, allowing shares on them is a great way to make new friends in the hacker community [Big Grin]

HTH,
Tom

(in reply to SimonBowles)
Post #: 6

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 Firewall] >> VPN >> VPN over back-to-back firewall Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts