• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Routing Question in Site-to-Site VPN

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> VPN >> Routing Question in Site-to-Site VPN Page: [1]
Login
Message << Older Topic   Newer Topic >>
Routing Question in Site-to-Site VPN - 26.Oct.2006 12:03:19 PM   
eddiec

 

Posts: 1
Joined: 26.Oct.2006
Status: offline
Hi, I am a network admin of 3 office (A, B, C). Each office has Cisco PIX 506 as front-end firewall and ISA 2004 as back-end firewall. Here are the VPN settings I have done.

1. PIX connected by IPSec (A<->B, A<->C, B<->C).
2. Based on IPSec, ISA 2004 connected by PPTP
(A<->B, A<->C, B<->C).

Now I have a question. I performed a network test and got the following results.

1. A<->B: 300K bps
2. A<->C: 1M bps
3. B<->C: 10M bps

Obviously, A->C->B will be faster than A->B. How can I add a routing setting in RRAS or ISA 2004 to force A->B must go through C and keep A->B as a backup route in case C is down?

In each office, 2 static routes are found in RRAS for DOD.

Office A
PIX (a1.b1.c1.d1 ; 192.168.1.1/255.255.255.0)
ISA (192.168.1.2 ; 10.1.1.1/255.255.0.0)

Office B
PIX (a2.b2.c2.d2 ; 192.168.2.1/255.255.255.0)
ISA (192.168.2.2 ; 10.2.1.1/255.255.0.0)


Office C
PIX (a3.b3.c3.d3 ; 192.168.3.1/255.255.255.0)
ISA (192.168.3.2 ; 10.3.1.1/255.255.0.0)




thanks,
eddie



< Message edited by eddiec -- 26.Oct.2006 12:04:25 PM >
Post #: 1

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> VPN >> Routing Question in Site-to-Site VPN Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts