We are about to install a IPSec tunnel between HQ and a branch office. We have two ISA Servers 2006 with NLB at HQ, but want to install a Cisco at the branch office. We have contacted a Cisco reseller and they don't recommend that we use our ISA server for VPN, and recommend that we set up a Cisco ASA 5505 at HQ and Cisco 881W in the branch office.
Is there any known problem with combining ISA and Cisco VPN?
Posts: 2244
Joined: 12.Apr.2004
From: Taylorville, IL
Status: offline
No there is no problem. They just want to sell you more firewalls. If you call MS they would try to sell you another ISA and tell you not to use the ASA,...that is how the game works.
The NLB won't apply to the VPN as far as I know. I think you just have to pick one of the ISAs and use it to create the VPN with the ASA.
Posts: 2244
Joined: 12.Apr.2004
From: Taylorville, IL
Status: offline
I don't mess with any arrays myself, but I'm sure there were some issues there with NLB -vs- VPNs. If a Site-to-Site it may reinitialize and connect to the other server but it probably uses the actual IP# and not the VIP.
If it is an incoming Remote Access VPN then I really don't know. I think there might be an article on the site here somewhere about it,..I'm sure I read something along those lines. But I can't remember any real details. I know that this whole subject has been one of the more obscure things about the product to try to understand.