Advertisement

06.04.2007 at 02:08PM PDT, ID: 22612239
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

7.6

SBS 2003/ISA 2004 IPSec Problem

Asked by skyefusion in MS Forefront-ISA, SBS Small Business Server, IPSec Security Protocol

Tags: , , ,

Hello,

This is an issue with SBS 2003 Premium (running with ISA 2004) and a Cisco 831 IOS Router.
The main office's SBS Box has an internal ip address range of 172.16.1.0/24. The Cisco router in the branch office has an internal ip rangeof 192.168.3.0/24. The ipsec is setup identical on the two units and the tunnel is establishing. From within the sbs network from a client machine we can ping and remote to a machine on the cisco network, but not from the SBS machine itself. From the cisco network out to the sbs network nothing works (ping, trace, rdp, telnet)

We suspect the problem to be that in SBS running isaserver we never set a default gateway on the internal nic. On the external nic we set it up normally with its default gateway. So when you are working on the sbs box itself and trying to go somewhere other than 172.16.1.X  it will always go out the external interface, but through the tunnel as encrypted. The cisco will not accept encrypted traffic from any ip range
other than 172.16.1.X   so the packets are discarded.

If we replace the PIX in place of the existing Cisco, will the external sbs ip be accepted encrypted by the pix? This will have to happen as the cisco network will have to authenticate from the sbs box and the clients will be a part of the domain.

Summary:
- Clients in SBS network can ping/access/rdp machines on the cisco network.
- SBS machine itself (with ISA running) cannot ping/access/rdp machines on the cisco network.
- Clients in cisco network can access the Internet, but not anywhere else (including machines on the SBS network, or the SBS itself).

If the SBS (without ISA) is behind another Cisco device, and the tunnel is between 2 cisco routers, the problem would be fixed because the SBS is using the cisco router's LAN ip as the gateway. It seems to me its a SBS 2003 / ISA 2004 issue. We have checked the ACL on the Cisco routers and compare it with Cisco config/tech republic guides and they are all the same setting. Any ideas?
Start Free Trial
[+][-]06.04.2007 at 03:08PM PDT, ID: 19212581

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.04.2007 at 10:48PM PDT, ID: 19214767

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.04.2007 at 10:50PM PDT, ID: 19214772

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.04.2007 at 11:07PM PDT, ID: 19214841

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.04.2007 at 11:19PM PDT, ID: 19214909

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.05.2007 at 07:52AM PDT, ID: 19217465

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]06.05.2007 at 02:39PM PDT, ID: 19221048

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: MS Forefront-ISA, SBS Small Business Server, IPSec Security Protocol
Tags: sbs, isa, ipsec, 2004
Sign Up Now!
Solution Provided By: TechSoEasy
Participating Experts: 2
Solution Grade: A
 
 
[+][-]06.07.2007 at 08:52AM PDT, ID: 19234623

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32