Windows Server 2008
--
Questions
--
Followers
Top Experts
I want to setup a VPN between two sites.
Both sites are running Windows Server 2008 with MS Forefront ISA / TMG as firewall.
We have a router in both sites with internet IP's connected to the ISA.
Not sure what the right / ideal approach will be for setting up a VPN to share data, files, videos, etc.
Any advise and direction will be appreciated.
Thanks
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Second, your ISA server should be just like any other firewall. Â Make sure the ports are forwarded through it to the Server 2008. Â The ports you need should be on the article but mainly 1723.
You could also set it up with VPN routers on both ends...this would eliminate the server setup need and bypasses the firewall as well...though it can be tricky since every router setup is different.
Good luck,
Todd
Should the additional "VPN" NIC be installed in the ISA box or the 2008 Server box?
If installing in the 2008 Server box, should it be connected back to the ISA box again? Â On top of the existing LAN link between ISA &Â Server 2008?
http://www.windowsecurity.com/articles/Configuring-Windows-Server-2008-Remote-Access-SSL-VPN-Server-Part2.html






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
In response to your post;
Our TMG already has two NICs, one for external &Â another for internal. Â Is this the config you are referring to?
It is behind a NATTED router, but the router has a public IP mapped directly to the TMG box.
We are already using the public IP via this router for RDP sessions into the Windows 2008 box, so our router NATs, etc. via TMG is working.
From your comment; Â "The best result is always achieved when the devices connected to the Internet manage VPNs" Â ... Unfortunately we are using an ISP router, which is blocked for any additional setting changes or functionality, apart from additional NATs we may require. Â
The VPN will be ocnfigured on the TMG box and not the Win2008 box?
On the remote site, they are using a Checkpoing R65 firewall with IPSEC, which is independantly configured and managed. Â Will it be possible to configure the TMG to dalk to the router config in the remote site?
Looking around, I found some working examples using ISA 2004 against CP NG or R55, so I suppose it should not be a big deal. One configuration example can be seen here: http://www.redline-software.com/eng/support/articles/isaserver/general/implementing_checkpoint_ng_r55_firewall_and_microsoft_isa_2004.php .
Our DC (Win2008) and the TMG already has a public certificate installed for Exchange. Â Does this mean that an additional certificate should be requested / installed, or will the current certificate and FQDN suffice?

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
I just went through the article you posted. Â And you are correct, it does not involve setting up SSL, but IPSec tunnel mode. Â I will configure this on the TMG and see how it goes. Â I noticed the last phase is for configuring the VPN access rule and it relates to the site-to-site custom needs. Â Could you perhaps give me an example for this access-rule? Â I assume this rule destination will be the Win2008 server?






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Windows Server 2008
--
Questions
--
Followers
Top Experts
Windows Server 2008 and Windows Server 2008 R2, based on the Microsoft Vista codebase, is the last 32-bit server operating system released by Microsoft. It has a number of versions, including including Foundation, Standard, Enterprise, Datacenter, Web, HPC Server, Itanium and Storage; new features included server core installation and Hyper-V.