Adding the second IP is fine (I have about 16, one for each service I publish) - and is common practice although not really for VPN headers.
You can select any IP that you want to act as the VPN header as you decide it when you launch/configure the vpn client. If you have two ip addresses on the ISA external nic then both of these constitute the EXTERNAL listener - and the VPN should respond on requests on either IP. What you cannot do is select to listen on only one ip address - for VPNs anyway.
Pwindell is correct about reboots. As changes to the VPN config likely will make changes to the RRAS service, it requires a reboot although this is not always the case.
Main Topics
Browse All Topics





by: pwindellPosted on 2009-06-05 at 08:01:56ID: 24557137
Added the extra IP# for what? It does not sound like you have a real reason to do that.
You should never add multiple IP#s to the ISA without a solid and specific reason to do so.
However that should not break the VPN in any case.
You can not select a specific IP to receive VPN Connections,...you can only select the Network Definition,...which is almost always going to be External.
Even though it is not supposed to be so,...sometimes changes do not work correctly until the ISA is completel rebooted.