I have a Windows Server 2003 Active Directory domain with an ISA 2004 firewall. I have several employees that successfully VPN into our network regularly. In order to do that, we issue them a certificate from our own internal MS certificate authority (I install the cert on their computer before deploying it to them) and we add them to an AD "VPN Users" group. That group is granted Remote Access permission via Remote Access policies on the ISA (which is our RRAS box as well).
Now, I have two consultants (developers) who are working with us. They wish to use their own laptops to VPN into our network and work on a project. Their laptops are already a member of the AD domain for their company.
My question: how do I give them VPN privileges if they are not members of my domain? I don't know where the settings in RRAS that require the use of the certificate. I assume I create an AD user account for each of them and add them to the allowed VPN Users AD group. Beyond that, I'm not sure.
Start Free Trial