rrincones
asked on
Need help setting up a site to site vpn using isa 2004
We are setting up a site to site vpn with a client. They requested that we nat our local IP, (192.168.16.0), to a scope they will provide.
I have done this on routers, such as sonicwall, which has an option to translate local network.
Is this possible on isa 2004? There is an option to nat local network, but I think it will nat it to our external (internet) ip.
I have done this on routers, such as sonicwall, which has an option to translate local network.
Is this possible on isa 2004? There is an option to nat local network, but I think it will nat it to our external (internet) ip.
Setup routing rules. Traffice for their network will go thru VPN.
ASKER
We will be accessing servers on their end. Are routing rules still the way to go? Can you give me a more detail?
Ok, yes I have a couple clients setup that way. I am in the middle of restoring a crashed server so don't have a chance to google but look up route add command don't forget to add -p to make it a persistent route.
ASKER
Im a little confused, On the VPN, they want us to nat our internal network, 192.168.16.0, to 10.100.162.0.
We will be accessing 4 servers. I have defined the Servers ip addresses on vpn configuration Address Ranges.
Do I use the Route ADD command to route to 10.100.162.0?
We will be accessing 4 servers. I have defined the Servers ip addresses on vpn configuration Address Ranges.
Do I use the Route ADD command to route to 10.100.162.0?
If I follow correctly I think they want you to change your internal network IP addresses.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Sorry had to reread this a few times I see what you are trying to do but why not just change the internal IP addresses? Or else you could do routes for every device on the isa server but seems like more work.
ASKER
"why not just change the internal IP addresses..." thats an option I am considering. So the option to translate local network to a different IP scheme is not available on isa2004?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
we did change the internal ip. thanks