player

page is under construction...

How to configure L2TP IPSec VPN using ISA Server

If you have roaming users who want to access internal/private network but you don’t want to spend money at all. Your existing infrastructure consist of Microsoft AD, DNS, DHCP and ISA as firewall. Same as the picture below. Well, you don’t need to spend money to accomplish this objective. It’s few mouse click away.
layout-large-edge
Figure: Microsoft ISA Edge Firewall, source: Microsoft Corp.
As I mention above, you need MS AD, DNS, DHCP, Active Directory Certificate Services and ISA server. If you don’t have certificate server, you can vertualize it following this instruction. Now you have to do following steps:
  1. Check DNS, DHCP and AD connectivity in ISA server, make sure it is functioning properly.
  2. Check/ping public IP configured in one of the NICs in ISA server (ISA got at least two NICs, internal-private IP and external-public IP)
  3. Create a specific group in AD and add users who want VPN access
  4. Install machine/computer certificate in ISA server
  5. Configure VPN in ISA server
  6. Create L2TP client access policy
  7. Install user and machine certificates in VPN client machine
  8. Create L2TP VPN dialler in client machine and test connection
The following the screen shots will definitely be helpful for you.
ISA Management console>VPN>VPN Property
 VPN VPN1 VPN2 VPN3
ISA Management Console>VPN>VPN Clients property
 VPN4 VPN5 VPN6
ISA management Console>Firewall Policy>Create New Access Policy
VPN7 VPN8 VPN9 VPN10 VPN11 VPN12
VPN13
ISA Management Console>Apply.

0 comments:

Post a Comment