|
Question : Multiple VPN connection over one Firewall/Gateway to one destination
|
|
Here's the deal: I need to establishe multiple VPN connections to an oversea office. All my users (around 10) are behind a MS ISA Server Firewall, which has one dynamic public IP (cable provider). Beside the VPN traffic, the ISA Server should also handle access to the internet for default services (mail, web, etc) and some custom services. The clients default gateway is set to the ISA server. We're also using the MS Firewall Client which comes with the ISA Server.
On the other end is a Cisco Altiga VPN Concentrator.
I managed to get VPN working for one client at a time. But everytime a second client tries to connect to the Altiga they can't establish a connection. Also, I tried to connect the ISA Server directly via VPN to the Altiga, but if the connection is up, the users can't access the internet anymore.
Has anyone a quick and solid solution to this? I'd prefer a version, where each client can connect for it's own to the remote host, since their login also handles some permissioning on the remote network.
Thanks for your help
|
Answer : Multiple VPN connection over one Firewall/Gateway to one destination
|
|
You can't. If you only have one public IP address, you cannot create more than one PPTP tunnel at a time. The issue is GRE which has no concept of ports and does not work over Port Address Translation.
Your best bet is to create a LAN-LAN ipsec tunnel between the ISA server and the Alitiga, else put in a real firewall like a PIX and do a LAN-LAN tunnel..
|
|
|
|