Dr. Tom Shinder's ISA Server 2006 Migration Guide

Creating a PPTP Site-to-Site VPN

Site-to-site VPNs allow you to connect entire networks to one another. This can lead to significant cost savings for organizations that are using dedicated frame relay links to connect branch offices to the main office, or branch offices to one another. The ISA firewall supports site-to-site VPN networking using the following VPN protocols:

  • PPTP (Point-to-Point Tunneling Protocol)

  • L2TP/IPSec (Layer Two Tunneling Protocol over IPSec)

  • IPSec Tunnel Mode

The most secure VPN protocol for site-to-site VPNs is the L2TP/IPSec VPN protocol. L2TP/ IPSec allows you to require both machine and user authentication. If you connect two ISA 2004/2006 Firewalls you should use LT2P/IPSec. IPSec tunnel mode should only be used when you need to connect to down-level VPN gateways. The major problem with IPSec tunnel mode might be that most down-level VPN gateway vendors require you to use a pre-shared key instead of certificate authentication, and there are a number of exploits that can take advantage of this situation (In the case of ISA 2004/2006 you must use a very long, complex and unguessable pre-shared key and you will stay out of trouble, ISA is using only IKE Main Mode and not IKE Aggressive Mode).

The use of PPTP should be avoided (it is the weakest VPN protocol available on ISA 2006). Creating a site-to-site VPN used to be a complex process in ISA 2004 days, because of the number of steps involved. However, with the ISA 2006 new site-to-site wizard, you ll find that setting...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: VPN Software
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.