How to Cheat at Configuring ISA Server 2004

We recommend that you use L2TP/IPSec as your VPN protocol for site-to-site VPN connections. L2TP/IPSec is more secure than PPTP and IPSec tunnel mode. However, to ensure that you have a secure site-to-site VPN connection using L2TP/IPSec, you must use machine certificates on all ISA firewall VPN gateways.
We can leverage the PPTP VPN site-to-site link we created in the previous section to allow the branch office ISA firewall access to the Web enrollment site of the enterprise CA located on the main office network.
We will perform the following procedures to enable the L2TP/IPSec site-to-site VPN link:
Enable the System Policy Rule on the Main office firewall to access the enterprise CA We will enable a system policy rule that allows the ISA firewall to connect from the Local Host Network to all Networks. While, ostensibly, this rule is to allow for CRL checking, we can use it to allow the ISA firewall at the main office access to the Web enrollment site on the Internal network.
Request and install a Web site certificate for the Main office firewall Once we connect to the Web enrollment site, we will request an Administrator certificate that we will install into the main office's local machine certificate store. We will also install the enterprise CA's certificate into the main office ISA firewall's Trusted Root Certification Authorities machine certificate store.
Configure the main office ISA firewall to use L2TP/IPSec for the site-to-site link The Remote Site...