I wish to know if anyone has tried such configuration before.
A VPN server in the DMZ (reasonably a MS machine) connected to another VPN server (definitely a MS one) through Internet.
The documentation I found at the MS site (http://www.microsoft.com/resources/documentation/WindowsServ/2003/all/deployguide/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/all/deployguide/en-us/dnsbj_ips_schx.asp) states:” you need to open port 500 (ISAKMP) and 4500 (ISAKMP over NAT-T) but also enable protocols 50 (ESP) and 51 (AH)”.
The first two are easy to do, but: what about the latter ones (ESP and AH)?
They are surely enabled by default if we are going to use the VPN service included with ASL, but what is the situation if the server is a third box placed in the DMZ?
Any idea is warmly welcome!
friscom
This thread was automatically locked due to age.
