03-19-2004 04:28 AM - edited 02-21-2020 01:04 PM
I want to set up a VPN between two sites using a PIX to PIX vpn tunnel. An Exchange 5.5 server with some Outlook clients sits in site 1 and Outlook clients only sit in site 2. What would be the best way of setting this up so that the clients in site 2 can access mails sent to them by clients in site 1?
TIA
03-19-2004 04:31 AM
Gary,
Here is a very good document on PIX site-to-site configuration using IPSec.
Hope this helps,
Jay
03-19-2004 05:16 AM
Cheers Jay, looks like the deal. Presumably I would just permit SMTP traffic between the real server IP and the real client(s) IP in the interesting traffic ACLs on each PIX?
03-19-2004 04:57 AM
a point to point ipsec tunnel will effectively act like a direct physical link between the two sites. You just need to treat the remote office like any other new subnet. WIll you have any servers at the remote site? If you do, make one a wins and dns server, and configure replication between it and the wins and dns server at the main office with the exchange server. That should take care of all name resolution issues.
Having a domain controller at the remote office is also a best practice
03-19-2004 05:28 AM
The 2 sites will use different IP network classes. Will this cause a problem with routing between them?
Unfortunately the remote site just has a couple of PC's, no servers. I suppose the remote client will have to authenticate on the main domain to access exchange? What would you suggest?
03-19-2004 05:48 AM
Gary,
No you'll not have any problems with having 2 different IP address/network. The remote site can authenticate to the primary domain via the VPN tunnel.
Hope this helps,
Jay
03-19-2004 06:00 AM
Cheers Jay, thought that probably would be the case - set up somehing similar a while ago. I suppose the PIXs act as a simple router as they are connected to different subnets? Would you know what nasty ports I would have to add to the interesting ACL to get the clients logged onto the domain.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide