Article ID: 812076 - Last Review: November 22, 2006 - Revision: 4.4 How to enable a Cisco IPSec VPN client to connect to a Cisco VPN concentrator through ISA Server 2000On This PageSUMMARYThis step-by-step article describes how to enable a Cisco
Systems virtual private network (VPN) client computer using the IPSec protocol,
on the internal network, to connect to an external Cisco VPN Concentrator using
the "transparent tunneling" feature through Microsoft Internet Security and
Acceleration Server 2000. Provide Support for the Cisco VPN ClientIn most cases, IPSec VPN traffic does not pass through ISA Server 2000. However, Cisco Concentrator 3300, with the latest firmware updates, uses "transparent tunneling" that uses User Datagram Protocol (UDP) ports 500, 4500, and 10000 to communicate securely between VPN clients and concentrators.To provide support for this configuration, create the following protocol definitions: Note The client computer must be configured as a SecureNat client. Port number: 500 Protocol type: UDP Direction: Send Receive Port number: 4500 Protocol type: UDP Direction: Send Receive Port number: 10000 Protocol type: UDP Direction: Send Recieve By creating these protocol definitions, you enable the SecureNat client to connect to the Cisco VPN server through ISA Server as all traffic is passed as UDP traffic. According to the Cisco Transparent tunneling technology, this traffic can traverse Network Address Translation (NAT) firewalls. Note You must make sure that your Access Policy permits these three custom protocols. Create the Protocol DefinitionsCreate the new custom protocols to enable the transparent tunneling feature. To do so, follow these steps:
Create a Protocol RuleCreate a protocol rule to allow access using the new custom protocols that you created. To do so, follow these steps:
Note After you perform the steps to add UDP Port 10000 as a protocol definition, you may also have to add UDP port 20000 to be able to work with some of the newer Cisco VPN Concentrators. Note This article is designed for SecureNAT clients. You must remove the ISA Firewall client software. REFERENCESFor information about how to obtain ISA Server 2000 Service
Pack 1 (SP1), visit the following Microsoft Web site: http://technet.microsoft.com/en-us/library/cc750281.aspx
(http://technet.microsoft.com/en-us/library/cc750281.aspx)
For additional help and support with Microsoft Internet Security
and Acceleration (ISA) Server, visit the following Microsoft Web site: http://www.microsoft.com/isaserver
(http://www.microsoft.com/isaserver)
For more information about ISA Server, visit the following
non-Microsoft Web site:http://www.isaserver.org
(http://isaserver.org)
For additional information about Cisco Systems VPN devices, visit
the following Cisco Web site:http://www.cisco.com/warp/public/44/jump/vpn_devices.shtml
(http://www.cisco.com/warp/public/44/jump/vpn_devices.shtml)
Microsoft
provides third-party contact information to help you find technical support.
This contact information may change without notice. Microsoft does not
guarantee the accuracy of this third-party contact information.
The third-party products that are discussed in this article are manufactured by companies that are independent of Microsoft. Microsoft makes no warranty, implied or otherwise, regarding the performance or reliability of these products. | Article Translations
|

Back to the top
