Two VPN gateways on one Windows Server 2008?


hello,

i'm thinking implementing following scenario: 2 vpn "gateways" (like "intranet.contoso.com" , "extranet.contoso.com"), users in active directory group allowed connect intranet vpn, users in group b allowed connect extranet vpn. clients in intranet should given broader access (more static routes internal networks) whereas clients in extranet allowed access one, specific network. 2 vpns should have different subnets, of course.

i think isolation part done using firewall how start: how differentiate clients , assign them different addresses , static routes? it's simple if have 2 windows server 2008 boxes possible use 1 system? maybe network access protection be useful? have 1 vpn configured dhcp relay agent on internal interface in rras. dhcp assigning static routes.

i'm looking forward suggestions , hints :) in advance,

regards,
wojciech

thank detailed information. i'm afraid documentation linked not helpful in scenario because none of these documents regard using nap & vlans in vpn scenario, 802.1x port security. 

in meantime, however, i've come solution on own seems trick: ip filtering. created multiple network policies in nap, 1 policy intranet , 1 extranet ad user group, , configured ip filters respectively. extranet explicitly allow traffic based on destination networks and/or ports. intranet allow traffic.

regards,
wojciech 



Windows Server  >  Platform Networking



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group