Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Replacing a MS ISA server with 5510

Status
Not open for further replies.

kp1658

Technical User
Jan 4, 2010
7
US
I have a non-profit client that got a 5510 w/Plus donated to them that will replace a MS ISA2006 server. I have not received the SmartNet paperwork yet - just want to figure out as much as I can.

I've got it setup in a test-lab environment to get it configured. My test lab is behind a Linksys router which only has 1 IP, so I have the Outside Interface setup in the DMZ of the linksys with a 10.0.0.x ip that routes out thru the linksys.

Final configuration will be :
2 seperate inside lans (2 groups will share the 5510 for internet access and firewalls. Have 2 public IP's from provider. Both have very similar needs... One is currently using an ISA2006 server and everything is working good.

-SBS2008 running Svr2008 w/ Domain/AD/DNS/DHCP etc, Exchange Svr, Sharepoint Svr and SQL. Using Exchange for both internal & external mail - syncing phones,home users,etc..
-One group also received a couple of 5505 -Plus's for 2 remote offices to have a nailed up VPN.

I just want to take this one step at a time to make sure I got a grip on the setup - adding a step once I confirm the previous step is working & solid.

I have 'step one' working so far, outgoing internet access from Group1 servers and workstations in my test lab.

Step 2 is to come from the outside and hit the company svr websites (exchange OWA, Sharepoint,etc.) and remote users Outlook to the Exchange svr. I didn't want to just wildly adding routes & acls -just go a step at a time.

I'm using ASDM for what I can, haven't touched a Cisco for 4-5 years ago and 2600's...but have been using the CLI and getting around ok.

Thats a lot of info...probably need more guidance than anything right now to get this scenario laid out properly.
Ready to answer your questions..

Kevin


 
so this 5510 is going to be the gateway for each of the LAN's or do you have some other layer 3 device providing this function?? if this will be the gateway for each LAN, what kind of switches do you have installed?? this 5510 will be a VPN headend for one of the groups and it will connect to two other remote offices??

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
"so this 5510 is going to be the gateway for each of the LAN's..."
- That is what I was thinking thinking.

"...what kind of switches do you have installed..."
- They have a DGS-1224t managed switch that is available for use, supports Vlans, trunking, etc...

"...this 5510 will be a VPN headend for one of the groups and it will connect to two other remote offices?? ..."

- One group will have 2 remote offices connected with 5505's eventually, plus regular vpn(either clientless or client based).

The other group will just need either clientless or client based vpn access.

Hope each group can have their own individual VPN access?

Kevin
 
Great -thanks for those links. I have one vpn setup and working fine and will try that link to set up the other..

Kevin
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top