Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

vpn/ ipsec tunneling 2

Status
Not open for further replies.

sonun

IS-IT--Management
Dec 26, 2001
384
US
Heres the scenario. There are 2 servers. One is win2k which is a web server with .net framework. The other is a win2003 with sql db server. These servers are on different segments of a Cisco pix firewall. The web server is the DMZ and the db server is on a more restricted segment. I want to setup VPN tunneling between the two servers.
Basically the db server should not be talking to any other server other than the web server. The web server should be able to talk to the db server as well allow clients from outside the firewall. Currently the web server allows clients connections from outside.

I thought this is what I should be doing to set up the VPN tunneling. Set up the DB server IPSec policy as Require security and specify the IP address of the web server. Set up the Web server IPSec policy as Client-Respond only (and add the IPaddress of the DB server ??). I guess I will also have to configure pix to allow ipsec traffic between the 2 servers.

Kindly let me know if I am in the right direction here. If yes, then can you kindly point me to detailed guides, step-by-step howtos to help me set it up the way I want to. Dont worry about configuring the pix part. If not, then could you point me in the right direction with the same guides and howtos.

Thanks
 
Thanks.
But what is the link supposed to convey.
I am not sure.
 
I think you better chak forum463 for that

Marc
[sub]If 'something' 'somewhere' gives 'some' error, expect random guesses or no replies at all. Please specify details.
Free Tip: The F1 Key does NOT destroy your PC!
[/sub]
 
O, and I notice you posted 196 questions so far but only gave out 5 'thank you's' in the form of a star.
Also, you do not seem to respond to questions asked in your post.
That is considered highly inpolite, so please pay attention to that.
You may want to backtrack your posts to thank the members helping you out in the past. Sooner or later you will get ignored otherwise.
Just some advice!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top