IPSec Connection Security Rule Through Firewall


hi all

we have requirement secure traffic ipsec security connection rules endpoint on internet reverse proxy iis arr server on our internal network.

we have created ipsec rule on iis arr server states endpoint 1 , endpoint 2 - 172.12.30.8 local private ip of iis arr server. bit confused @ how should configure ipsec connection security rule on internet client.

the problem face there firewall in-between nat ip address of iis arr server server has private ip address. 

my questions is:

1. can use ipsec in way, possibly using ipsec nat-t, if need do, matter of allowing udp port 4500 on firewall between endpoints? , ip address should security connection rule on internet endpoint configured with, should firewall public ip or nat (private) address on iis arr server. i'm assuming need private ip??

the other option move iis arr server dmz , give public ip trying avoid if possible

any appreciated.

thanks

johny

hi johny,

1. can use ipsec in way, possibly using ipsec nat-t, if need do, matter of allowing udp port 4500 on firewall between endpoints?

based on know, routers need support nat-t, , indeed udp port 4500 on endpoints should open.

and ip address should security connection rule on internet endpoint configured with, should firewall public ip or nat (private) address on iis arr server. i'm assuming need private ip??

i believe security connection rule on internet endpoint should configured firewall public ip address, since private ip address cannot reached external network while public ip address can translated private ip address nat-t.

if further assistance required, please post new thread in network infrastructure servers forum below professional support network experts.

https://social.technet.microsoft.com/forums/windowsserver/en-us/home?forum=winservernis

best regards,

amy


please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file