Hi all.
Happy new year!
I have the following task: I have Wingate 6 in the head office and Cisco router plus one more Cisco in our branch. Now I need to create IPSec (ESP + ISA KMP protocols) VPN between this 2 Ciscos and want to know the following:
- how to allow ESP + ISA KMP protocols to pass through Wingate (I want to forward them to the Cisco)?
I know ISA KMP utilizes UDP port 500 (or UDP port 4500, when NATed by NAT-T, which I believe Wingate makes), but I cann't see the way how to make a hole for ESP, which is "ip protocol N50"!? How to do it?
Besides, I want to connect 2 ISPs to Wingate to have redundancy for Internet connection, and have some more questions for it:
- is it ok if I install 4 NICs (2x WAN, 1x LAN, 1x DMZ) in Wingate machine (XP SP3)?
- how to provide simultaneous functioning of two Internet connections to utilize the whole bandwidth?
- when having multiple ISPs, how Wingate define if one of the Internet connections becomes non-operational?
I am asking, because most part of our issues with Internet connection take place when our ISP himself has no connection to Internet (but we still have good connectivity to the ISP, i.e. our gateway is available). Is it possible for Wingate to check Internet availability itself, not just its gateway? (Of course the question is what is then "Internet connection"? Pinging google.com or what? I don't know the answer, may be you can give an advise...)
- in case of above mentioned VPN, Cisco ip will also be NATed by Wingate, and I can not understand, how Wingate will do it, if it has two Internet connections (=> 2 public ips)?
Each time (i.e. for each VPN session) use only one public ip or what?
Thank you.