Post by Bahrs, Ar » Fri, 15 May 2009 02:33:29

Hi All J

Ok... this one is interesting... and cite Eugene V. as the

This is interesting to me as here the Courts rule that the Police
obtaining a warrant was nice but unnecessary and then the Court tells
the State "Improve the law so a Warrant will be needed!"

SmallCo has just been purchased by BigCo

SmallCo has MO and BOs connected by ISA 2006 EE Site-to-Site VPNs. All sites
are connected to all other sites. Also uses MO ISA for VPN Clients.

BigCo stays "as far away from ISA as possible" (their words), because all
they know is Cisco. However, they will reluctantly let SmallCo keep using
ISA for MO and BO VPN endpoints, provided they all have connectivity to all
of BigCo's many subnets. Here's the diagram that's evolving:

4 SmallCo BO LANs
| | | |
4 SmallCo BO ISA VPN Endpoints
| | | |
| | | |
SmallCo MO ISA VPN Endpoint/VPN Server--Internet--VPN Clients
SmallCo MO LAN
BigCo MO LAN Subnet--Outbound Internet Access for BC & SC
| | | | | | | | | | | | |
Many Routers
| | | | | | | | | | | | |
Many MPLSs
| | | | | | | | | | | | |
Many Routers
| | | | | | | | | | | | |
Many BigCo LAN Subnets

What I think I know of ISA tells me that SmallCo BOs and VPN Clients will
never see packets from BigCo because SmallCo BO ISAs will drop them as

If I (like it or not) disable spoof detection, will this diagram work?

Do I add BigCo address ranges to the MO VPN Networks at the BO ISAs? On the
Internal Network at the MO ISA?

Anything else it will take to make this design work?

Jeff Vandervoort

