VPN to PIX, Win2K, Active Directory - where to start?

Hello world.

I am waiting the arrival of a PIX 515 and 501 for firewalls and creating VPN between my main site and a remote location. Remoteness is having a LAN installed but will not have a real Win2k domian while the main site is an area complete with exchange and AD win2k. The two site will connect to INet w / cable modems.

Here's the question:

Is it possible to have this remote site to be part of my site main area via the VPN? Can I set up a server on the remote site to replicate AD to, in which case the VPN is stopped for some reason any. Do I need to open ports on the firewall or not because it will be on a VPN?

Is it an easy thing to do? Is a beginner at the top of his head?

Thanks in advance for any advice.

Marc

No router required - basically, everything will be static routed - your customers, regardless of the site, will have the pix as the default gateway. each pix will have a default gateway configured, by you, by a statement of 'road '. Each pix ACL crypto will also act as a static route through the tunnel to the other pix

Tags: Cisco Security

Similar Questions

  • Server 2008 R2 Active Directory Certificate Services does not start

    Hello

    I had a power failure on both of my units of WD Sentinel DX4000 running Windows Server 2008 r2. Come to fine and checked the integrity but now a unit gives me an error and does not start the Active Directory Certificate Services. I checked google and read where I need to run the eseutil.exe on the CA database, but discovered that utility is provided only with the server Exchange that I'm not running. Is there another utility that allows you to defragment and correct the Microsoft database. Here is the error I get when you try to start it:

    Log name: Application
    Source: Microsoft-Windows-CertificationAuthority
    Date: 28/07/2014 06:01:39
    Event ID: 17
    Task category: no
    Level: error
    Keywords: Classic
    User: SYSTEM
    Computer: WDOffice
    Description:
    Certificate Services Active Directory did not start: could not initialize the connection of database for WDOFFICE-CA.  Error 0xc8000147 (SEE:-327).
    The event XML:
    http://schemas.Microsoft.com/win/2004/08/events/event">
     
       
        17
        0
        2
        0
        0
        0 x 80000000000000
       
        40337
       
       
        Application
        WDOffice
       
     

     
        WDOFFICE-CA
        Error 0xc8000147 (ESE:-327)
     

    Any help would be greatly appreciated,

    Thank you

    Bob

    BBob

    This issue is beyond the scope of this site and must be placed on Technet or MSDN

    http://social.technet.Microsoft.com/forums/en-us/home

    http://social.msdn.Microsoft.com/forums/en-us/home

  • upgrade from 5.0 to 5.5 vCenter: DNS domain name to be added as a source of identity, Active directory native

    I intend to upgrade a vCenter 5.0 to 5.5.

    The vShpere environment is used for the test and is not integrated with Active Directory, if users log on the vCenter uses groups and users local vCenter.

    During the upgrade, I have the option to check a box saying "Add < nom_domaine_dns > as a source of identity, Active directory native.

    Please can someone explain what this means?

    What it is supposed to happen if I do not check the box?

    Local users and groups vCenter will be able to log on again after the upgrade?

    Even if it's a test environment I can't create any kind of problems for existing users, so selecting the right answer is essential...

    Concerning

    Marius

    SSO, you have the option to add Sources of identity (like LDAP, Active Directory) where the useres and groups are managed.

    This option has no meaning for you if you vpshere environment is not integrated with active directory. But it makes no difference if you select or deselect it.

    local users will continue to work...

  • remove an active directory domain controller that no longer starts

    I'm in the process or upgrading active directory from Windows 2003 to WIndows 2008.  There are between 20 and 30 of the domain controllers.  I'm about to halfway through the process and have had no problem.

    So far.  One of the Windows 2003 domain controllers has declined before the demotion.  It has been restarted and it won't start.  What can I do to remove this Active Directory server without starting the system?  Is there a clean solution to the withdrawal?

    Hi McGinleyM

    The answers community is more than one instance based home user. Your question would be better suited for our group of TechNet. The link is below. Thank you.

    http://TechNet.Microsoft.com/en-us/ms772425.aspx

  • Client pix VPN how to authenticate with Active Directory

    Hi all, I've just set up my first Client VPN on a Cisco PIX. Everything works very well so that hitting the correct subnet and logon. However, I would like to see how I can get my connection of remote users with there active directory accounts. Right now I use the local connection for the pix for testing purposes. Sounds easy, but I'm missing something

    We use:

    Cisco Pix 515E version 6.3 (3)

    Thank you

    Dan

    Unfortunately the PIX 6.3.3 version does not support Active Directory authentication. V6.3.3 PIX only supports authentication to the server database, radius, and Ganymede local PIX.

    If you want to authenticate to active directory, it is support for PIX v7.x go.

    Here are the different types of authentication support for PIX v7.x leave for your reference:

    http://www.Cisco.com/en/us/docs/security/ASA/asa70/configuration/guide/AAA.html

    Hope that answers your question.

  • Where can I find and download the Active Directory users and computers for Windows 7

    Where can I find and download Active Directory users and computers for Windows 7

    Thank you

    Fred Tarpley

    Announcement is not a consumer product.  You'll be much more likely to get an answer as to where you can buy it on TechNet (for IT Pro)

    This issue is beyond the scope of this site (for consumers) and to be sure, you get the best (and fastest) reply, we have to ask either on Technet (for IT Pro) or MSDN (for developers)

    If you give us a link to the new thread we can point to some resources it
  • How can I use MS Active Directory to authenticate a PIX?

    I currently have a race PIX515 6.3 and I have created user manuals from via PPTP (VPDN) to my protected network (administrative nightmare). Is it possible that I can use MS Active Directory database user and have the PIX refer to him for authentication? Or do I need to Cisco's ACS software to accomplish this?

    Here you go

    http://www.Cisco.com/en/us/products/HW/vpndevc/ps2030/products_configuration_example09186a00800b6099.shtml

    http://www.Cisco.com/en/us/products/HW/vpndevc/ps2284/products_configuration_example09186a0080094700.shtml

    concerning

    John

  • Cisco VPN client v5 and integration Active Directory 2008

    Hi all

    I need to know if I can integrate Single Sign On for my Cisco VPN Client v.5 with my Active Directory which run on windows 2008

    THX in advance

    No, unfortunately, Single Sign On is only supported on Clientless SSL VPN (WebVPN), not on the IPSec VPN Client AnyConnect VPN Client.

  • Where to download and how to install Active Directory in Windows 7

    I think that I installed it (title) partially. I have something that is our main servers of the subnet by name. But I can't find anything executable that allows me to reset the passwords of authorized users. I installed once on Win 7 Pro, but I had to crush this system for other reasons. On this system, I even had the executable that is pinned to the taskbar.   Can someone help me, please?

    Hello

    Ask the TechNet and Windows 7 IT Pro forums server. This is where
    Active Directory is taken in charge and not the answers.

    I hope this helps.

    Rob Brown - Microsoft MVP<- profile="" -="" windows="" expert="" -="" consumer="" :="" bicycle=""><- mark="" twain="" said="" it="">

    Thanks, I did & hope it helps. I misunderstood you at the first, sorry!

  • VCOPS 5.8 - where is the "Active Directory integration"?

    5.8 Notes version is a "novelty".

    Authentication options with the new integration with active directory for authentication.

    Where is this new option? All I see is former "LDAP import', which works, somehow. I was expecting something more easy to AD.

    I understand that it was a typo in the rel notes, because there is no change in the integration of Ops 5.8 vC ads. I think that this excerpt was intended to rel Insight journal notes, that add features more AD.

  • where domain services active directory

    I am trying to install my HP F4500 printer wireless on my new HP Probook 4430 s.  I get the message that Active Directory domain services is not available.  I looked at every page HP I can find. enabled, disabled, uninstalled and reinstalled - worked on it for a week. Can anyone help.
    I went to activate windows to confirm that I have a windows on my computer.

    Windows 7 64-bit on Probook.
    Thank you
    Barbara
    E-mail address is removed from the privacy *.
    E-mail address is removed from the privacy *.

    I get the message "Active directory domain Services is not available.

    One of the reasons why I said is that I have been unable to identify my printer installed as default printer.

    The thing is I can print Word and Internet but not Excel.
    I've seen a lot of questions on this subject, but no solutions.
    Do you have a?

  • Connectivity to Active Directory/network of remote desktop resources

    We have a network of the issue of the standard with Active Directory.  We plan to take one of our employees and making them work from home.  Is it possible to simply take their workstation connected to Active Directory, and transport to their home, plug it into our network (via a VPN client) and have the user choose right there where they left (as if they were in the building on the real network)?  Has anyone tried this before?  How did it happen?

    Hello

    The question you posted would be better suited in the TechNet Forums; We recommend that you post your question in the TechNet Forums to get help:

    http://social.technet.Microsoft.com/forums/en-us/category/w7itpro

    Hope that the information provided is useful.

  • Open migration to Active Directory directory Windows vs Mac

    OK, so I help my old school to their IT needs, because they do not have a person hired for this role.

    Currently, they have a center where the staff use computers based on Windows 10 10 (systems of Core 2 Duo, especially assembled; all about 3 years) connected to a Windows 2008 Server (from Dell; about a year). As the institution wishes to expand the computers available to their staff (from 90), my suggestion was to move to Mac (probably 11 '' MBAs), with a MacBook Pro 15 "is the duty of the server.

    This migration can be done in one shot and would happen progressively (probably MBAs purchased each year for the next four years, 20-25).

    The current configuration is that there is a local + Admin user configured on each of the 10 Windows PC - based, with all personnel having access to the user not local administrator.

    In order to facilitate the management, I would like to move to the logons on the network, as we begin our migration to a Mac OS environment.

    Should we configure AD on Windows Server and bind it as MBAs, and when to buy us, with the final being the MBP 15 "for server-buying functions, or is it possible we can get the MBP 15" now and use Open Directory and binding the existing 10 10 Windows-PC with the macOS Server?

    NOTE: The school operates Google Apps, and all employees have a Google Apps account with a custom domain name.

    You can't link PCs to Open Directory without using 3rd - Party (page). In addition, depending on the operating system will not work reliable? You'd have to trial it first. Beyond bond and provide a home folder there will be nothing else. No management, no policies etc Open Directory to your PC.

    Support way to achieve this is to use Active Directory and complete with OD to manage your estate of mac only. Again, you can apply GPOS for Mac without 3rd - Party help which can be very expensive.

    Not that it's something that you would consider - although you could do? It may be preferable to go ' all the mac "If your intention is to switch to Mac OS. If your PC using the software that is available only for PCs consider using virtual machines on your Mac to keep this aspect of the school.

    My 2 p

  • Password locking Active Directory - Apple ID

    In my office, we have three Macbooks linked to the Active Directory domain and all the three machines to meet the same problem. On all three machines, we use different local Admin, Mobile AD managed accounts. Accounts use private Apple ID in Itunes and App store. All three accounts have experienced what seemed to be random AD accounts locks.

    We have managed to limit somewhat through troubleshooting a problem with Apple ID and keychain.

    Users, initially created their Apple ID with their e-mails and the company when they connect to their Apple App Store ID they get locked out AD almost immediately.

    After they changed their Apple ID to their private emails, they got locked out AD whenever they tried to authenticate more than 5 times on App Store (or any where else some application requires Apple ID). Even if their identity papers have absolutely nothing to do with their usernames and passwords AD account. Somehow Apple ID or key ring tries to authenticate against AD. Whenever you enter the password wrong or correct it increments the counter "badpwdcount" of 1. If you try to authenticate five or repeatedly, causes it to lock the user of the AD because of the "5 bad passwords GPO" in AD.

    Even if the user enters a password valid, it always raises the 1 meter. If the user authenticates Apple ID with its business e-mail the lockout is immediate, which would mean the Apple itself ID forces on AD in quick succession or done something that causes lock it the user to use the e-mail AD and move. Is not question even if the pass is the same on the AD and Apple ID.

    Can you suggest what newspapers should happen to us AD to eventually find the reason that newspapers we checked that no information. Even the attribute which must display the name of the computer where the lockout was made has no information.
    We know when the lockout occur and we manage to avoid them but we would like to know why they happen. Why Apple ID, or Keychain has something to do with authentication on AD.

    We have studied this issue widely on the Interwebs and found no information that we could carry on. Locking issues revolve around a few old passwords stored on IPad and other similar positions only here on communities are way back in 2007. None of this information relates to our AD locking problems.

    We even did some heavy troubleshooting with certificates, but nothing helped.

    Someone else has the same or similar problems?

    I run several Mac Pro and Macbook Pro (El Capitan OS X 10.11.5 & 10.11.6) with the mobile AD accounts and links AD back to the domain AD WIN2012R2 server, where connection system is different from the apple ID used to access the apple store/itunes and have no problem with locked out as you describe.

    I've known a lot of problems but with "compatibility between previous versions of Mac OS X (Mavericks and Yosemite)" with WINSBS2003 then WIN2008 Server OS. Do not know what is the relationship of platform (OS X to WIN) of the software you have.

    I have found many problems have been fixed just by signing on iCloud, restart the MAC then sign in iCloud, don't know if doing the same thing could help you. The offender has generally been OS X, especially after an upgrade.

    Are your Mac related to AD, but search LDAP and NIS or too? This was one of my problems with WIN2008 and Nonconformists.

  • Active Directory user profile question

    I have a weird problem.  I use two server Remote Office Server R2 2012 with roaming profiles.  If I create a new user profile in active directory all works fine.  I had a situation where I had to remove a user profile for cause of termination.  He was rehired after 3 days.  I created a new profile with the same username as before.  Now, when the user connects, they are logged in a temporary profile.  There is no .bak profile lists on with rds server.  Event files give a 1521 event ID Windows cannot locate the server copy of your roaming profile and is trying to connect you with your local profile. Changes to the profile will not be copied to the server when you log off. This error can be caused by network problems or insufficient security rights.

    DETAIL - access is denied.

    and 1511 Windows cannot find the local profile and connects you with a temporary profile. Changes to this profile will be lost when you log out.

    I thank in advance for your suggestions.

    Hello

    Post your question in the TechNet Server Forums, as your question kindly is beyond the scope of these Forums.

    http://social.technet.Microsoft.com/forums/WindowsServer/en-us/home?category=WindowsServer

    See you soon.

Maybe you are looking for

  • Messaging and storage

    I have an iphone 5 and he recently told me that I didn't have enough storage and that I had to turn to a certain substance, after deleting all my apps but one (and I don't really want to delete because this app is no longer in the app store so if I r

  • C855-1VT satellite - cannot start media recovery disk

    Hello I have the laptop above that was dumped on its edge causing the hard drive to the jam and fail.This means no access to the system recovery, so I ordered arvato shop Toshibas Recovery Media recovery media. I installed a new HARD drive has slippe

  • jammmed letters together in the Works word processor

    everything stored in the processor Works suddenly has the letters in each word packed together. other works such as database functions are not affected.  can find no way to change this.  stored objects can be opened OK in Word 2003.  I've got windows

  • event ID 576 displays the user name or domain name: only displays privileges: is this normal

    I was checking my audits of security one came across one with event ID 576 I noticed there was no 'user name' or 'Domain name' is this normal Date: 21/05/2012 Source Security Time at 12:01 category: privilege use Event ID of success A 576 Authority/n

  • Temporary files lost after burn error

    Help me! I had chosen a whole bunch of files that I wanted to burn to disc. The burn process has failed and I had a few options - one of them being "save temporary files to burn later. I chose this, but now my files are gone? HELP!!!!!!!!!!!!!!!!!!!