Networking Forums

Networking Forums > Computer Networking > Windows Networking > Use of Microsoft stand-alone root CA for VPN, Simple Certificate Enrollment Protocol (SCEP)

Reply
Thread Tools Display Modes

Use of Microsoft stand-alone root CA for VPN, Simple Certificate Enrollment Protocol (SCEP)

 
 
Edward W. Ray/502974
Guest
Posts: n/a

 
      04-06-2004, 05:11 PM
I currently have a Windows 2003 native Active Directory Domain located
behind a Netscreen-50 firewall. One of my domain controllers is set up as a
stand-alone root CA. The Windows AD computers have no routable IPs; they
are all NAT mapped behind the firewall. A DHCP server runs behind the
firewall to assign static IPS to each computer which joins the domain. I
plan to use a Netscreen 5GT at the client end to establish the VPN tunnel.
Some questions:

1. Can I keep the domain controller NAT-mapped or will I have to assign
it a routable static IP?

2. Is it possible to use SCEP to automate enrolling a PKCS10 cert
request?

3. Will I need to install the certificate on the 5GT prior to
establishing the tunnel?

4. Can a VPN connected computer join a Windows 2003 native AD domain?

5. Can I join the remote computer to the Windows 2003 AD through the VPN
tunnel, or will I have to join it prior to establishing the VPN tunnel?

I already have a Netscreen doc to guide me through the VPN connection. If
there are some corresponding Microsoft docs which address my questions,
please provide the link.

Thanks in advance!

Edward W. Ray



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Automatic certificate enrollment for local system failed to enroll kristy Windows Networking 0 04-03-2006 09:44 PM
Which certificate/protocol would I use? Paul Wireless Networks 4 03-17-2006 04:02 AM
Automatic certificate enrollment for local system failed after upgrading member server to domain controller Arch Willingham Windows Networking 4 08-28-2005 09:17 PM
Automatice Certificate Enrollment Failure westernwind Windows Networking 3 07-19-2005 06:06 AM
Automatic certificate enrollment for local system failed MR Windows Networking 5 01-14-2005 11:38 AM



1 2 3 4 5 6 7 8 9 10 11