Hi,
We are looking to setup a remote support zone to different customers (more than 500) for our different software developers.
The type of connections to customers can be PSTN/ISDN dialup, PPTP and ipsec L2L connections.
We don't want that the connections can be initiated from within the local lan so we thought of having a DMZ with terminal server and workstations where the different teams can logon.
Different needs :
Terminal server & workstations (for debugging) in zone
One team can only access his customers from Terminal server and from his workstations.
AAA
We thought of using the new ISR routers for dialup and ipsec in combination with ACS.
For PPTP we still need a Windows server.
a few remarks : how is it possible to use ACS with auth-proxy if you let the users login to the same TS (so same source ip ?)
Can ACS be used together with the microsoft server for setting up PPTP connections ?
Any ideas about architecture and a secure zone are welcome.
Regards,
Kristine