IPSec Tunnel Mode Site-to-Site VPNs with Downlevel VPN Gateways
One of the major improvements that the new ISA firewall has over ISA Server 2000 is that it can be configured to use IPSec tunnel mode for site-to-site VPN connections. Most third-party VPN gateways require that you use IPSec tunnel mode for site-to-site VPN connections. It was very difficult to find a third-party VPN gateway that would work with ISA Server 2000. But with the new ISA firewall, you can establish a IPSec tunnel mode site-to-site link with just about any third-party VPN gateway.
Because of the number of third-party VPN gateways available on the market today, it's not possible for us to go into detail on how to configure the ISA firewall to connect to each of these devices. The good news is that Microsoft has published a comprehensive set of documents on how to connect the ISA firewall to a number of popular VPN gateways. At the time of this writing, there are documents on how to connect the ISA firewall to the following VPN gateways:
Cisco PIX
Astaro Linux
SmoothWall Express
Generic third-party gateways
You can find these documents and more on the Microsoft ISA 2004 VPN documentation site at http://www.microsoft.com/isaserver/techinfo/guidance/2004/vpn.asp