When you use Microsoft Internet Security and Acceleration (ISA) Server 2004 to perform network address translation (NAT), an Internet Protocol security (IPSec) policy that is set through Group Policy is not applied to traffic after the traffic is translated. For example, IPSec policy is not applied in the following scenario:
1. | There is an IPSec policy defined for traffic between an internal host and the ISA Server 2004-based computer that is performing NAT. |
2. | Traffic from an external host or a virtual private network (VPN) client is received by the ISA Server 2004-based computer, and is then translated by using NAT before it is sent to the internal host. |
In this scenario, the traffic that is sent from the ISA Server 2004-based computer to the internal host has no IPSec encapsulation.