Problem Receiving Internet E-Mails On ISA/Exchange Server

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Imran Vilcassim (mvimran_at_hotmail.com)
Date: 08/06/04


Date: Thu, 5 Aug 2004 22:05:44 -0700

Hi,
    do this. remove the public ip in the isa server and
assign an ip which is in the same range as the private ip
of the NAT Device. confugure a NAT rule which forwards
mail traffic arriving on the external interface of the
NAT device to the external interface of the ISA server.
publish the exchange server in the ISA server.

Mohamed Imran Vilcassim (MCSE,MCT)
Technical Specialist - Microsoft MDP Sri lanka
email:mvimran@hotmail.com

>-----Original Message-----
>Sorry for the confusion. Yes, the external IP on the
ISA
>is a public IP. And the device performing NAT has both
a
>public IP and a private IP. The public IP on the NAT
>device is address translated to the private IP on the
ISA
>server.
>
>The DNS entry (I'm assuming you're referring to the MX
>record) points to the public IP address on the NAT
>device.
>
>Any ideas? Thanks again.
>
>>-----Original Message-----
>>hello,
>> your configuration is a little confusing? the
>>external ip u use on the ISA is a public IP is it? and
>>you say you have a device which performs NAT, what is
>>public and what is private here? where does you dns
>entry
>>point to?
>>
>>regards
>>
>>Mohamed Imran Vilcassim (MCSE,MCT)
>>Technical Specialist - Microsoft MDP Sri lanka
>>email:mvimran@hotmail.com
>>
>>>-----Original Message-----
>>>We are not able to receive Internet (outside) e-mails,
>>>but everything else works fine. We can send/receive
>>>internal e-mails and even send Internet e-mails. ISA
>>>Server and Exchange Server are installed on the same
>>>server, and the server has two nics.
>>>
>>>External nic IP address: 200.200.200.200 (w/def.
>>gateway)
>>>Internal nic IP address: 10.10.10.10 (no def. gateway)
>>>
>>>However, we also have a router which is performing
>NAT.
>>>So our router maps (NATs) our external "e-mail server"
>>>address of 250.250.250.250 (which is just the ip
>address
>>>of the serial interface on the router) to the internal
>e-
>>>mail (ISA) server IP address of 10.10.10.10.
>>>
>>>I've been trying to follow various documents on ISA,
>but
>>>have had no success. I don't know whether our
Exchange
>>>server is considered BEHIND the ISA server or ON the
>ISA
>>>server, because we are using the serial IP address on
>>the
>>>router for our external e-mail IP, instead of the
>>>external IP address on the ISA server (but Exchange is
>>>installed on the same server as ISA).
>>>
>>>Do I have to set up some form of access policy (like a
>>>packet filter) to receive Internet e-mails? If so,
>>could
>>>you please give me some guidance? Any help is
>>>appreciated. Thanks!
>>>
>>>
>>>.
>>>
>>.
>>
>.
>



Relevant Pages

  • Re: Natting external IP Address
    ... concept of Reverse NAT. ... Understanding the ISA 2004 Access Rule Processing ... Microsoft ISA Server Partners: Partner Hardware Solutions ... I need to NAT an external IP address with a private one. ...
    (microsoft.public.isa)
  • Re: NAT without DHCP? (w2k3)
    ... How I can troubleshoot the problem and see why ip packets from the private ... DNS works perfectly fine but nothing else. ... How does your server connect to the Internet? ... I also enabled NAT tracing - may be this can help? ...
    (microsoft.public.windows.server.networking)
  • Re: NAT without DHCP? (w2k3)
    ... is that dialog to configure address pool for the private network? ... (Just to add to the confusion there is another pool of addresses in RRAS ... If you want to use it, you configure a pool of IP addresses for NAT ... is enabled on the public interface of the RRAS server already. ...
    (microsoft.public.windows.server.networking)
  • Re: NAT and RDP ?
    ... NAT device from a Client on the private side of the LAN. ... If the Resource is bound only to the Public IP# of the Server (like IIS can do ...
    (microsoft.public.windows.server.networking)
  • Re: RRAS Win2003: Cannot reach public IP reserved hosts behind our NAT
    ... From within our intranet we can access the machines by> their private addresses just fine, as these packets are not> routed to our RRAS box. ... The role of the IP# in Ethernet is only to provide a Layer3 routing> mechanism and to provide a means to resolve the MAC address. ... The> reason intranet host must use the private addresses to access the servers is> because NAT can't make "u-turns". ... When you send a packet to the external> IP# the "NAT" process takes it and creates a situation where the source and> destination MAC addresses in the packet headers are the same address. ...
    (microsoft.public.windows.server.networking)