Re: Routing between internal network and DMZ

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Thank you for responding Phillip. So, there is not a way for the DMZ to get
internet acces then?

"Phillip Windell" wrote:

>
> "Keith" <Keith@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:563C547B-D87C-4864-94A1-5253B5CFE511@xxxxxxxxxxxxxxxx
> > We are running a tri-homed ISA server 2000. Our internal network is
> > 10.200.225.x, and we also have a DMZ, 10.200.135.x that is on a 3rd NIC.
> The
> > DMZ is not part of the LAT. I setup Site and Content Rules and Protocol
> > rules for our internal network to access the DMZ. This is working fine.
> I
> > would like the DMZ to access our internal network and the internet as
> well.
> > So I setup Site and Content Rules and Protocol rules for the DMZ as well.
> I
> > created a client set for the DMZ and put this client set in the rules.
> > However, machines in the DMZ cannot access our internal subnet or the
> > internet. What am I doing wrong? Can't I route traffic between the 2
> NIC's?
> > Are there any logs I can look at to help troubleshoot?
>
> .....with ISA2000
> No. You can't. The DMZ is an untrusted external network just like the
> Internet. The only way it can access internal resources is to "publish" the
> internal resource to the external Nic and then access it from the DMZ by
> going to the ISA's external Nic as if it was the resource.
>
> Things are all different with ISA2004. You can actually route between the
> internal and the DMZ networks and control it with Access Rules.
>
> --
>
> Phillip Windell [MCP, MVP, CCNA]
> www.wandtv.com
>
>
>
.



Relevant Pages

  • Re: AD in the DMZ - Any thoughts on this scenario?
    ... forest in a DMZ, not one that spans the DMZ and internal network. ... > in our internet facing DMZ. ...
    (microsoft.public.win2000.active_directory)
  • Re: Where to place the DMZ zone?
    ... hypothetically lets say you have no DMZ hosting an email bridgehead ... If a hacker were to compromise one of your email or web servers (they are ... That is, the Internet accessible servers ... that can be compromised are on your internal network, ...
    (microsoft.public.isa)
  • RE: Cracking a server without services
    ... The point is I'll have a linux firwall, connected to that the internet, ... It will however forward some ports to the DMZ ofcourse :-) ... comes from internal network. ... The servers on your DMZ is then, only as secure as how secure your ...
    (Security-Basics)
  • Re: Lets talk about firewalls - what do we as a group think a firewall should be/have?
    ... NAT, and the DMZ, since it's already secured, is a good place to tack ... If the "company" is not offering services to the Internet, ... and connections to the internal LAN should ... be by means of a second interface on the server. ...
    (comp.security.firewalls)
  • Re: Prividing Intranet Website Access To External Users
    ... I really wouldnt like to be having my company intranet on the ... I would probably integrate the ldap/dc as a security server on the ... >> The web server will be in the DMZ, and only port 443 will be ... >> intranets to the internet in a secure manner. ...
    (Security-Basics)