RE: CheckPoint + ISA2004 Nat'ing



Hi,

You should modify the NATs on your Checkpoint so that all traffic is
forwarded to the external interface IP of ISA instead of individual servers.
The ISA Server should have publishing rules defined that will take care of
which servers the requests will be sent to.

ISA server will take care of both IP based and username based rules.
Checkpoint would be used as a second level of security in front of the ISA.
--
Shijaz
MCSE:Security, CCNA
www.shijaz.com/isaserver


"New comer" wrote:


Hi all,
At present, we have network as describe below:

Internet
|
|
CheckPoint ---------- Web server (static Nat), Name server (static Nat) [DMZ
segment]
|
|
LAN
Please take note that CheckPoint' rules base on IPs of workstations.

Now, we would like to have ISA 2004 behind CheckPoint acting as Back to Back
firewall model.The next step I have to move DMZ segment from Checkpoint to
ISA 2004 to enhance security.

Internet
|
|
CheckPoint
|
|
ISA ---------- Web server (static Nat), Name server (static Nat) [DMZ
segment]
|
|
LAN
The question is:
1/ Our servers' NATTING still available after movinh from CheckPoint - DMZ
to ISA - DMZ ?
2/ My boss want ISA will be in charge authenticate base on username and
checkpoint will be in charge authenticate base on IP. Is this possible ?
3/How can IPs from LAN still remain their IPs after traverse thru ISA ? I
confuse a litle bit about Nat'ing, can anyone explain me more ?

Please help and thanks in advance.




.



Relevant Pages

  • Re: CheckPoint + ISA2004 Nating
    ... servers.If those servers in DMZ segment have been nated then the Incomming ... You should modify the NATs on your Checkpoint so that all traffic is ... forwarded to the external interface IP of ISA instead of individual ...
    (microsoft.public.isa.configuration)
  • Re: CheckPoint + ISA2004 Nating
    ... You will have to publish the servers on ISA. ... publishing can be done based on the ... There is no NATing to DMZ from Checkpoint. ...
    (microsoft.public.isa.configuration)
  • Re: back to back DMZ
    ... As in a back to back DMZ ISA configuration,.. ... The Servers still have to talk to the LAN,..if ... Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa)
  • Re: back to back DMZ
    ... The views expressed, are my own and not those of my employer, or Microsoft, ... As in a back to back DMZ ISA configuration,.. ... The Servers still have to talk to the ...
    (microsoft.public.isa)
  • Re: back to back DMZ
    ... DMZ at all) rests with you and your design skills. ... Jim Harrison (ISA SE) ... but what does microsoft say about this, ... The Servers still have to talk to the LAN,..if ...
    (microsoft.public.isa)