dmz server access issue



Hi all,

I have setup a new network configuration and am using ISA Server as my
proxy/firewall for my Internal Network. Here is my setup

CISCO Firewall - 172.19.1.1

Web Server 1 - 172.19.1.5
Web Server 2 - 172.19.1.6

ISA Server - 172.19.1.4 (External) & 172.19.2.4 (Internal)

AppServer - 172.19.2.21
DBServer - 172.19.2.41
Workstations - 172.19.2.100 - 172.19.2.254

I need to allow the web servers access to my database server and app server.
So here are the steps I did:

1. Created a static route on the web servers and specified to use 172.19.1.4
as the gateway.
2. Created a new Network on the ISA Server and gave it the ip address range
172.19.1.5 to 172.19.1.40. Named it DMZ Computers
3. Created a new Network Rule in ISA: Source - DMZ Computers. Destination:
Internal and finally chose Route traffic.
4. Created a new Access Rule which allowed All Outbound Access from DMZ
Computers to Internal for All Users.

I then tried to ping the database server from the Web Server and it didnt
work. I checked the ISA Monitoring logs and it was denying the connection.

What did I do wrong? Please help! I am running ISA 2004 on Win2k3 SP1.

TIA!


.



Relevant Pages

  • Re: ISA 2006 configuration question - multiple VLANs and domains
    ... very familiar with network segments vs. domains et. al. ... multihomed ISA 2006 server forward a DHCP request to the proper VLAN ... ISA is a Firewall Product designed to protect a network from the Internet. ...
    (microsoft.public.isa.configuration)
  • RE: Firewall service and remoteaccess service shut down frequently
    ... Do you have run the CEICW after installing the ISA components? ... please open SBS server management console, ... Click the Add Adapter button, and add your internal network adapter ... Meanwhile, from the subject, you said you the firewall service and RRAS ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN breaks after installing patches
    ... I have just received your email due to some network traffic problems. ... access the network shares was denied by ISA Server. ... Open the Server management console, navigate to "Internet and E-mail", ...
    (microsoft.public.windows.server.sbs)
  • Re: Connect the SBS to a remote IIS for Internet Printing
    ... the server can access the Internet with no problems at all. ... Checking network connection, and after a few seconds it says The ... the problem is cause by the configuration of ISA. ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA 2006 and SSL
    ... Because the ISA 2006 is a new ... | 3) From your port I am reading things about publishing to a web server. ...
    (microsoft.public.isa)