Re: ISA 2004 in DMZ, Web/Email Servers in Internal



=?Utf-8?B?TWFya0g=?= <MarkH@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
news:813D7C8F-7BA1-4717-90B9-2F9E69A90726@xxxxxxxxxxxxx:

I would like to install our new ISA 2004 Server into the DMZ and place
our Web/Email Servers in the Internal Network.


What do mean by placing ISA in the DMZ?

Do you mean a back-to-back config where you have:
internet--firewall--ISA--LAN

or somthing like:
internet--firewall--LAN
| |
ISA-------

The first on makes sense, if not unnecesseraly redundant. The second one
makes no sense at all.

Also, open port 443 from a 2nd NIC of the ISA 2004 server to the
Web\Email Servers.

Is this safe?

Is this recommended?

Is there a better alternative?

.


Loading