Re: Web access through 2 external IP addresses



Thanks Gershon,

The task that I need to acomplish is that I have two e-mail servers, one is
located on internal network and one on DMZ. And I need that one server is
using one public IP address for outgoing SMTP and the other server the other
public IP also for outgoing SMTP.
Can I acomplish this by making route relationship DMZ to external network,
and assigning public IP to server in DMZ zone? But there are another things,
I need to have VPN access to this DMZ server and the public IP address
needed for DMZ server is also using one published web (HTTPS) server on
internal network.

Is there a way?

Gatis



"Gershon Levitz [MSFT]" <gershonl@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:064E02D8-4C06-4C4D-977F-A050A9555CF6@xxxxxxxxxxxxxxxx
Hi Gatis,

Packets that orginate from the Internal and DMZ networks that have a NAT
relationship with the External network, will always use the primary IP
address of the external network adapter. This is the case for ISA 2004 and
2006.

What are you trying to accomplish and why do you need to do it this way?

--
Thanks,
Gershon Levitz
ISA Server Product Team
=====================================================
This posting is provided "AS IS" with no warranties, and confers no
rights.



"Gatis Vilc?ns" wrote:

Hi,
I have ISA 2004 EE with 3 network interfaces: internal, DMZ and external.
To my external interface i have asigned two public IP addresses.
How is it possible form me to configure that some users are using one
external IP address to access web, and some other users ar using the
other
public IP to access web?

Thanks

Gatis





.



Relevant Pages

  • Re: Unable to join AD domain from DMZ network
    ... > the captured traffic between the server in DMZ to the DC from internal ... >> unless you lock it down to a specific port. ... >>> authentication from DMZ to 2003 AD internal network. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Gurus: server on perimeter vs. corporate advice
    ... But if you put the Sharepoint in the "DMZ", you would need to open various ... ports to allow communication from the DMZ to the Internal network (I think ... When you "open" such ports for a server that resides in the DMZ, ...
    (microsoft.public.security)
  • Re: [fw-wiz] Rationale of the great DMZ
    ... >DMZ and its implied security has changed. ... Network activity wouldn't ... >necessarily begin from the DMZ and be tunneled in to the internal network. ... >Commonly SSL accelerators terminate the SSL end point prior to the ...
    (Firewall-Wizards)
  • Linux, New Corporate Network, Cisco Routers, T1 Ethernet Handoff, DMZ...
    ... I am setting up a network for a company that I am part owner of. ... internet go into my Cisco 2621 router that has 3 10/100Mbs FE interfaces. ... the same switch creating the "sandwich" DMZ setup with the public devices in ... PBX server that uses a straight VoIP connection all the way to our service ...
    (comp.os.linux.networking)
  • New Corporate Network, Cisco Routers, T1 Ethernet Handoff, DMZ...
    ... I am setting up a network for a company that I am part owner of. ... internet go into my Cisco 2621 router that has 3 10/100Mbs FE interfaces. ... the same switch creating the "sandwich" DMZ setup with the public devices in ... PBX server that uses a straight VoIP connection all the way to our service ...
    (comp.security.firewalls)