RE: DMZ




1- ONLY the External NIC SHould have a Gateway !!! emove all the gateways
from the DMZ NIC & The Internal NIC

2- Only the Internal NIC Should have DNS Entry on it, and it should be to
your Internal DNS Server that should forward external requests to your ISP
DNS Servers, check this article for more info :
http://elmajdal.net/isaserver/Internal_DNS_Forwarding.aspx

3- THE DMZ NIC should have neither a Gateway nor a DNS setting on it!

HTH,
Tarek
--
_____________________________

Tarek Majdalani
Computer Engineer, CIW, MCSA: Security 2000/2003
http://www.elmajdal.net/ISAServer


"Rafael" wrote:

Hi

I installed ISA 2006 and implemented model 3 leg perimeter.
This implementing in LAN simulated INTERNET.

The network IP 10.0.4.0 - 10.0.7.255
I have in ISA 3 network card:

The External configure ip :10.0.6.1 gw 10.0.4.54 this router LAN, mask
255.255.255.248 e dns 10.0.4.61
The perimeter configure IP: IP: 10.0.6.2 gw
10.0.6.1 e mask 255.255.255.248
The INTERNAL configure IP 192.168.254.1.

In machine the DMZ:
IP:10.0.6.3 gw 10.0.6.2 mask 255.255.255.248


I configure in ISA network perimeter IP10.0.6.2 até
10.0.6.7 e 10.0.6.0
I access the network external in network perimeter in use ROUTE, i not
use NAT.
Add rules in ISA allow acess External to DMZ, and DMZ to EXTERNAL
But ping result TIMEOUT
I need help to problem?Configuaration IP this correct?





.



Relevant Pages

  • Re: Non-domain connection problem
    ... For some reason the DNS is persistent. ... connect new PC to the internet from the non-domain network: ... In server 2000 gpoedit.msc showed them but in SBS it is different. ...
    (microsoft.public.windows.server.sbs)
  • Re: Non-domain connection problem
    ... You said that you "hard coded the DNS server to a known DNS on the internet: ... Connect to Internet from Internal Network ... NSLOOKUP always looks for the SBS as the default gateway. ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA 2006 Basic Configuration
    ... Why would we point Preferred DNS to itself? ... Configuring the Internal Network Interface ... In the Internet Protocol Properties dialog box, ... Select the Use the following DNS server addresses option. ...
    (microsoft.public.isa.configuration)
  • Re: IE cant connect to any sites
    ... On the General tab in the Temporary Internet Files Folder, ... Click on "LAN Settings" and make sure everything is blank, ... Network settings ... IP address automatically", click on the DNS tab, disable DNS here, click ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: sasser virus; now I get page error every time I try to access the web and fail
    ... On the General tab in the Temporary Internet Files Folder, ... Click on "LAN Settings" and make sure everything is blank, ... Network settings ... IP address automatically", click on the DNS tab, disable DNS here, click ...
    (microsoft.public.windows.inetexplorer.ie6.browser)