Re: using my ISA for some routing




"Alex" <nospam@xxxxxxxxx> wrote in message
news:%23OrinB6oIHA.5836@xxxxxxxxxxxxxxxxxxxxxxx

Currently my user's default gateway is my WAN router and for access to the
itnernet they're using my ISA 2006 server as a proxy server by specifying it
in Internet Explorers proxy settings (done by GPO).

GPO for this is a bad deal. It cannot properly handle machines that
travel,..like laptops.

I'd like to move away from using the proxy settings (for various reasons)
and set my ISA 2006 server as the users default gateway so they have
direct internet access, however I still need them to access machines in
other offices over the WAN ...

I don't know why you would want to go "backwards" in security and control.
SecureNAT Clients cannot authenticate, therefore all Access Rules must be
anonymous.

I don't really want to fiddle and add manual routing entries for every
user, so is it possible to tell ISA 2006 server that when it see's traffic
for ip addresses ranges that match my other offices (they are defined as
internal) to pass it onto to my WAN router and what sort of area of ISA
2006 should I be looking to implement this?

Impossible to answer. SecureNAT functionality is based on the LAN's Routing
Scheme (I should say the *correctness* of it),...it is not based on making
the ISA the Default Gateway of Clients,...that is only in "simple"
single-subnet LANs.

Requires 2 things:

1. I need to know and understand the LAN's Routing Scheme

2. You need to be willing to change the Routing Scheme if it is not optimal.

Or...

Forget the whole SecureNAT, Configure the LAN for Proxy Auto-detection via
WPAD and install the Firewall Client on the machines. This is the best
option, the most flexable, requires no topology change, requires no routing
changes, and will automatically adjust for clients that travel.


--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.mspx

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------


.



Relevant Pages

  • Re: ISA 2004 & companyweb
    ... Server, the traffic will still be handled by the ISA Server because the ... "Bypass proxy server for local addresses" option is disabled, ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA server 2004 and Bluecoat proxy
    ... i want to mention that we have configured a backup rout (backup bluecoat ... i want to ask about event 14130 that related to web proxy chain fauilire. ... If you were able to work around the upstream proxy server, ... upstream ISA Server, you might want to change it back. ...
    (microsoft.public.isa.configuration)
  • RE: Proxy Server in SBS 2000
    ... sites through port 443. ... If you install ISA 2000 on the SBS 2000 server, ... Connections->LAN Settings, tick the Use proxy server for your LAN, and then ... Is ISA 2000 installed on the SBS Server? ...
    (microsoft.public.windows.server.sbs)
  • Poor client web browsing performance
    ... I've switched all our users from an old proxy 2.0 server to ISA 2004, ... That DNS server is configured with the ISA server's internal NIC ... The first firewall policy rule is called "unrestricted internet ...
    (microsoft.public.isa.configuration)
  • Re: Need help with ISA setup.
    ... Key in your SBS (ISA) Server's NetBIOS name and port 8080 in the Proxy Settings boxes. ... Click the Action tab and choose Routing them to a specified upstream server. ... Point the default gateway to the ISA Server and the clients will be a SecureNAT client. ...
    (microsoft.public.windows.server.sbs)

Loading