Re: ISA 2006 Basic Configuration

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Phillip, thanks for your quick reply.
more inline...

"Phillip Windell" <philwindell@xxxxxxxxxxx> wrote in message
news:uRyZmDkqIHA.4492@xxxxxxxxxxxxxxxxxxxxxxx
External nic:
IP
Mask
Gateway
No DNS
No WINS
Configure Nic to not register itself in DNS

IP 1.2.3.4
Mask 255.255.255.248
Gateway: 1.2.3.1
DNS <blank>
WINS <blank>
Register this connection's addresses in DNS (UNchecked) - is this necessary?
If there is no DNS on the external NIC, there's nothing to register.

Internal
IP
Mask
No Gateway
LAN's AD/DNS
LAN's WINS

IP 192.168.1.2
Mask 255.255.255.0
Gateway <blank>
DNS 192.168.1.10 and 192.168.1.11 (both are internal AD DNS)
WINS 192.168.1.10

Internal Nic should be first in the Binding order.

It is. I've reconfirmed it.

First Access Rule in ISA Rule List needs to be:
Source: AD/DNS Server
Destin: External
Protocol: DNS
Users: All Users

I'm not there yet so I can't comment.

LAN's AD/DNS needs to list the ISP's DNS in the Forwarders List in the MMC
of the DNS Admin Tool. This can optionally be left blank which allows the
DNS to use Root Hints instead.

Forwarder IPs are already listed for quite some time.

Which setting should I use on either NIC?
- Disable NetBIOS over TCP/IP (or enable?)
- Client for for Microsoft Network (unchecked or checked)
- File and print sharing for Microsoft Network (unchecked or checked)

I'll have a look at the links in your sig. Thanks again.


.



Relevant Pages

  • Re: AD DC registering private IP as AD DNS
    ... so we have a Server 2003 Domain Controller which also runs DNS. ... Unchecking the "register this connection's IP in DNS" box ... NICs, when opening ADUC or any other domain requests, it maybe getting the ...
    (microsoft.public.windows.server.dns)
  • Re: srv2008 dc self register ip address on dns
    ... With one NIC you can not disable DNS registration. ... And if both NICs from the same subnet remove one, still multihoming because more then one ip address. ... Flag "register this connection's addresses in DNS" is complilty ... The one section of the article that disables these records is ...
    (microsoft.public.windows.server.dns)
  • Re: Win 2003 Server wont stop registering DNS addresses
    ... "Register this connection's address in DNS" field under advanced ... When there are multiple NICs, ... The one section of the article that disables these records is done with ...
    (microsoft.public.windows.server.dns)
  • Re: Stop Auto Register
    ... only want a specific IP to register, ... Multihomed DCs, DNS, RRAS servers and any other servers that you don't want ... When there are multiple NICs, ... multihome a non-DC then having to alter the DC. ...
    (microsoft.public.windows.server.dns)
  • Re: srv2008 dc self register ip address on dns
    ... Flag "register this connection's addresses in DNS" is complilty useless, ... Being a VPN Server and even simply running RRAS makes it multi-homed. ... When there are multiple NICs, ...
    (microsoft.public.windows.server.dns)