Re: ISA 2006 Basic Configuration



Guys.. I'm getting no luck :(
Please help me as you can, just initial setup to get the traffic in and out

Look, I have a eth cable from out ISP with public IP 162.168.x.x
I got a two server IT, one of those is ISA with two NIC cards
One NIC is set up using 162.168.x.x. , mask and ISP's GW and no DNS (Use the following, but empty)
Second internal NIC is set up using 10.0.1.1, mask, no GW and internal DNS (10.0.1.2, in the second server)

What should I do next, I can't figure out?

My ISA says this:

Description: The routing table for the network adapter Internal includes IP address ranges that are not defined in the array-level network Internal, to which it is bound. As a result, packets arriving at this network adapter from the IP address ranges listed below or sent to these IP address ranges via this network adapter will be dropped as spoofed. To resolve this issue, add the missing IP address ranges to the array network.
The following IP address ranges will be dropped as spoofed:
External:10.0.0.0-10.0.0.0,10.0.100.1-10.0.255.255;

ISA Server detected routes through the network adapter External that do not correlate with the network to which this network adapter belongs. When networks are configured correctly, the IP address ranges included in each array-level network must include all IP addresses that are routable through its network adapters according to their routing tables. Otherwise valid packets may be dropped as spoofed. The following ranges are included in the network's IP address ranges but are not routable through any of the network's adapters: 10.0.0.0-10.0.0.0,10.0.100.1-10.0.255.255,10.255.255.255-10.255.255.255;. Note that this event may be generated once after you add a route, create a remote site network, or configure Network Load Balancing and may be safely ignored if it does not re-occur.

Thank you in advance.

"John" <a> wrote in message news:#GSia9jqIHA.1872@xxxxxxxxxxxxxxxxxxxxxxx
I have just installed Windows Server 2003 R2 SP2 on a machine that has 2 NICs. This is a standalone machine. My next step is to join Windows Server 2003 AD domain. After that, I'll install ISA2006 on this machine.

I'm not sure how to configure the internal and external NICs, gateway, preferred/alternate DNS etc. If I understand correctly, it should be as follows:

External NIC (I do have a real static IP - but it's not the one shown below)
IP: 1.2.3.4 / 248
Gateway: 1.2.3.1 / 248
DNS: should I use Windows 2003 DNS in the trusted LAN or ISP's DNS??

Internal NIC (private IP)
IP: 192.168.1.2
Gateway: <empty> ??
DNS: I think the internal interface should point to Windows 2003 DNS but feel free to correct me


I'm also looking for a basic ISA configuration settings (walk thru or read me documentation). Can someone point me in the right direction? Thanks much.

.



Relevant Pages

  • Re: ISA 2006 Basic Configuration
    ... I have deployed a template that allow these: Web Access Only, Allow DNS to the Internet, VPN Clients to the internet. ... The routing table for the network adapter Internal includes IP address ranges that are not defined in the array-level network Internal, ...
    (microsoft.public.isa.configuration)
  • Re: ISA 2004 SP2 slow performance - could be DNS or AV?
    ... network element to which this adapter belongs. ... The following ranges are in the network's IP ... in/out via this network adapter and they are from/sent to the IP ... ISA Server relies on DNS lookups ...
    (microsoft.public.isa)
  • Re: Alert Configuration Error, please explain.
    ... ranges that are not defined in the array-level network ... The following IP address ranges will be dropped as spoofed: ... I don't know what an "array-level network Internal" is ... The routing table for the network adapter INTERNAL includes IP address ...
    (microsoft.public.isa)
  • Re: ISA 2006 Keeps Having Errors Event ID 21265 and 14147
    ... Disable the spoofing alerts. ... ISA Server detected routes through the network adapter Local Area ... the IP address ranges included ...
    (microsoft.public.isa)
  • RE: not seeing path to local domain
    ... WHEN YOU GO TO NETWORK NEIGHBORHOOD AND CLICK ON OUR DOMAIN THE FOLLOWING MESSAGE IS DISPLAYED "ABCFireControl is not available, The list of servers for this workgroup is not currently available." ... In the DNS console, right click your ServerName and click ... your ISP DNS server IP should be ... you can manually retry registration of the network adapter and its settings ...
    (microsoft.public.windows.server.sbs)