ISA 2006 Enterprise install/config questions reference NICs
- From: "Bruce Lautenschlager" <brucel.spamless@xxxxxxxxx>
- Date: Mon, 7 May 2007 15:55:29 -0400
I'm setting up a 2 server ISA 2006 Enterprise array - and I have some
questions. Both running on Windows Server 2003 R2, with 3 NICs (one
internal, one external, one was going to be for DMZ...but...read on). The
system will be used for outbound Internet access from clients (mostly
browsing, some FTP, RDP, etc.) - it's not protecting any inbound stuff like
web servers. The servers are called ISA1 and ISA2 (clever, huh?).
1) A consultant we hired (familiar with single ISA deployments but not
Enterprise) said the internal NIC shouldn't have a gateway set in the GUI
TCP/IP Properties page, and I should manually add persistent routes (via
ROUTE ADD) to all my internal networks. This sounded odd. But I did it. Is
this correct?
2) He also said the external NIC should not have DNS servers configured -
the internal NIC DNS settings will query my internal DNS server. This sounds
okay, I suppose, and would appear to work.
3) I installed everything okay, but was occasionally seeing errors that the
second server (ISA2) couldn't contact the CSS (which I put on ISA1). Then it
would get resume contact. But the errors persisted, intermittently. He
suggested that we use the third NIC I was going to use for a DMZ and use it
for intra-array communications only - connecting the two servers with a
crossover cable, much as I do with a Windows Server Cluster. One NIC has an
IP address of 10.1.1.1 and the other NIC 10.1.1.2. This sounded odd - I
posted about this weeks ago and was told you don't need a dedicated NIC just
for this. I'm willing to do it - but it hasn't gone well. Intra array
communications only went downhill from there, and in fact after uninstalling
ISA 2006 from ISA2, I've never been able to reinstall it in the Array - I
get a host of errors during the install about not being able to contact the
CSS (where I didn't upon initial install) - but I will save that for another
post. I guess the question here is - is using a NIC with a crossover cable
for intra array communications between ISA1 and ISA2 okay, best practices,
or just pointless?
I'm at the point now where I just want one to work - and I'll focus on
getting the Array part together after that.
Thanks,
Bruce
.
- Follow-Ups:
- Re: ISA 2006 Enterprise install/config questions reference NICs
- From: Jim Harrison \(ISA SE\)
- Re: ISA 2006 Enterprise install/config questions reference NICs
- Prev by Date: Re: NLB
- Next by Date: Re: ISA2K4 EE missing Toolbox Network Object entries.
- Previous by thread: Re: NLB
- Next by thread: Re: ISA 2006 Enterprise install/config questions reference NICs
- Index(es):
Relevant Pages
|