multiple web listeners with certificates

Tech-Archive recommends: Speed Up your PC by fixing your registry



Hi,

I am running isa 2006 behind a pix firewall.

I have two nics and the external nic is using 192.168.x.x which seems to
work OK.

The problem is I am unsure how to set the web publishing rules for multiple
web sites all using certificates.

To explain:

I have three sites on a web server all running SSL certificates listening on
443. I have followed the instructions to export a copy of the certificate
from the web server to the ISA server.

I have registered the external ip address of the pix firewall in external
dns for the web addresses.

I have a rule on the PIX to throw all https requests received on the pix
external interface to IP 192.168.x.x which is the external interface of the
ISA server.


When I try to three web listeners each using one of the copied certificate
it fails complaining that the ip address or port are being used on another
listener.

I suppose I could add another 192.168.x.x address to the external interface
of the isa but I would also in this scenario have to have multiple external
ip addresses to create a new rule on the pix to give me the one to one rule.

Surely my setup is not that different to others.

So could someone explain the best way for me to set this up?

Thanks


.



Relevant Pages

  • Re: Firewall Frage
    ... Je nach dem welche PIX du dir zulegst, ist die PIX in der Anschaffung sogar ... günstiger als ein ISA Server! ... Nun zum Thema VPN: ...
    (microsoft.public.de.german.isaserver)
  • Re: ISA Configuration question
    ... ISA does *not* require itself to be the Default Gateway of the Clients. ... If you want the ISA to be only used for HTTP/HTTPS and browser-based FTP ... Leave the PIX as the Default Gateway like it already is. ... add the static routes for the public addresses. ...
    (microsoft.public.isa)
  • Re: Security
    ... I would use a combination for your network layout:) You could use ISA ... depth and the PIX allows unnecessary/unwanted traffic to be removed on the ... Subsequently I would use two Nics in your SBS server with the topology ... how do I open ports to allow e-mail to come directly to my ...
    (microsoft.public.windows.server.sbs)
  • Re: CSS cant talk to array members in workgroup config
    ... Trying to play the "port" game with RPC across a basic L3 ... PIX doesn't understand RPC, but ISA does. ...
    (microsoft.public.isa.enterprise)
  • Re: ISA Verses Cisco PIX in Exchange 2003 Front End - Back End Top
    ... pix, but with alot of trial and error, and how many holes in the firewall ... I like the way you put it "extension of the Exchange infrastructure" ... ISA 2004 Enterprise it is! ...
    (microsoft.public.exchange.setup)