Please Help - critical issue

From: Imran Vilcassim (mvimran_at_hotmail.com)
Date: 08/04/04


Date: Tue, 3 Aug 2004 21:55:36 -0700

Hi Jessie,
          can u explain what exactly you have tried to
do.. this info would help. but at a higher level the
following needs to be done.

(1)configure your Check Point firewall to allow the IP
address of the caching only ISA Server to access
outbound TCP 80, TCP 443, TCP 21 or any other protocols
that u desire.

(2)Ensure that the Web Proxy clients can resolve the ISA
server by the FQDN. Also ensure that the ISA Server can
access the CheckPoint Firewall.if the ISA Server and the
CP Firewall are on the same internal network, then this
shouldnt be a problem.

(3)Configure the TCP/IP Settings on the ISA Server.assign
the ISA Server a valid IP address and subnet mask, a
default gateway that will route Internet bound requests
to your Internet access device (CP Firewall),
and a DNS server that can resolve Internet host names.
The best option for the DNS server is an internal network
server that has been configured to use a Forwarder to
resolve Internet host names.

Note: Installing the ISA Server in cache only mode is a
bit different then what you might be used to if you
usually install in integrated mode. The main difference
is that there is no LAT to configure. The unihomed
caching-only ISA Server doesn't use a LAT because it's
connected to a single network; there is no concept of
internal and external, trusted or untrusted. The unihomed
caching-only ISA Server accepts requests for Web objects,
obtains the objects from the Internet servers, and sends
these objects back to the Web Proxy clients using the
same interface. The Incoming Web Requests and the
Outgoing Web Requests listeners are on the same physical
adapter.

(4)After Installing ISA, create your protocol rule and
your site and content rule.

(5)configure your browser to use the ISA server as a
Proxy server. this can be automated by using WPAD.

hope this helps.

Regards
Mohamed Imran Vilcassim (MCSE,MCT)
Technical Specialist - Microsoft MDP Sri lanka
email:mvimran@hotmail.com

>-----Original Message-----
>Hello everyone,
> i have been working day and night to fix
>this problem but still without any luck and my manager
is
>getting increasingly frustrated with me. i hope someone
>would be able to help me out with this problem.
>
>I have a server with ISA server installed on it. I also
>have checkpoint firewall as the perimeter firewall at
the
>gateway. i am trying to configure ISA as a caching
server
>on my intranet so that clients will access the intenet
>through the ISA server. i have tried many methods of
>doing this in combination with the cp firewall, but i
>have failed miserably. can anyone give me some guidlines
>as to how this can be done?
>
>Thanks a million in advance.
>
>Jessie
>.
>



Relevant Pages

  • Re: Firewall problem
    ... Forget Microsoft's suggestions about staying secure. ... > on of the most veritile firewall solutions arround. ... >> We're using MS ISA server as our firewall. ... >> However we can't connect telnet traffic, nor can I ping internet sites, ...
    (Security-Basics)
  • error downloading http://java.sun.com/webapps/download/GetFile/1.4.2-b28/windows-i586/Java 2 Runtime
    ... We are using an ISA server in cache mode to connect to internet. ... there is a viruswall and a firewall. ... the web-application for the first time, the Java Installer is launched. ...
    (microsoft.public.isa)
  • Re: CEICW fails - several errors
    ... The firewall isn't used when ISA is installed. ... On the WAN NIC of your server the DNS has to point to the LAN IP. ... I immediately checked and ISA Server ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA2004 client firewall slow webpage loading
    ... have you configured this new client as web proxy client? ... configure ISA server as your Proxy ... stop the Microsoft Firewall service. ...
    (microsoft.public.windows.server.sbs)
  • Re: CEICW fails - several errors
    ... On the WAN NIC of your server the DNS has to point to the LAN IP. ... Ethernet adapter Internet Connection: ... I immediately checked and ISA Server ... Management said that Web Proxy, Firewall and ...
    (microsoft.public.windows.server.sbs)