Re: one to one NAT

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Matt-Helm (anonymous_at_discussions.microsoft.com)
Date: 08/17/04


Date: Tue, 17 Aug 2004 04:50:44 -0700

Hey! THANKS!

I just really wanted to know if I could do that or not =)

I guess I cant, which is fine. So now if I wanted to use
ISA 2004 as a back fire firewall how would I go about
setting it up?

Do I still need two network cards? Do I use the route
option instead of the NAT option?

Is there some sort of tutorial that explains this?

Any help is appreciated!

Thank
helm
>-----Original Message-----
>Hi Matt,
>
>All outbound connections will have the source of the
primary address on the
>external interface of the ISA firewall. If you want a
NAT server, CP is a
>good bet (PIX is a good NAT server too). If you need a
firewall, ISA is the
>firewall of choice.
>
>HTH,
>--
>Tom
>www.isaserver.org/shinder
>Get the book!
>Tom and Deb Shinder's Configuring ISA Server 2004
>http://tinyurl.com/3xqb7
>MVP -- ISA Firewalls
>
>
>"Matt-Helm" <anonymous@discussions.microsoft.com> wrote
in message
>news:005001c483e1$00da6710$a301280a@phx.gbl...
>: Well.. Could you please help me wrap my head around
what
>: I'm suppose to do if I have a client with the ip
>: 10.1.1.25 -> whatever.outside.ip.25 This client is
using
>: a VPN for EDI on a specific port on a specific external
>: IP that is being mapped to the internal one.
>:
>: Now on the ISA 2004 box i can certainly add that
external
>: IP to the outside interface, not a problem. I still
cant
>: figure out how to "publish" this to work.
>:
>: What do I do?
>:
>: Thanks
>: Helm
>: >-----Original Message-----
>: >
>: ><anonymous@discussions.microsoft.com> wrote in message
>: >news:6d7f01c483b0$b97d0ec0$a501280a@phx.gbl...
>: >> "You don't"
>: >>
>: >> Don't what?? I want to do ONE TO ONE NAT! Either I
can
>: or
>: >> I cant with ISA 2004! =)
>: >
>: >You don't do One-toOne NAT. That is what you do with
a
>: NAT box,.... not
>: >with ISA. ISA is not a "nat box" it is a proxy server
>: and that is and
>: >entirely different technology.
>: >
>: >>I have been working with ISA 2004 Beta and searching
>: for what appears to
>: >be
>: >> not possible. MS really needs to include a static
nat
>: feature in ISA if
>: >it's
>: >> ever going to fully replace the Cisco,
Checkpoint, ...
>: environments. I've
>: >
>: >No, it doesn't have to do that to replace those. The
>: problem is that you
>: >have the wrong method stuck in your head as if one-to-
>: one nat was the only
>: >way of doing things. It is not the only way to do
>: something. With ISA you
>: >use the "Publishing" features. Use the Server
>: Publishing features like I
>: >told you in the last post.
>: >
>: >--
>: >
>: >Phillip Windell [MCP, MVP, CCNA]
>: >www.wandtv.com
>: >
>: >
>: >.
>: >
>
>
>.
>



Relevant Pages

  • Re: Must I be forced to Upgrade from SBS 4.5?
    ... Just sometimes with security you need to be political, a NAT only customer ... "wrong" if no "industrial strength" firewall is not installed, ... The good thing about ISA is that it can be updated ...
    (microsoft.public.backoffice.smallbiz)
  • Re: Webproxy und Firewallfehler
    ... Der ISA will der einzige auf dem ... Rechner sein, der NAT anwendet. ... Verbindung die Firewall akiviert hast, wenn ja, dann deaktiviere auch diese. ... Angeblich soll die Netzwerkkarte nicht richtig funktionieren. ...
    (microsoft.public.de.german.isaserver)
  • Re: I hope ISA is what I think it is
    ... lastest version of ISA will be called TMG. ... PAT would be part of the same Server Publishing except that the listening ... So it would effectively be Static Nat with PAT or maybe just SNAT/PAT ... The Firewall Service is a Winsock based ...
    (microsoft.public.isa.configuration)
  • Re: Should I still buy SBS 2003 Premium w/ ISA in light of XP SP2s ICF2?
    ... NAT firewalls operate on the "you asked for it, ... Does the ISA server in SBS 2003 run a full application layer firewall? ... I know XP SP2 is not a firewall in relation to ISA. ...
    (microsoft.public.windows.server.sbs)
  • Re: one to one NAT
    ... The key to the back-end firewall config is to make the ISA firewall a member ... option instead of the NAT option? ... :>Tom and Deb Shinder's Configuring ISA Server 2004 ...
    (microsoft.public.isa)