Re: Cannot web internal servers from firewall clients via ISA2K4

From: Phillip Windell (_at_.)
Date: 10/22/04


Date: Fri, 22 Oct 2004 15:40:08 -0500

Sorry, ISA2004 has no LAT like ISA2000 did, instead it uses "networks" that
must be properly designed as being internal (on the LAN) or being external
(on the Internet side). But it is still the same principle, so it must be
done right.

-- 
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com
"Phillip Windell" <@.> wrote in message
news:%23HDa4WHuEHA.3152@TK2MSFTNGP14.phx.gbl...
> "KingBuzzo" <KingBuzzo@discussions.microsoft.com> wrote in message
> news:AC67955E-8D2E-4D54-B95D-3A18C74EAF95@microsoft.com...
> > When a user tries to access a web server on the internal LAN, it cannot
be
> > reached.  However, the user can ping the server.
> > This is same if they are trying to http a printer, the pbx, or whatever.
> > Does ISA intercept the HTTP request even though there is a browser
setting
>
> Sometimes...
>
> > to NOT use the PROXY for a local address?
> > What am I missing here?
>
> The Firewall Client and the Firewall Service...
>
> > Do I have to also setup an HTTP rule to web to a local box?
>
> No. ISA is for handling traffic to the Internet, not to other machines on
> your LAN.
>
> Configure the LAT properly.  It should list all LAN Address Ranges, but
> never Internet Addresses.
>
> Configure the LDT properly. It should contain the internal Active
Directory
> Domain Name.
>
> -- 
>
> Phillip Windell [MCP, MVP, CCNA]
> www.wandtv.com
>
>


Relevant Pages

  • http
    ... I have a small lan which connects to internet through the cable. ... Only HTTP with/out directly IP addressalways display this message in IE ... I disabled ISA server, the NIC for the ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Moving Exchange Server
    ... Placing them in the LAN gives internal users 100% access with no firewall to ... DMZ, thus 0% risk/ports open between them. ... If Microsoft Exchange and/or Active Directory cannot run ... >> Internet is better? ...
    (microsoft.public.exchange.setup)
  • RE: Firewall Rule Set not allowing access to DNS servers?
    ... > My LAN is configured with static IP addresses, ... > I have full connectivity with the internet from every machine on my ... > # Allow out access to my ISP's Domain name server. ... > # Interrogate packets originating from the public internet ...
    (freebsd-questions)
  • RAS - Routingproblem? DNS? Wins?
    ... ging übers Kabelmodem ins Internet und die andere ins LAN. ... Adapter und über diesen nam der Router externe Anrufe unseres Aussenlagers ... anderen PCs ganz normal mit 1 Netzwerkkarte im LAN angehängt ist. ...
    (microsoft.public.de.german.windowsxp.networking)
  • RAS - Routingproblem? DNS? Wins?
    ... ging übers Kabelmodem ins Internet und die andere ins LAN. ... Adapter und über diesen nam der Router externe Anrufe unseres Aussenlagers ... anderen PCs ganz normal mit 1 Netzwerkkarte im LAN angehängt ist. ...
    (microsoft.public.de.german.windowsxp.networking)

Quantcast