Re: ISA serv 2004 one to one NAT

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: ABH (andyspamfee_at_hotmail.com)
Date: 10/26/04


Date: Tue, 26 Oct 2004 22:39:57 +0100


"Lucas Schick" <lucas@abc-computers.com> wrote in message
news:a6dcd78c.0410261139.3d634195@posting.google.com...
> really care what they want to call it. If Microsoft really wants to
> compete with the Checkpoints and Pix's of the world, I just think 1 to
> 1 NAT'ing is a basic function of a FIREWALL, which is what ISA is
> supposed to be.

I can only agree 100%

No matter what the technicalities and terminologies, if Microsoft want
ISA2004 to sell into the market place that currently has Checkpoint
installed then it really needs to add traditional 1:1 NAT with configurable
translation rules (like FW1).

We are in the (much slower than we hoped) process of replacing FW1 with
ISA2004 and have learned that some of what we do with Checkpoint simply
isn't possible on the Microsoft product.

As a result our single FW1 box is now being replaced by ISA2004, as our
primary Internet firewall, and an additional dedicated NAT router to connect
some of our PCs to a separate private network which needs 1:1 NAT to treat
our PCs as local (licencing and security is based on the IP address).

-- 
Andy 


Relevant Pages

  • RE: Questions about fw-1
    ... FW1 works well because it works at the lower levels. ... You can and should make the OS that runs the firewall as ... You should be able to do a search for hardening the OS for checkpoint. ... Solaris makes a far more secure OS to run Checkpoint FW1 off of than NT. ...
    (Security-Basics)
  • Re: VPN-1 Secureremote pass-through on a PIX 506
    ... I've seen this happen when the client site (behind a NAT router) is ... I've known this to be solved by setting up the Checkpoint ... This might not be the issue, since it works with the PIX. ... DSL router, fits with the symptoms I've seen. ...
    (comp.dcom.sys.cisco)
  • Re: IPSEC vs. PPTP, etc
    ... the combination of L2TP/IPSEC (ala Microsoft VPN) does NOT go ... >PPTP is no longer recommended by Microsoft for secure comms. ... >most of us and it can go through a NAT. ...
    (comp.security.firewalls)
  • Re: trust forests without trusts
    ... have external forests that I want to assign resources to. ... use NAT between the two forests, ... Instead of the website you're using, I suggest to use OEx (Outlook Express ... This is a direct link to the Microsoft Public ...
    (microsoft.public.win2000.active_directory)
  • RE: [fw-wiz] Checkpoint to Cisco - Hardware VPN works, software d oesnt
    ... Is the Checkpoint performing NAT on the software VPN's internal IP address? ... does that translation equate to the IP address that your Concentrator ... This tunnel works fine. ...
    (Firewall-Wizards)