Re: DMZ to Internal problem

Tech-Archive recommends: Speed Up your PC by fixing your registry



Hey Martijn,
I am not sure if you have got your answer or no. Neither do I wish to
comment on the design.
ISA has some other rules which are defined along with the explicit rules
that you define. This is the System Policy. I suspect that there is something
in there that may be coming in the way.

Vakharia


"Martijn" wrote:

> Thanx for this useless answer. But what I'm asking is how to get it to work.
> I don't need to know that it's a flawed design.
>
> I'm trying to setup a Exchange 2003 Front-End Server (This usually is
> located in the DMZ), but it seems that during the setup I need to use RPC,
> which by default is not allowed by the ISA 2004 firewall. How can I setup a
> situation that allows all traffic between the DMZ and the internal network?
> Without interferance of any kind.
>
>
>
> "A.Klimkin" <aklimkin at mail dot ru> schreef in bericht
> news:%23WIIS5XSFHA.3988@xxxxxxxxxxxxxxxxxxxxxxx
> > You've got flawed newtwork design here. You shouldn't place in DMZ any
> > trusted resource. DMZ is *untrusted* network. That is the whole idea of
> > DMZs. If the host should be a part of your domain, so place it on the LAN
> > side of the firewall and use server publishing to share its services (like
> > web, mail or so) with internet.
>
>
>
.



Relevant Pages

  • Re: WMATA crash & track circuits
    ... So what are you trying to prove, that ISA is the future? ... If PCs are needed to interface, then it does not matter, what PCs. ... If you design embedded solutions you need no ISA either. ... If you design for 10 years, yeah, then stuff will go kaputt. ...
    (sci.electronics.design)
  • Re: WMATA crash & track circuits
    ... I wonder if you ever designed for industry, those things never were an issue. ... There is not much a difference between the cosmic rays at that altitude and those on top of a high mountain. ... So what are you trying to prove, that ISA is the future? ... ISA was easy to design, I designed ISA cards for industry for a living, hehe. ...
    (sci.electronics.design)
  • Re: Perimeter Dare!
    ... This may have been the preferred methodology in the past, but ISA is designed specifically to protect published servers. ... If you've got the resources using a DMZ/Perimeter network is preferred ... If you have a very secure network design ... Should I just Publish my web server from my Internal Network? ...
    (microsoft.public.isa.enterprise)
  • Re: What am I missing? Routing Troubles
    ... topology design which is absolutely crucial to undstanding routing issues. ... and at least one location has an ISA. ... Internal destination: RemoteClients ...
    (microsoft.public.isa)
  • Re: Can anythink kill x86-64? (was Re: IPFs future?)
    ... front of an x86/AMD64 chip and measured the difference, ... There's simply too many other factors in system design ... to consider any "ISA" comparison to be meaningful these days. ... Comparing NetBust to the P6/PM or Hammer proves this even within the same ISA. ...
    (comp.arch)