Re: Any Way to Pass DHCP From Internal to Perimiter?



You are guessing wrong because of two reasons:

1) If you create an additional perimeter network in ISA as you intend that
has to be on a totally different subnet than your internal LAN, otherwise IT
WON'T BE a separate network. You cannot have an "external" (DMZ) network
using addreses from the same IP subnet as the LAN. And reason #2,

2) Regardless of the above DHCP operations are confined to the "physical"
subnet where the DHCP server resides. In order to make broadcast DHCP
queries travel from a given subnet to the one where the DHCP server is, you
have to install and configure the DHCP relay service on a machine in the
first subnet (your LAN in your case), that will relay all the queries to the
DHCP server on the other network segment. You could for example install the
DHCP relay service on your ISA server itself, then of course you will have
to configure the firewall rules to allow required traffic to flow. Remember
that in this scenario ISA server acts as both a DHCP server (for the
machines in the LAN) and a DHCP client (to the DHCP server on your AD
controller). You will therefore need the following:

-in the system policy you need to enable the Network Services/DHCP node and
specify domain controller's subnet as the "source" in the From tab

-for running the DHCP relay service (which behaves like a DHCP server to
clients in the Internal subnet), on the ISA computer, you can refer to the
following articles:

Configuring the DHCP Relay Agent on ISA Server 2004
http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/isadhcprelay.mspx

Configuring the ISA Server computer as a DHCP server:
http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/isaondhcpserver.mspx


Virgil





"Will" <westes-usc@xxxxxxxxxxxxxx> wrote in message
news:%236Nm5JMwFHA.3188@xxxxxxxxxxxxxxxxxxxxxxx
> We want to put our Active Directory server on a perimiter network in order
> to restrict access from rogue machines on the Internal network.
> Unfortunately, the Active Directory server also runs DHCP. How can you
> configure ISA Server so that DHCP broadcasts (requests) on the Internal
> network will pass through ISA to the Active Directory server?
>
> I'm guessing that you could subclass a single Class C network and have the
> Active Directory servers occupy a small address space within the same
> Class
> C used by your Internal network. But could you configure ISA to allow
> DHCP Broadcasts from the Internal network to pass to the subclass where
> the
> Active Directory servers reside?
>
> What other rules would be required? Probably you would need a separate
> rule to allow the DHCP replies travel from Active Directory to the
> Internal
> network?
>
> If anyone has an example of this configuration I would like to see it.
>
> --
> Will
>
>


.



Relevant Pages

  • Re: ISA 2006 configuration question - multiple VLANs and domains
    ... very familiar with network segments vs. domains et. al. ... multihomed ISA 2006 server forward a DHCP request to the proper VLAN ... ISA is a Firewall Product designed to protect a network from the Internet. ...
    (microsoft.public.isa.configuration)
  • RE: Firewall service and remoteaccess service shut down frequently
    ... Do you have run the CEICW after installing the ISA components? ... please open SBS server management console, ... Click the Add Adapter button, and add your internal network adapter ... Meanwhile, from the subject, you said you the firewall service and RRAS ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN, RRAS & DHCP
    ... After researching your logs, I found the Event ID 20169 ... Please try to set RemoteAccess service to depend on the DHCP server ... Reboot the server to see whether the issue still occurs. ... The problem occurred after you install ISA server. ...
    (microsoft.public.windows.server.sbs)
  • Re: DHCP Problem
    ... Internet Security and Acceleration Server 2004 Standard ... An ISA repair might be order. ... Why DHCP Stops Working After You Add a Custom Access Rule ...
    (microsoft.public.backoffice.smallbiz)
  • Re: VPN breaks after installing patches
    ... I have just received your email due to some network traffic problems. ... access the network shares was denied by ISA Server. ... Open the Server management console, navigate to "Internet and E-mail", ...
    (microsoft.public.windows.server.sbs)