Re: ISA 2004 VPN Client can access DMZ but not Internal Domain

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



How is your ISA 2 configured? If you have internal and external conguration,
you will need to publish the internal domain to the DMZ.

hope this helps!


"FijianTribe" <FijianTribe@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:FB3D2FC7-5DDF-456B-B4E0-E32C4F848C90@xxxxxxxxxxxxxxxx
My setup looks like this:

(Internet) -> (ISA 1) -> (DMZ) -> (ISA 2) -> (Internal Domain)

ISA 1 & ISA 2 are two different machines. One serves as a front end and
the
other serves as the backed fire wall.

On my test DMZ I have a single machine that acts as a Domain
Controller/RADIUS Server/DNS/WINS/DHCP.

My VPN clients can authenticate and access all machines on the DMZ. They
also seem to see the ISA 2 server, and even resolve IP addresses for
machines
on the Internal domain.

The problem is that they cannot access any machines through the ISA2
server.

Any thoughts on where I can start? TechNet only seems to discuss the
solution for 2000 ISA.


.



Relevant Pages

  • Re: ISA and hardware firewall
    ... the hardware firewall is faster. ... someone breach an hole in your first firewall, there is always ISA protecting ... internet from the DMZ before publishing them to the internet. ... can put certain machines in the DMZ between the two firewalls,..but you ...
    (microsoft.public.isa.configuration)
  • Re: ISA and hardware firewall
    ... ISA has never been hacked. ... can put certain machines in the DMZ between the two firewalls,..but you ... The only thing I can think of is that the machine in the DMZ would be ... But then if those machines need to contact the LAN or the ...
    (microsoft.public.isa.configuration)
  • Re: IPSec question
    ... Why not to put FEs in the DMZ ... And a lot of people tend to think that the machines in the DMZ are "safe" ... And the reason why ISA is recommended? ... So if you are happy with the level of integration ...
    (microsoft.public.exchange.setup)
  • Re: IPSec question
    ... Why not to put FEs in the DMZ ... And a lot of people tend to think that the machines in the DMZ are "safe" ... And the reason why ISA is recommended? ... So if you are happy with the level of integration ...
    (microsoft.public.exchange.admin)
  • Re: IPSec question
    ... Why not to put FEs in the DMZ ... And a lot of people tend to think that the machines in the DMZ are "safe" ... And the reason why ISA is recommended? ... So if you are happy with the level of integration ...
    (microsoft.public.exchange.clients)