I don't understand this



This is a chunk of text of the book of Thomas Shinder's, I refer to the last
paragraph. It is the first step to create a dmz.


In the lab network that we're using for the examples in this section, the
external network host is on the same network ID as the external interface of
the ISA firewall, which is 192.168.1.0/24. The external IP address on the
ISA firewall is 192.168.1.70 and the external host will use an IP address
assigned in the same network ID. The DMZ segment uses the network ID
172.16.0.0/16. Therefore, on the Windows XP external network host we use in
this section, we configured a routing table entry to tell it to use the
external IP address of the ISA Server 2004 firewall to reach network ID
172.16.0.0/16. Specially, here's what we did:

route add 172.16.0.0 MASK 255.255.0.0 192.168.1.70Note that this example
does not use a subnet of a public address block. In your production
environment, you would subnet your public address block and create a routing
table entry for your DMZ segment's subnetted block on your router upstream
from the ISA Server 2004 firewall. This implies you have control over the
upstream router, which makes public address DMZ segments a moot point for
hobbyist ISP accounts. However, there's no reason why you can't create
private address DMZs with a hobbyist ISP account.
--
Regards



.



Relevant Pages

  • Re: Third NIC
    ... the 192.168.16.x network between the two nics for internal (third is ... Have created an ISA protocol to define the DMZ as the 192.168.x.x subnet ... Create a web service on the primary domain to allow traffic from a ...
    (microsoft.public.windows.server.sbs)
  • Re: [fw-wiz] Rationale of the great DMZ
    ... >DMZ and its implied security has changed. ... Network activity wouldn't ... >necessarily begin from the DMZ and be tunneled in to the internal network. ... >Commonly SSL accelerators terminate the SSL end point prior to the ...
    (Firewall-Wizards)
  • Re: Firewall and DMZ topology
    ... attacker cannot spread his influence across the network. ... If the DMZ resides between the public Internet and the ... Should the DMZ be behind the LAN and not split off at the firewall, ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)
  • RE: SUS server
    ... Where in my network should I place the SUS server? ... Everything inside my network can talk to the DMZ, ... SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers of ...
    (Focus-Microsoft)
  • RE: 504 Proxy timeout only with SSL traffic
    ... the DMZ network is considered External to the ... this may have an effect when you access the DMZ. ... And can access all other HTTPS sites on the internet? ... that there may be something wrong with the proxy engine on the ISA, ...
    (microsoft.public.isa)