Re: Installing ISA Server in Trihomed DMZ firewall



Thanks for quick message. In fact company wants to keep the Sonicwall
firewall.

So, would this proposed configuration work and can you please give me
some understanding regarding configuration of the ISA & firewall, as I
don't have good experience in firewall.

Please help me by providing information that how I will configure ISA
in DMZ zone and what configuration I need on the firewall it self to
route web traffic and smtp traffic.

Thanks,

Lucky
Phillip Windell wrote:
<liaqatba@xxxxxxxxx> wrote in message
news:1146681139.564310.301460@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
internet, one for DMZ and one for internal. I want to install &
configure ISA sever in DMZ as web proxy server only, so it will not be
a firewall.

Then what good is it? Why waiste your money buying it? ISA is a better
product and more capable than the Sonic Firewall and should be replacing the
Sonic Firewall,...not being subjegated to a DMZ segment in a one-nic setup
that you could probably do with a linux box instead of spending $2000-$4000
for ISA and the hardware it sits on.

In DMZ I will also configure the SMTP server. I have
following questions:
1. In DMZ, may I use public or private IP addresses?

Depends on the Firewall's abilities and design.

2. For ISA server, may I just use one NIC and if I just use one NIC
then how I can configure it for web proxy?

The Web Proxy Serivice will run on one Nic. It is the only feature of ISA
that will.


--
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com

.



Relevant Pages

  • Re: SBS R2 ISA2004 Dark Arts
    ... ISA in SBS as intended or you'll get into trouble. ... I have to get the back firewall configuration to work with the ... network in the rules/policies. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS R2 ISA2004 Dark Arts
    ... Right now the front firewall is not an ISA ... NIC-2 faces the internal "Live" network. ... I have to get the back firewall configuration to work with the ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS R2 ISA2004 Dark Arts
    ... All my ISA 2004 installs also have another router in front of them. ... network configuration after running the CEICW is as an Edge Firewall not a ... Back Firewall. ... CEICW do the configuration and setup the proper default ISA rules and then ...
    (microsoft.public.windows.server.sbs)
  • Re: OWA_Frontend_Firewall
    ... >>the OWA server in the DMZ to the exchange server and DC's on the LAN ... >ISA is a workgroup box not joined to the domain) and that way you only ... >GCs between a DMZ and a firewall. ...
    (microsoft.public.exchange.admin)
  • Re: SBS R2 ISA2004 Dark Arts
    ... You'll have to use ISA ... I have to get the back firewall configuration to work with the ... I have lots of NICS on the server running SBS 2003 R2. ...
    (microsoft.public.windows.server.sbs)