Re: ISA 2004 Enterprise in Checkpoint DMZs

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi there,

Your proposed configuration with ISA having two interfaces in two separate
DMZ's is an overly complicated contraption that will not work, and even if
it _could_ be made to work it would be a nightmare to administer.

The key concept here is that ISA really shines in configurations where its
internal interface is connected to the LAN. That is the perfect textbook
example for Exchange publishing. Of course you can place another firewall in
front of ISA in this scenario, for an even more secure (read paranoid)
deployment. That is called a back-to-back firewall topology and it is what
you would do - seeing as the Checkpoint needs to stay in place.

So basically what you do, is alter your suggested diagram a little, so that
the 2nd ISA interface connects to the Internal network, instead of
connecting to that "DMZ2" contraption. Obviously in this topology you don't
need routes or to open "blanket" ports through DMZ2 - you only need to open
ports in Checkpoint for the published services.

Having said that, here's an article that deals with this exact kind of
setup - except the front firewall is another ISA not a Checkpoint; concepts
apply word for word though.

Publishing an OWA Site in a Back to Back ISA Firewall Configuration
http://www.isaserver.org/tutorials/Publishing-OWA-Site-Back-to-Back-ISA-Firewall-Part1.html

Virgil


.



Relevant Pages

  • Re: SBS R2 ISA2004 Dark Arts
    ... Right now the front firewall is not an ISA ... NIC-2 faces the internal "Live" network. ... I have to get the back firewall configuration to work with the ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS R2 ISA2004 Dark Arts
    ... All my ISA 2004 installs also have another router in front of them. ... network configuration after running the CEICW is as an Edge Firewall not a ... Back Firewall. ... CEICW do the configuration and setup the proper default ISA rules and then ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS R2 ISA2004 Dark Arts
    ... You'll have to use ISA ... I have to get the back firewall configuration to work with the ... I have lots of NICS on the server running SBS 2003 R2. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN PPTP problem
    ... The ISA Info which I gathered from you before including all ISA ... So I had checked your ISA configuration at the beginning. ... suppose the firebox will show you a PPTP service to publish. ... Click Virtual Private Network connection, ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS R2 ISA2004 Dark Arts
    ... ISA in SBS as intended or you'll get into trouble. ... I have to get the back firewall configuration to work with the ... network in the rules/policies. ...
    (microsoft.public.windows.server.sbs)