Checkpoint Front End server - ISA Back End server - OWA Setup



We currently use checkpoint firewall as our front end firewall. We are
looking to use owa with an ISA Server used as a back end firewall. My
understanding from articles I have read is to setup the following.

Client/Internet
|
|
Checkpoint Firewall - - - - - -DMZ
| |
| |
| External
interface
Internal Lan ISA Server
\ Interal interface
\ |
\ |
- - - - - - -- Exchange server

I am not a firewall expert, but our firewall guy tells me this is a risk, as
we dont want the Isa Server internal interface bypassing the checkpoint
firewall. He is suggesting the following.


Client/Internet
|
|
Checkpoint Firewall - - - - - -DMZ
| | |
| - - - - - | |
| | External
interface
Internal Lan | ISA Server
| | Internal
interface
Exchange server - - - - - - |

To clarify the request comes through the firewall then to the external
interface on the ISA server in the dmz and then through the internal
interface back through the checkpoint firewall and forwarded onto the
exchange server. Is this way overcomplicated and would it even work?

Thanks in advance

Ictuser






.



Relevant Pages

  • Re: CEICW fails - several errors
    ... The firewall isn't used when ISA is installed. ... On the WAN NIC of your server the DNS has to point to the LAN IP. ... I immediately checked and ISA Server ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA2004 client firewall slow webpage loading
    ... have you configured this new client as web proxy client? ... configure ISA server as your Proxy ... stop the Microsoft Firewall service. ...
    (microsoft.public.windows.server.sbs)
  • Re: CEICW fails - several errors
    ... On the WAN NIC of your server the DNS has to point to the LAN IP. ... Ethernet adapter Internet Connection: ... I immediately checked and ISA Server ... Management said that Web Proxy, Firewall and ...
    (microsoft.public.windows.server.sbs)
  • Re: Trying to understand this behavior, Ports in IIS
    ... network devices between the firewall and ISA Server ... server was successful only upon opening port 8080 in the firewall. ... > Prior to 'open' port 8080 in our main edge Checkpoint firewall, ...
    (microsoft.public.inetserver.iis.security)
  • ISA Spoofing Issue Using Second Firewall with One to One NAT
    ... Two tier firewall implementation segmenting the Internet, ... ISA Server configured with packet filters ... facing firewall's one to one NAT are seen as a spoof by ISA. ...
    (NT-Bugtraq)