ISA 2006 web proxy scenario



I have the following ISA 2006 configuration: 4 ISA 2006 Standard
Editions servers, each with 2 NICs (External and Internal) in
workgroup mode. The 4 servers are in 2 separate DMZ's - see below.


Internet->PIX-> ISA2006 external array (DMZ) -> Internal network <-
ISA2006 internal array (DMZ) <-Internal users

I would like to consolidate this configuration by removing the ISA2006
internal array and having all traffic handled by the external array.
However, this has to happen without internal traffic being routed to
the Internet.

I've considered a couple of options but would like someone's feedback
on their viability:

option #1 - Create a 3rd NIC in the ISA array and route all requests
for the published servers through that NIC. I'm not sure if this will
work or if I need to use a NAT relationship.

option #2 - Add a 2nd external interface on the PIX. NAT all internal
user traffic destined to the published servers through the PIX's 2nd
external interface which in turn will forward that to ISA's external
interface.

Will either of these work and if not, what are the better options that
I am missing?

Thanks,

Paul

.



Relevant Pages

  • Re: Client PC cannot access internet
    ... ISA is re-installed and hey presto! ... Merv Porter [SBS MVP] ... Server can access the internet. ... Have you checked the binding order of the NICs? ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Disable dynamic route entries in Windows 2003?
    ... have two Nics. ... to publish applications to the Internet; ... destination network through two different interfaces, ... If you correctly configure the ISA machine with respect to the VLANs and the ...
    (microsoft.public.windows.server.networking)
  • Re: No internet access thru SBS
    ... it always needed at least 2 NICS) I did not check the ISA log. ... working the day before then somwhere the internet pass-through in the SBS ... I assume that is the proxy server feature that quit. ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA 2006 web proxy scenario
    ... The 4 servers are in 2 separate DMZ's - see below. ... internal array and having all traffic handled by the external array. ... You now have a Back-to-Back DMZ sitting between the ISA Array and the PIX. ... Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa)
  • Re: Questions re SBS and Public Websites
    ... confusion re the 2 NICs - what I meant was I was going to duplicate the IP ... ISA 2000 SP2. ... Internet ... > some questions about Windows 2003 Standard Server deployment. ...
    (microsoft.public.windows.server.sbs)

Loading