Back to Back DMZ configuration

Tech-Archive recommends: Fix windows errors by optimizing your registry



I have the following ISA 2006 configuration:

Internet --> PIX --> ISA --> Internal network (published servers)


DMZ IP's : 192.168.1.x
Internal IP's: 10.0.0.x

Here is what I would like to do:

1) Route external connections through PIX, authenticate through a domain-joined ISA 2006 server and reverse proxy to
the published servers.

2) Establish internal connections directly through ISA 2006 without the need to route through PIX (see diagram below).
Before you suggest I send users directly to the application servers, this is not an option -- all connections must be
authenticated through ISA.


Internet --> PIX --> ISA --> Internal network (published servers)
|
|
Internal users


Question:

How do I define and configure the networks in ISA 2006 to make this work? Can I use two NICs or do I need three?


Thanks,

--Paul

.



Relevant Pages