Re: ISA 2006 an NAT rules [IP Translation]

Tech-Archive recommends: Fix windows errors by optimizing your registry



Not possible.
Never gonna happen.
The whole idea of what you want to do is from the 1980's and you need to
move up to the 21 century.

The real solution to your issue is to analyse the circumstances that cause
you to want to do things this way and get them changed so that this is no
longer a requirement.

I know of universities who still have public IP#s on every desktop and have
their firewalls set for packet filtering only without any NAT. They have no
*real* reason to keep things that way other than they just don't *want* to
change it. And "not wanting" to do something is not the same as "not being
able" to do something.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------

"Casio" <eng.mohammed.hammad@xxxxxxxxx> wrote in message
news:1184853810.797691.70340@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello,

We are planning to have a PIX at the edge then after it an ISA 2006
appliance.

It is very important to us to be able to make translation rules [as
those on PIX] so that an internal host would appear to the public with
static public IP.

I understand from my experience with ISA2004 that I can publish
certain server to listen on specific public IP, but all my internal
hosts when initiating connection to the internet appear as the default
[first] public IP bind on ISA external NIC.

Is there a method to achieve that or will I have to give up the idea
of isa behind pix.

Thanks a lot in advance for your help.



.



Relevant Pages

  • Re: VPN USERS - Question For Mark Renoden and Phillip Windell
    ... You can't have both interfaces of the ISA in the same subnet. ... > PIX VPN Clients get the ip's from the PIX, ... > access everything on the network, but they cannot browse the internet once ...
    (microsoft.public.isa)
  • Re: VPN USERS - Question For Mark Renoden and Phillip Windell
    ... Internal Network - 192.168.0.0/24 ... ISA is being used firewall and proxy only for a small part of the ... PIX VPN Clients get the ip's from the PIX, ... but they cannot browse the internet once ...
    (microsoft.public.isa)
  • Re: ISA and PIX 506
    ... Internet -> DSL Router -> Cisco PIX(Internal IP IE: ... If we were in the network we could not ... We had a remote site that had a ISA to ISA VPN connection for ... and the Pix in the middle would tunnle the tunnel. ...
    (microsoft.public.isa.configuration)
  • Re: Cisco Pix ---DMZ ---ISA2004
    ... I have setup maybe a dozen Public facing PIX to Internal ISA firewall configs and the PIX is not the flaw.. ... i don't have RDP or VPN access from the hotel i am at currently or i would look at my config.. ... Run the ISA between the LAN and the Internet. ...
    (microsoft.public.isa.configuration)
  • ISA 2006 an NAT rules [IP Translation]
    ... We are planning to have a PIX at the edge then after it an ISA 2006 ... those on PIX] so that an internal host would appear to the public with ... hosts when initiating connection to the internet appear as the default ...
    (microsoft.public.isa)