general question on design options



current infrastructure (with respect to internet connection and VPN) is
based on ISA 2000. I'm looking to change internet providers to a T1 service
and incorporate a Cisco device as the outer most edge device of my network,
instead of the ISA server. I want to keep the ISA server for its
proxy/caching and windows user-based control features.

what arrangement options do I have for this?

The first one that comes to mind is to have the Cisco device simply route
(with public IP on both external and internal facing interfaces) and ISA
would continue to have public IP on cisco facing interface and private IP on
internal facing interface. In this scenario ISA would just continue doing
what its doing (VPN server, Firewall, NAT, with several port forwarding
rules). Anything wrong with that scenario?

What if I want to add the cisco device and utilize it as another layer of
security rather than simply a router? How might that work?

final question: (this is a stupid question but even though I'm trying I
can't stop myself from asking): ISA can't have IP addresses from the same
private subnet on both interfaces and still provide proxy services right?


.



Relevant Pages

  • Re: RWW - Cant login
    ... Premium and ISA. ... In the Microsoft Internet Security and Acceleration Server 2004 ... In the center pane, find a policy named SBS Internet Access Rule, ...
    (microsoft.public.windows.server.sbs)
  • Re: RWW - Cant login
    ... MVPs do not work for Microsoft ... Must be a difference between Standard and Premium and ISA. ... In the Microsoft Internet Security and Acceleration Server 2004 console, ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: RWW - Cant login
    ... Modify Internet Access Rule in ISA server ... In the Microsoft Internet Security and Acceleration Server 2004 console, ... In the center pane, find a policy named SBS Internet Access Rule, ...
    (microsoft.public.windows.server.sbs)
  • Re: The Web site cannot be found - errors
    ... problems connecting with the internet. ... Internet Connection Wizard from the server. ... > files and ISA cache on all ...
    (microsoft.public.windows.server.sbs)
  • RE: Group Policy - Restrict Internet Access by OU?
    ... you could not find ISA on SBS 2003, you can use SBS premium technology disk ... to install ISA server. ... restrict internet access on special user group. ...
    (microsoft.public.windows.server.sbs)