Publishing On Interfaces Other Than External?
- From: "Will" <westes-usc@xxxxxxxxxxxxxx>
- Date: Wed, 12 Dec 2007 22:53:29 -0800
Has anyone ever gotten Server Publishing to work on any interface other than
External? We have no problem getting it to work on the External
interface, but we have NOT had any luck getting Server Publishing to work on
any other network interface. We do have separate ethernet adapters in the
ISA Server 2006, and the subnets defined on those adapters correspond
exactly to the address range defined in separate Network objects in ISA (one
ISA Network per adapter port).
When we publish a server, if we select a Network other than External in the
server publishing rule's Networks tab, and then publish to an IP address on
that Network interface, then Server Publishing enters into a strange
quazi-working state. Incoming packets to the interface with the published
IP show up in the ISA monitor as being destined to the correct IP, so
clearly the published IP is being translated to the hidden server's IP by
something. But the rule is showing in Monitor as:
1) Having no Network Rule
2) Failing on the Default firewall rule.
We do define an NAT Network relationship in ISA between the hidden machine
and the Subnet from which the incoming traffic is coming.
When we examine traffic on a sniffer, it doesn't get past the firewall on
the interface with the incoming traffic, so the problem is not a routing
issue behind the firewall.
We have started two tickets with Microsoft over the last nine months on this
issue, and both times we end up getting passed to a senior tech who tells us
that the way to get it to work is to publish on the External interface. :)
I can configure ISA as a routing firewall all day long, and at this point I
can make a simple access rule dance on the head of a pin and do anything I
want to do. Publishing rules still aggravate me and just don't seem to
function in a rational way I can understand unless I publish to the External
interface. There appears to be functionality on the Networks tab of the
server publishing dialog to let publishing work on interfaces besides the
External interface. Can someone with experience making this work tell me
how you did it?
--
Will
.
- Follow-Ups:
- Re: Publishing On Interfaces Other Than External?
- From: Phillip Windell
- Re: Publishing On Interfaces Other Than External?
- Prev by Date: Re: ISA 2006 and Internal Network
- Next by Date: Re: IN ONE SWITCH TWO DHCP
- Previous by thread: Re: Problem accessing sharepoint v3 site behind ISA over internet
- Next by thread: Re: Publishing On Interfaces Other Than External?
- Index(es):
Relevant Pages
|