Re: policy based routing

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



"Vassilis Sotirchenas" <VassilisSotirchenas@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote
in message news:4FED8F47-1EE6-4D6C-89B6-E58A57728D7C@xxxxxxxxxxxxxxxx
I have an ISA 2006 Enterprise edition with 3 NICS. one is to my internal
clients, one is to ISP1 and the other is to ISP2. I want to be able to
route
some clients to ISP1 and others to use ISP2. I also want some flexibility
in
this, so I can quickly change the routing when I feel like it. Also,
policy
based routing on protocol used (ftp, http, etc.) would be cool too. As a
newbie to ISA i know little of its capabilities.

can it do this sort of thing?

if yes, how?

any pointers to the docs greatly appreciated.

The way this could be solved would be to put a simple firewall that is
capable of source routing in front of ISA and then route all of your
outgoing connections to that box. Then enter the source routes there
directly.

Depending on your circumstance, if each "client" represents for example a
different customer of your ISP network, then you might think of separating
them onto different subnets behind ISA, and then setting up your source
routes based on subnet rather than specific IP.

A box I really like is the Fortinet Fortigate. If you don't need their
yearly services for anti-virus, etc, the entry level models can be picked up
extremely cheap. It appears to do source routing competently, and some of
their entry level boxes have an explicit provision for dual WAN connections.

But, alas, as Phil says ISA by itself doesn't solve that problem.

--
Will


.



Relevant Pages

  • Re: CIFS Probleme mit NAT
    ... vor dem fileserver aufmachen lassen, das die clients direkt zugreifen ... ISA muß doch mit dem maskieren der quelladresse klarkommen. ... das heisst Du hast das standardmaessige ROUTE Netzwerkverhaeltnis zwischen ...
    (microsoft.public.de.german.isaserver)
  • =?iso-8859-1?q?Re:_Routing_=FCber_zwei_Netzwerke?=
    ... auf der 192.168.1er Seite ist der ISA das Default Gateway auf ... >Wo habt Ihr diese Route eingetragen? ... >werden, nicht auf den Clients. ... Den brauchst Du zum Surfen nicht. ...
    (microsoft.public.de.german.isaserver)
  • Re: Kleines Routenproblem
    ... Wie sieht denn die Route an den Clients aus, ... > ISA haben? ... kommt der Client ins Subnetz ...
    (microsoft.public.de.german.isaserver)
  • Re: CIFS Probleme mit NAT
    ... als ob der isa die pakete an die clients nicht mehr sauber zuordnen kann. ... habe ich so noch nicht probiert, aber ich kann mir vorstellen, dass es daran liegt, dass ISDA ja die IP der Clients maskiert und mit der eigenen VPN IP zum Client geht und ISA dann fuer die VPN Clients kein Stateful Inspection macht und so die Pakete nicht dem Ursprung zugeordnet werden koennen. ... Stell mal auf ROUTE um. ...
    (microsoft.public.de.german.isaserver)
  • Re: Route an external IP address via site to site vpn
    ... You can try the command "route ... add" on site 1 ISA server. ... If the command unable to resolve your issue, ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)