Re: Multiple external IPs, binding on outbound
- From: "David Maskell - BUI Security" <DavidM@xxxxxxxxxxxxxxxx>
- Date: Tue, 18 Sep 2007 10:06:29 +0200
Absolutely agreed, I support this. This is a big problem exactly because of what you mention here. Checkpoint can do it :) and it would be great functionality to have.
From what I understand, this is a limitation in the OS at the moment, italways uses its primary IP for outbound traffic of any kind, rather a problem for reverse lookup!
--
David Maskell
(CISSP, MCSSA, MBCS, CITP, WCE-WS, nCSE, MCSE: NT4, 2000,2003,Messaging,Security, MCTS:SQL 2005,Vista)
"Tim Parker-Nance" <tim_pn@xxxxxxxxxxx> wrote in message news:Oi%233$uf9HHA.3916@xxxxxxxxxxxxxxxxxxxxxxx
Hi all
My ISA server has a hoard of external IPs. Amoungst them are 4 for mail servers and 2 for Radius servers. Inbound works ok, but outbound always binds to the primary external IP. There have been suggestions to change the primary IP to the IP of the mail server, but in our case we have multiple servers so this is not possible.
For mail it is not too much of a problem, except for those mail servers using reverse lookups to identify spam.
For Radius it is a problem. Our upstream provider will only accept Radius Packets of Disconnect (PoD) from our Radius server IPs it knows. As ISA is using the primary external IP all our PoDs are being rejected.
Is there any way of binding outbound traffic to a specific external IP?
If not, please consider this 'feature' of ISA useless and in the next service pack please provide a way to publish outbound traffic simillar to inbound so that we can bind our services to the correct external IPs.
Thanks
Tim Parker-Nance
.
- References:
- Multiple external IPs, binding on outbound
- From: Tim Parker-Nance
- Multiple external IPs, binding on outbound
- Prev by Date: Re: Enable SSL for web proxy
- Next by Date: ISA 2004 failed to send alert notification by e-mail
- Previous by thread: Multiple external IPs, binding on outbound
- Next by thread: Re: DHCP Server on combined DC/ISA Server
- Index(es):
Relevant Pages
|