Re: IP Relay/NAT set up on W2K3

Tech-Archive recommends: Fix windows errors by optimizing your registry



"Mike Michael" <MikeMichael@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:E62F137F-AD67-48E8-A3C2-EFB68DD76D02@xxxxxxxxxxxxxxxx
We have an IP on a Windows 2K3 server in our DMZ. We need to allow a type
of
automated process to access an internal server via a specific port. The
network/security folks do not want to just NAT on the firewall, they want
to
NAT on the perimeter, then "proxy" the connection to the internal server.
So,
since I happen to have a Windows server in the DMZ which already accesses
said internal server, my straw was drawn.
External client > firewall > my windows box in DMZ > firewall > internal
server
And in this hypothetical/make believe scenario, the W2K3 server would
accept
the connection and redirect to the internal server (is that proxy or
relay?).

1. They cannot choose to "not" NAT at the firewall,...it isn't a choice, it
is a requirement,...the firewall is "in the way", and the only way into the
LAN is via it.

2. You can't proxy without a Proxy. You do not have a proxy. The only real
"proxy-based" Firewall product on the market worth mentioning right now
(that would fit this situation) is MS ISA Server. It is designed to
*replace* one or both of those Firewalls, not sit on the middle of the DMZ

3. This is a Back-to-Back DMZ built between two Firewalls,..an Inner
Firewall and an Outer Firewall. These firewalls, particulrly if they are
Applicances, are just simply NAT Boxes. We can debate all day about what
features they have or don't have,...but they are just NAT Boxes.

So there is only one way to get inbound traffic from a user on the "outside"
to a resource on the "inside".
Step 1. The Outer Firewall does a Static NAT (aka Reverse NAT) back to
the Inner Firewall
Step 2. The Inner Firewall does a Static NAT (aka Reverse NAT) back to
the Resource on the "inside".

The Reverse NAT should only respond to traffic directed at the required
Initial Connection Port of the Application/Service being used. This is
almost always a single number. The random Client Source Ports do not have
to be accounted for on modern Firewalls that monitor the state of the
Session.

Adding anything in the center of the DMZ to pass the traffic through is
totally pointless, it doesn't accomplish anything and only over complicates
things and creates yet another way/place for the whole thing to fail.


--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.asp

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------


.



Relevant Pages

  • Re: EBS 2008, TMG and external firewall. Dont want double NAT
    ... but didn't find it (searched this server for business, ... security level tool that comes with feature pack 1 if you set the ... disable NAT. ... I forward from the firewall to the internal interface it works (external ...
    (microsoft.public.windows.server.sbs)
  • Re: IP Addressing
    ... Address of the ISA server? ... firewall and router). ... On the firewall create a static NAT entry as I wrote ...
    (comp.dcom.sys.cisco)
  • Re: EBS 2008, TMG and external firewall. Dont want double NAT
    ... but didn't find it (searched this server for business, ... security level tool that comes with feature pack 1 if you set the ... disable NAT. ... I forward from the firewall to the internal interface it works (external ...
    (microsoft.public.windows.server.sbs)
  • Re: WSS v.3 BETA 2 - FQDN REQUIRED for external access?
    ... I'm not sure I follow the question, but I can tell you that I'm doing NAT ... firewall to an internal IP address won't SharePoint think it's talking to ... Mine went into the default zone, so if that's your only option you're ... I installed this server over a week ago and still cannot access ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: PASV FTP behind NAT firewall
    ... Displaying the NAT IP instead of the internal server IP is the way to go, ... On the ftp feature, it is not Microsoft focus since it was introduced. ...
    (microsoft.public.inetserver.iis.ftp)