Re: RRAS ip routing and ISA
- From: bingyeo <bingyeo@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Thu, 27 Aug 2009 20:51:02 -0700
"Ace Fekay [MCT]" wrote:
If the config works for your requirements, I would go with it. As for not
being able to access the router on it's .10 interface from the .10 subnet,
which it appears one of the rules may be doing it, assuming that you;ve
defined both subnets as internal, you may be able to add an exception to the
rule? It's been a little while since I've administered an ISA, so I can't
help specifically, but that is what I am preliminarily thinking.
I hope that helps.
Ace
Hi Ace
not sure if you have misread, but the filter is actually done on the RRAS,
not the ISA.
Here's what I have configured:
Internet
|
ISA
10.10.10.7
|
10.10.10 x dg 10.10.10.7
|
10.10.10.250 dg 10.10.10.7
RRAS/NAT <----- the Inbound/Outbound Filters
are configured here
10.10.11.254 dg blank
|
10.10.11.x dg 10.10.11.254
So the filters are actually preventing the 11 subnet from accessing anything
related to 10 subnet directly.
However, even though it has been configured as an Outbound filter, the
10.10.10.250 interface seems to be preventing inbound traffic from the
10.10.10.x network as well (no ping, RDP).
And there is no way to configure exceptions at the RRAS filters, unless
there is some way which I am unaware of. The only options are Allow all
traffic except, or Block all traffic except, and any option you pick applies
to all the filters that you configure.
.
- Follow-Ups:
- Re: RRAS ip routing and ISA
- From: Ace Fekay [MCT]
- Re: RRAS ip routing and ISA
- References:
- RRAS ip routing and ISA
- From: bingyeo
- Re: RRAS ip routing and ISA
- From: Bill Grant
- Re: RRAS ip routing and ISA
- From: bingyeo
- Re: RRAS ip routing and ISA
- From: Ace Fekay [MCT]
- Re: RRAS ip routing and ISA
- From: bingyeo
- Re: RRAS ip routing and ISA
- From: Ace Fekay [MCT]
- Re: RRAS ip routing and ISA
- From: bingyeo
- Re: RRAS ip routing and ISA
- From: Ace Fekay [MCT]
- RRAS ip routing and ISA
- Prev by Date: Re: favicon.ico
- Next by Date: Re: favicon.ico
- Previous by thread: Re: RRAS ip routing and ISA
- Next by thread: Re: RRAS ip routing and ISA
- Index(es):
Relevant Pages
|