Re: Best Overall SBS2003 Prem Install Procedure?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Chad A. Gross [SBS MVP] (chad.gross_at_laytonflower.nospam.com)
Date: 05/29/04


Date: Fri, 28 May 2004 23:39:36 -0500


-- 
Chad A. Gross - SBS MVP
SBS ROCKS!
www.msmvps.com/cgross
www.gosbs.org
root wrote:
> Thanks and inline below.
>
> "Chad A. Gross [SBS MVP]" <chad.gross@laytonflower.nospam.com> wrote
> in message news:ucfc0qSREHA.3140@TK2MSFTNGP11.phx.gbl...
>> If both NICs are plugged into something, then they will be detected &
>> installed during setup.
>
> Is this something new in W2K3?  Previously(NT4, W98SE, XP & W2K) a
> NIC(most any gadget) and its drivers would be installed because it's
> a powered PCI card and detected during install and that's when the
> drivers would be installed.  It had nothing to do with a plugged LAN
> cable.
>
>> DHCP has always been an interesting issue with SBS since the SBS
>> DHCP will shut itself down if it detects another DHCP server on the
>> LAN.
>
> Or is it that SBS2003 insists that it be DCHP on at least one of it's
> NICs and that's probably the LAN NIC??
In a default setup, SBS is going to try to be the DHCP for it's LAN 
connection, unless of course it detects another DHCP server.  Doesn't make a 
whole hell of a lot of sense if you ask me - I think about the best argument 
I've heard is that it is easier to have a single DHCP, so SBS lets an 
existing DHCP take precedence.  SBS doesn't insist to be DHCP.  If you 
choose, you can completely disable the DHCP Server service on SBS and have a 
router or other server acting as your DHCP, and the SBS will run fine 
(assuming of course that the DHCP scope options are set correctly on the 
DHCP server  :^)
<snip>
>
> But you keep inbound traffic disabled until WinUp is done so the need
> for that router seems redundant and therefore any need for an
> alternate download site/list for security fixes is also eliminated.
> Just do WinUp.
It's true that with inbound traffic disabled in ISA, the router is 
redundant.  Again, as a matter of personal preference, I like to have a 
router between ISA and the internet for several reasons - including the 
router's firewall will block most of the PITA stuff banging on the door, 
which leaves the ISA logs pretty clean - which makes it easier to see what I 
need to see.  In addition, the router offers a lot of options for things 
like DMZ's, web servers, granting internet access to business guests, 
wireless, etc.  In addition, if the server is down - I have a way to get my 
laptop on the internet so I have a lifeline to Google & this group  :^) 
Again - it's just a matter of personal preference.
>
> Now,  should I do the ISA SP before I do the ISA setup above?
You could apply the ISA SP before you connect to the internet if you have it 
available - but you aren't exposing your server to great risk by connecting 
to the internet to do updates with a non-SP'd ISA.  Unlike IIS where there 
are script kiddies hitting servers constantly, there isn't that sort of 
large scale attacks on ISA - primarily because the known issues aren't as 
critical as the known issues of other products like IIS, and the 
overwhelming majority of exposed ISA servers are front end servers that do 
nothing but firewall - so they aren't nearly as attractive a target as IIS 
servers.  But again, it comes down to personal preference and how healthy 
your dose of paranoia is  ;^)


Relevant Pages

  • Re: RWW Timing
    ... If you have installed ISA, ... Expand the server node and highlight ''Monitoring''. ... In the following website you can find many useful resources related to SBS ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Urgent! New router and big disaster
    ... so we don't even know if dhcp is configured on ... Les Connor [SBS Community Member - SBS MVP] ... no internet connection from the server. ... dns suffix search list: MuellerElectrical.local ...
    (microsoft.public.windows.server.sbs)
  • Re: DHCP Issues. Very strange
    ... default order of rule in ISA 2004. ... Windows SharePoint Services intranet site, ... server certificate on Web server name column and then click Next. ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS VPN setup?
    ... The 2-nic configuration is used when the SBS server will *also* act as your network's firewall. ... You purchase 2k3 PREMIUM and that comes with ISA to handle the firewall duties. ... To compare apples to apples, let us assume there is a network setup as I outlined above...and the firewall appliance is an ISA server, such as those available from Celestix. ...
    (microsoft.public.windows.server.sbs)
  • Re: DHCP and companyweb problems
    ... If the DHCP traffic is being denied by ISA which rule is it showing that is ... SBS FTP Server Access, RDP Server Access, RDP Outbound disabled. ... Client name is correct ...
    (microsoft.public.windows.server.sbs)