Re: 2 nics, isa, hw fwall



Your problem could be related to Network Address Translation (NAT): If
you have NAT enabled in ISA, that means that ISA is wrapping the data
packets with its' own info, then passing it to another firewall that
has NAT enabled as well. Firewalls are sometimes easily confused. Also,
are you using port forwarding (for access to specific internal hosts,
perhaps)? Which box is handling those chores? What do your routing
tables look like? You might have to make static entries into your
routing table(s). Posting your HW and ISA firewall configurations would
help, if possible.

Also, a TCP/IP packet sniffer might be helpful. There's a more than
capable sniffer built into Windows Server (Add/Remove Programs,
Components, Mgmt and Mon., Network Monitor Tools). There are many
third-party products as well, some of them are free and some of them
are very expensive. Putting a network device between the two firewalls
(or subnets), running various tests (ping, nslookup, etc.), and
analyzing what the TCP/IP packets are doing can be invaluable.

Good luck!

Patrick Pitre

.



Relevant Pages

  • Re: iptables and dhcp
    ... > the same physical network segment as the firewall and the remote DHCP ... You used INPUT and not FORWARD chain ... # This target allows packets to be marked in the mangle table ...
    (comp.os.linux.networking)
  • Re: SBS R2 ISA2004 Dark Arts
    ... ISA in SBS as intended or you'll get into trouble. ... I have to get the back firewall configuration to work with the ... network in the rules/policies. ...
    (microsoft.public.windows.server.sbs)
  • Re: Outgoing VPN Error 619
    ... I've checked in local network rules and I do have a rule called VPN clients ... PPTP clients are configured to use ISA as a hop to the Internet ... SecureNAT Clients while still trying to have Web and Firewall Client ...
    (microsoft.public.isa.vpn)
  • Re: SBS R2 ISA2004 Dark Arts
    ... Right now the front firewall is not an ISA ... NIC-2 faces the internal "Live" network. ... I have to get the back firewall configuration to work with the ...
    (microsoft.public.windows.server.sbs)
  • RE: Firewall service and remoteaccess service shut down frequently
    ... Do you have run the CEICW after installing the ISA components? ... please open SBS server management console, ... Click the Add Adapter button, and add your internal network adapter ... Meanwhile, from the subject, you said you the firewall service and RRAS ...
    (microsoft.public.windows.server.sbs)

Loading