Re: SBS Hardware Firewall 2 NICs How To Configure

Tech-Archive recommends: Fix windows errors by optimizing your registry



If I understand this correctly, the Linksys is being used as a perimiter
firewall and the SBS box, having 2 nics is also being used as a secondary
firewall between the Linksys and the rest of the internal network. The
"external NIC, the one that connects to the LinkSys box should be configured
with a static IP in the range of 192.168.1.2-99. It is NOT necessary to turn
off DHCP in the Linksys box unless you're connecting it to the INTERNAL
network but then if you were you'd only have one NIC in the server and you
wouldn't have a secondary firewall ISA or not.

Internet<---->[Linksys]<--->[SBS box]<--->Internal network client PC's

You'll have to use Port Forwarding on the Linksys box for any services you
wish to host on the internet. I.E. you'll at least want to forward port 25
for email, Ports 80 and 443-444 for RWW and maybe even 110 if you have any
POP3 clients. If you want remote admin or VPN you'll need to forward those
ports also. DO NOT configure the SBS server on a DMZ, only forward the ports
you need.

Edwin

"Cris Hanna [SBS-MVP]" <crisnospamhanna@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
wrote in message news:E954CE17-EE16-4B69-83F8-F69FCD29A5FF@xxxxxxxxxxxxxxxx
I think Pop is not being as clear as you may need him to be
First of all, you don't indicate if your SBS box is Standard Edition or
Premium with ISA installed and configured?

The main thing here to understand that:
a) The NIC connected to your LINKSYS router/firewall must have a static
IP in the range to match the LAN side of the Router (Probably 192.168.1.2
if that range has not been modifed)
b) DHCP must be turned off on the LINKSYS router
c) It must be in a completely different subnet from the LAN connected nic
(which is no problem if you let SBS select it during install)

Then you should configure the Firewall to pass port 25, 443, 444 and 4125
(at a minimum) to the external nic.



--
Cris Hanna [SBS-MVP]
------------------------------
Please do not contact me directly, only respond in the Newsgroups
MVPs do not work for Microsoft
------------------------------
Send via Windows Mail on Vista Ultimate connected to SBS 2003 R2
"Magnetoram" <Magnetoram@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:50BE978F-5E6A-4454-93BB-B275696322C7@xxxxxxxxxxxxxxxx
Thanks for your post. The website link does not show the hardware
firewall
between the internet and the sbs box so I stil am not sure how to set all
the
ips and such.

"Pop" wrote:

This should help...

http://www.smallbizserver.net/Default.aspx?tabid=266&articleType=ArticleView&articleId=77


"Magnetoram" <Magnetoram@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C5E82F23-A98C-4D72-864B-D2DCEBBCB313@xxxxxxxxxxxxxxxx
I have a Linksys Router and a SBS box with 2 NICS and static IP. I am
not
sure on the configuration. The router will get the static IP. What
does
the
external NIC get for IP, subnet, gateway and wins. What does the
internal
get
for IP, subnet gateway and wins?






.



Relevant Pages

  • Re: SBS 1002 Premium R2 Mangling Port Issues
    ... For solutions like forefront, I am unsure why MS is not using the Windows ... When we use the term "hardware" firewall, ... The direction now is hardware firewall in front of SBS. ... NIC or 2 NICs) did you finally end up with? ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 1002 Premium R2 Mangling Port Issues
    ... When we use the term "hardware" firewall, ... The direction now is hardware firewall in front of SBS. ... your users or use some other feature of ISA). ... NIC or 2 NICs) did you finally end up with? ...
    (microsoft.public.windows.server.sbs)
  • Re: Changing from 1 NIC to 2 NICs
    ... Are you referring to a firewall appliance? ... > passes freely between the two nics. ... > on the lan, you have to have an access point on the lan. ... Have SBS do DHCP for the ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS R2 ISA2004 Dark Arts
    ... I suspect you need to be over in the ISA forum. ... Folks that try to do three nics don't ... I have 4 NICS in the SBS 2003 R2 server. ... Right now the front firewall is not an ISA ...
    (microsoft.public.windows.server.sbs)
  • Re: best network setup?
    ... An appliance based firewall is a separate dedicated device designed to do ... You can be sure that any changes to your server will not affect the ... If the SBS server is down for whatever reason all clients can still get ... SBS doesn't rely on two NICs to provide any services other than the ...
    (microsoft.public.windows.server.sbs)