It is just a bad network design that most people never know about because most "hardware firewalls" are not fully "stateful" on all interfaces and so the [way too common] bad design "still works". ISA is fully statefuil on all interfaces and will drop the traffic because it does not see "both sides" of the converstation.
You can't use the EBS/ISA as the LAN Router. One of the other Routers used for the Remote Sites must be the LAN Router. This means the Default Gateeway of the Hosts is the LAN Router,..not the EBS/ISA.
This is a well established and fully documented situation.
The Official SBS Blog : Network Behind a Network
http://blogs.techne
Be
(http://www.microsoft.com/
Tips and hints on configuring network objects in ISA Server, and how to
avoid "network-behind-network" misconfigurations.





by: HayesJupePosted on 2009-07-27 at 00:10:49ID: 24949333
any traffic that traverses an interface with ISA/TMG will be scanned and evaluated. I dont really do any SBS/EBS style of work - but im guessing that all products need to be one box ?
If this is the case, i'd be simply ensuring that all the internal ranges are defined in the internal network object, and creating a rule that allows all to all for local host/internal to internal/local host