Hi Experts,
I tried at the weekend to switch over to ISA 2006 from our current ServGate hardware firewall, but unfortunatley failed and had to roll back to the ServGate to keep the business running this week. They say failing to plan is planning to fail, and thats exactly what I did!
Anyway, I have a few general questions all related in some way to ISA 2006 that I hope you can help me with, I'll start with a brief summary of the setup.
Dell Poweredge 1950 / 2 NICs (LAN & WAN) LAN interface has no gateway defined and uses internal DNS. WAN interface has it's Default Gateway set to the real IP of the Zyxel router it is connected to, and there is no DNS defined on this interface. Client for MS Nets, File & Print Sharing, and NetBT are all disabled on the WAN interface. The WAN interface uses one of the live IPs from our range and all the other live IP's have also been assigned to this interface.
Zyxel Router - Supplied and managed by our ISP (Claranet) and as far as I know is configured to pass everything through to it internal interface with no filtering whatsoever.
Windows 2003 SP2 - member server sitting in the LAN.
My questions:
1. Is it necessary to create a rule to allow our internal DNS servers to query external DNS servers.
2. Are current hardware filewall allows me to define the live IP that our Exchange server uses for outbound communication, I can't see how this can be achieved with ISA. For example, currently inbound/outbound traffic to/from the Exchange server uses IP xxx.xxx.xxx.235, when ISA is being used it appears that inbound comms uses xxx.xxx.xxx.235 but outbound comms come from xxx.xxx.xxx.238.
I think this will cause some mail to be rejected if the recepients mailserver does a reverse DNS.
3. Do I need to install the firewall client on workstations? I know this is a bit of a 'it's up to you' type question, but any examples of why you have had to use the clients in your environments would be appreciated.
4. If not using the Firewall Client, what is the best way to configure IE to use ISA as it's procy, DNS or DHCP?
I really appreciate any help you can give.
Kind regards
Gary
Start Free Trial