Solved

Local computers behind ISA Server with NAT on router

Posted on 2002-04-16
6
322 Views
Last Modified: 2010-04-11
Hi can anybody help:

I am running the following:
Windows 2000 server in the following way:

External IP --> Router (NAT translation) --> Local IP on MyServer --> ISA on MyServer --> IIS on MyServer --> Local LAN Users (connected via second network card)

I am hosting a couple of websites using IIS on the ISA Server computer (behind the firewall)

Anyone connecting to the server from an external location can access the websites - ie. everything is working correctly.

The problem is, local computers behing the firewall cannot connect to the websites hosted on myServer.

Local computers CAN browse the internet in the usual way.

I assume there is a problem with address translation.

Any suggestions?

0
Comment
Question by:georgep23
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 3

Expert Comment

by:cincin77
ID: 6945282
There must be a problem with the configuration rules of your ISA firewall.
0
 
LVL 3

Expert Comment

by:trath
ID: 6946124
I had some real issues with publishing websites also, which were resolved once I removed IIS.
0
 
LVL 8

Expert Comment

by:scraig84
ID: 6947541
There could be a few things going on here.  You mention translation as a possible problem - do your internal clients resolve the web names to external IP addresses?  If so, you should be providing them internal IP addresses so that they can connect with these.  Can users connect using IP address rather than name?  If this is not the issue, you may have some issues with IIS or ISA, such as only publishing the web sites on the external card etc.  However, the first issue is most likely the problem.
0
Report: Liquid Web beats Amazon, Rackspace & More

A study by performance analyst firm Cloud Spectator finds that Liquid Web beats rivals Amazon, Rackspace and DigitalOcean when it comes to website and cloud application performance.

 
LVL 1

Accepted Solution

by:
georgep23 earned 300 total points
ID: 6950844
Yes, the internal clients resolve the domain names of sites hosted locally on MyServer to an external IP address.

If I type the internal IP address of the server into a clients browser I get the 'Default Website' page on the MyServer. (Note: I am using multiple sites on IIS using host header information and 1 IP address)

Therefore, do you suggest that DNS requests for websites hosted on MyServer from internal comuters should resolve to the internal address of the server? If so how do I do this - I tried using the hosts file on the clients but this does not work.

MyServer is also a DNS server - ie. internal clients point to MyServer for DNS requests. External address requests are routed to the external NIC --> to my ISP's DNS server.

Any ideas?
0
 
LVL 8

Expert Comment

by:scraig84
ID: 6950902
If hosts files aren't working, it sounds like you are using the Proxy portion of ISA.  Can you get to the sites when sitting at the server using a browser?  Better yet, if you modify a client's host file and remove the proxy setting in the browser, can you get to it then?  There are a few things you can try.  My first thought would be to try adding the entries to the server's host files, since proxied DNS resolution comes from the server acting as the DNS client.  If that doesn't work, you could try pointing the server's DNS entries to itself, and setup the domains on the local DNS server and point the sites to the internal address.  If that still doesn't work, I would say you could tell the client browser not to proxy requests for the sites in question and make sure the clients get resolved to internal addresses through their local host files or modified internal DNS.

Anyway you cut it, when you have NAT and a proxy, it can be a bit tricky with local sites.
0
 

Expert Comment

by:CleanupPing
ID: 9155718
georgep23:
This old question needs to be finalized -- accept an answer, split points, or get a refund.  For information on your options, please click here-> http:/help/closing.jsp#1 
EXPERTS:
Post your closing recommendations!  No comment means you don't care.
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question