Solved

ISA Server behind PIX 515

Posted on 2004-08-20
7
258 Views
Last Modified: 2008-11-18
Ok lets let the dumb questions fly!  I gotta learn somehow right?
I have been handed a fun little project, this compnay has a PIX 515 and wants to install ISA server to monitor its users.  How do I setup the NIC card on the ISA box to see the interent through the PIX.  Assuming that this is how I have to go about it.  ISA is not installed yet and I have two NIC cards in the machine where ISA is going to be installed.
0
Comment
Question by:SoonersFan
  • 3
  • 3
7 Comments
 
LVL 36

Accepted Solution

by:
grblades earned 250 total points
ID: 11852964
Hi SoonersFan,
ISA can act as a router/firewall but as you already have a very good PIX firewall I would not use the ISA in this manner aswell as it will just complicate the configuration and wont give you any benefit.

What I would do is only configure the ISA server with a single network interface and set it with a fixed IP address on the network with the default gateway set to the PIX's IP address.
Then configure the web browser of everyones machine to use the ISA server as the proxy server.
Then configure the outbound access-list on the PIX to enable web access from the ISA server only.
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 11853937
I second grblades' suggestion. Use the ISA as a standalone, single nic proxy server only. If you have Windows 2003 and the ISA 2004, the proxy reports are so detailed it'll knock your socks off.. and setup is very simple with the wizards in 2004.
0
 

Author Comment

by:SoonersFan
ID: 11855472
"Then configure the web browser of everyones machine to use the ISA server as the proxy server."

I did this and it is working from a web browser standoint but it isnt showing anythign in ISA as far as a connection.

"Then configure the outbound access-list on the PIX to enable web access from the ISA server only."

Can you give me an example of what this woudl look like and where.  I don't know much about the PIX at all.

Thanks
0
Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

 
LVL 36

Expert Comment

by:grblades
ID: 11855610
Assuming you don't already have an access list to restrict outbound traffic which is the default and therefore everything is permitted you could add something like:-

access-list inside_in permit tcp host 10.0.0.1 any eq www
access-list inside_in permit tcp host 10.0.0.1 any eq https
access-list inside_in permit tcp host 10.0.0.1 any eq ftp
access-list inside_in deny tcp any any eq www
access-list inside_in deny tcp any any eq https
access-list inside_in deny tcp any any eq ftp
access-list inside_in permit ip any any
access-list inside_in permit icmp any any
access-group inside_in in interface inside

This allows the machine with IP 10.0.0.1 to access the web and ftp. Substitute this IP with the IP address of your ISA server.
The next 3 lines deny web and ftp directly from any other machine so they have to go via the ISA server.
The remaining two lines permit everything else.

Ideally you should not have the last two lines but should just permit everything that you wish to allow. This can be a bit time consuming to work out and it is best to implement in stages.
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 11855620
Which version ISA are you using?

Your pix config would restrict all outbound web access to only the Proxy's IP address.
Proxy IP address = 192.168.1.100

PIX config:

access-list proxy_restriction permit tcp 192.168.1.100 any eq www
access-list proxy_restriction deny tcp any any eq www
access-list proxy_restriction permit ip any any
access-group proxy_restriction in interface inside

0
 
LVL 79

Expert Comment

by:lrmoore
ID: 11855633
damn! I'm typing too slow today...
0
 
LVL 36

Expert Comment

by:grblades
ID: 11855664
There must have only been seconds between us.
At least we both gave the same answer ;)
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
Common practice undertaken by most system administrators is to document the configurations and final solutions of anything performed by them for their future use and reference. So here I am going to explain how to export ISA Server 2004 Firewall pol…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now