Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Connecting device directly bypassing ISA

Posted on 2004-10-13
7
Medium Priority
?
385 Views
Last Modified: 2013-11-16
Hi there,
I was just hired by non-profit organization to do tech staff and one of the problems is that i am new to Microsoft ISA(internet security and Acces..) and to network overall. One of the users wants to use broadband videoPhone on LAN, which is device with its own firewall and needs to be connect directly to internet. However, there is simple ISA setup and Cisco 675 router configured in server side. I have been trying to figure out what would be the best way to conect only this paricular device directly to internet bypassing filters
Thank's
makapacs
P.S there is idea on conecting between the ISA external interface and the LAN interface of the Cisco router, but in office where the device and user PC is placed, has only one jack in use. So we are using a switch to connect PC and device. I guess i could connect that particular jack to external subnet, but then the user PC will not be in business domain any more. Is there a way around?
0
Comment
Question by:margotsk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
7 Comments
 
LVL 8

Expert Comment

by:Marakush
ID: 12299087
margotsk,

The easyiest way to do this is to add the device to the DMZ of the firewall and open the needed ports to the device. You need to check the documentation of the device and make sure you have the port numbers on the firewall open to that device. Also by putting in the DMZ you can assign it a real IP address.

Marakush
0
 

Author Comment

by:margotsk
ID: 12300753
Thank's Marakush for getting back,
I wonder if you could list step-by-step that i have to take in order to make it work. All of the servers are runing on one mashine which is conected to Cisco 675 router. I will have port numbers that vidiophone uses tommorow.
thank's
margotsk
0
 
LVL 8

Assisted Solution

by:Marakush
Marakush earned 1050 total points
ID: 12300987
margotsk,

Okay first things first... you are going to need another piece of hardware, a firewall.. It will need a DMZ option. Frankly you should have one in place even if you weren't doing this thing with the video, just to protect your office.

What is your IP address scheme like? (depending, you might have to request a small IP address block from your ISP, which is going to be another hardware change, but that depends on a few factors)

Here is a listing of a few firewall appliances on the market.

http://www.nextag.com/serv/main/buyer/OutPDir.jsp?search=firewall&x=0&y=0&node=0

You might want to consider a PIX 501 or Sonicwall pro series, both will fit your needs. The 501 is nice but expencive and not the easyiest thing in the world to configure, but secure if its configured correctly. The Sonicall is a nice middle of the road in price, protection and ease of configuration.

Okay get back to me on the configuration of your IP addressing, your current router / current router configuration, and check out a firewall appliance.

(Depending on your router, we might be able to just do a pass though on the needed ports to the devices LAN address)

Marakush
0
Looking for a new Web Host?

Lunarpages' assortment of hosting products and solutions ensure a perfect fit for anyone looking to get their vision or products to market. Our award winning customer support and 30-day money back guarantee show the pride we take in being the industry's premier MSP.

 

Accepted Solution

by:
DebbieFost earned 450 total points
ID: 12310094
if you want to create a DMZ with an ISA server it reqires that the DMZ have its own network card that is connected directly to the videophone. for a better understanding check out this website : http://www.isaserver.org/tutorials/ISA_Server_DMZ_Scenarios.html

Thats the only way to create a direct conneciton to the internet with an ISA server (that i know of). The route that Marakush was explaining would involve just removing ISA and relying directly on the hardware firewall/router that you would install, which isnt that bad of an idea either.
0
 

Expert Comment

by:DebbieFost
ID: 12310122
EDIT: "it reqires that the DMZ have its own network card" is supposed to read: "it requires the server running the ISA to have a dedicated NIC card that will be directly connected to the video phone."
0
 
LVL 8

Expert Comment

by:Marakush
ID: 12310248
Thanks DebbieFost...

Personally I do not like using a primary server to act as the router and DMZ its just a beef I have after the melissa.virus and a small client got hammered... Ever sense... I've just been very weary about it...

DebbieFost's suggestion will also work if you do not want the added cost of new hardware.

Cheers!

Marakush
0
 

Author Comment

by:margotsk
ID: 12338662
Thank's for responding.
Before i post this thread, i was not aware of possibility to conect this device through the company's ISA firewall by opening certain ports. I guess DMZ is an option as well since the device has its own firewall, but problem is that it has to be conected directly, but in the office where the videophone, has only on jack for PC and VideoPhone. So at this time the best bet seems to be opening ports. I would still like to split the points, but 400 since i haven't solve the problem yet and I encourage you to get rest of 100 points by helping me open the range of ports posted in thread http://www.experts-exchange.com/Security/Q_21169826.html
Marakush 300p and DebbieFost 100p
Thank you one more time
m
0

Featured Post

Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This program is used to assist in finding and resolving common problems with wireless connections.
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question