Solved

Connecting device directly bypassing ISA

Posted on 2004-10-13
7
355 Views
Last Modified: 2013-11-16
Hi there,
I was just hired by non-profit organization to do tech staff and one of the problems is that i am new to Microsoft ISA(internet security and Acces..) and to network overall. One of the users wants to use broadband videoPhone on LAN, which is device with its own firewall and needs to be connect directly to internet. However, there is simple ISA setup and Cisco 675 router configured in server side. I have been trying to figure out what would be the best way to conect only this paricular device directly to internet bypassing filters
Thank's
makapacs
P.S there is idea on conecting between the ISA external interface and the LAN interface of the Cisco router, but in office where the device and user PC is placed, has only one jack in use. So we are using a switch to connect PC and device. I guess i could connect that particular jack to external subnet, but then the user PC will not be in business domain any more. Is there a way around?
0
Comment
Question by:margotsk
  • 3
  • 2
  • 2
7 Comments
 
LVL 8

Expert Comment

by:Marakush
ID: 12299087
margotsk,

The easyiest way to do this is to add the device to the DMZ of the firewall and open the needed ports to the device. You need to check the documentation of the device and make sure you have the port numbers on the firewall open to that device. Also by putting in the DMZ you can assign it a real IP address.

Marakush
0
 

Author Comment

by:margotsk
ID: 12300753
Thank's Marakush for getting back,
I wonder if you could list step-by-step that i have to take in order to make it work. All of the servers are runing on one mashine which is conected to Cisco 675 router. I will have port numbers that vidiophone uses tommorow.
thank's
margotsk
0
 
LVL 8

Assisted Solution

by:Marakush
Marakush earned 350 total points
ID: 12300987
margotsk,

Okay first things first... you are going to need another piece of hardware, a firewall.. It will need a DMZ option. Frankly you should have one in place even if you weren't doing this thing with the video, just to protect your office.

What is your IP address scheme like? (depending, you might have to request a small IP address block from your ISP, which is going to be another hardware change, but that depends on a few factors)

Here is a listing of a few firewall appliances on the market.

http://www.nextag.com/serv/main/buyer/OutPDir.jsp?search=firewall&x=0&y=0&node=0

You might want to consider a PIX 501 or Sonicwall pro series, both will fit your needs. The 501 is nice but expencive and not the easyiest thing in the world to configure, but secure if its configured correctly. The Sonicall is a nice middle of the road in price, protection and ease of configuration.

Okay get back to me on the configuration of your IP addressing, your current router / current router configuration, and check out a firewall appliance.

(Depending on your router, we might be able to just do a pass though on the needed ports to the devices LAN address)

Marakush
0
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

 

Accepted Solution

by:
DebbieFost earned 150 total points
ID: 12310094
if you want to create a DMZ with an ISA server it reqires that the DMZ have its own network card that is connected directly to the videophone. for a better understanding check out this website : http://www.isaserver.org/tutorials/ISA_Server_DMZ_Scenarios.html

Thats the only way to create a direct conneciton to the internet with an ISA server (that i know of). The route that Marakush was explaining would involve just removing ISA and relying directly on the hardware firewall/router that you would install, which isnt that bad of an idea either.
0
 

Expert Comment

by:DebbieFost
ID: 12310122
EDIT: "it reqires that the DMZ have its own network card" is supposed to read: "it requires the server running the ISA to have a dedicated NIC card that will be directly connected to the video phone."
0
 
LVL 8

Expert Comment

by:Marakush
ID: 12310248
Thanks DebbieFost...

Personally I do not like using a primary server to act as the router and DMZ its just a beef I have after the melissa.virus and a small client got hammered... Ever sense... I've just been very weary about it...

DebbieFost's suggestion will also work if you do not want the added cost of new hardware.

Cheers!

Marakush
0
 

Author Comment

by:margotsk
ID: 12338662
Thank's for responding.
Before i post this thread, i was not aware of possibility to conect this device through the company's ISA firewall by opening certain ports. I guess DMZ is an option as well since the device has its own firewall, but problem is that it has to be conected directly, but in the office where the videophone, has only on jack for PC and VideoPhone. So at this time the best bet seems to be opening ports. I would still like to split the points, but 400 since i haven't solve the problem yet and I encourage you to get rest of 100 points by helping me open the range of ports posted in thread http://www.experts-exchange.com/Security/Q_21169826.html
Marakush 300p and DebbieFost 100p
Thank you one more time
m
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question