Connecting device directly bypassing ISA

Hi there,
I was just hired by non-profit organization to do tech staff and one of the problems is that i am new to Microsoft ISA(internet security and Acces..) and to network overall. One of the users wants to use broadband videoPhone on LAN, which is device with its own firewall and needs to be connect directly to internet. However, there is simple ISA setup and Cisco 675 router configured in server side. I have been trying to figure out what would be the best way to conect only this paricular device directly to internet bypassing filters
Thank's
makapacs
P.S there is idea on conecting between the ISA external interface and the LAN interface of the Cisco router, but in office where the device and user PC is placed, has only one jack in use. So we are using a switch to connect PC and device. I guess i could connect that particular jack to external subnet, but then the user PC will not be in business domain any more. Is there a way around?
margotskAsked:
Who is Participating?
 
DebbieFostConnect With a Mentor Commented:
if you want to create a DMZ with an ISA server it reqires that the DMZ have its own network card that is connected directly to the videophone. for a better understanding check out this website : http://www.isaserver.org/tutorials/ISA_Server_DMZ_Scenarios.html

Thats the only way to create a direct conneciton to the internet with an ISA server (that i know of). The route that Marakush was explaining would involve just removing ISA and relying directly on the hardware firewall/router that you would install, which isnt that bad of an idea either.
0
 
MarakushCommented:
margotsk,

The easyiest way to do this is to add the device to the DMZ of the firewall and open the needed ports to the device. You need to check the documentation of the device and make sure you have the port numbers on the firewall open to that device. Also by putting in the DMZ you can assign it a real IP address.

Marakush
0
 
margotskAuthor Commented:
Thank's Marakush for getting back,
I wonder if you could list step-by-step that i have to take in order to make it work. All of the servers are runing on one mashine which is conected to Cisco 675 router. I will have port numbers that vidiophone uses tommorow.
thank's
margotsk
0
SMB Security Just Got a Layer Stronger

WatchGuard acquires Percipient Networks to extend protection to the DNS layer, further increasing the value of Total Security Suite.  Learn more about what this means for you and how you can improve your security with WatchGuard today!

 
MarakushConnect With a Mentor Commented:
margotsk,

Okay first things first... you are going to need another piece of hardware, a firewall.. It will need a DMZ option. Frankly you should have one in place even if you weren't doing this thing with the video, just to protect your office.

What is your IP address scheme like? (depending, you might have to request a small IP address block from your ISP, which is going to be another hardware change, but that depends on a few factors)

Here is a listing of a few firewall appliances on the market.

http://www.nextag.com/serv/main/buyer/OutPDir.jsp?search=firewall&x=0&y=0&node=0

You might want to consider a PIX 501 or Sonicwall pro series, both will fit your needs. The 501 is nice but expencive and not the easyiest thing in the world to configure, but secure if its configured correctly. The Sonicall is a nice middle of the road in price, protection and ease of configuration.

Okay get back to me on the configuration of your IP addressing, your current router / current router configuration, and check out a firewall appliance.

(Depending on your router, we might be able to just do a pass though on the needed ports to the devices LAN address)

Marakush
0
 
DebbieFostCommented:
EDIT: "it reqires that the DMZ have its own network card" is supposed to read: "it requires the server running the ISA to have a dedicated NIC card that will be directly connected to the video phone."
0
 
MarakushCommented:
Thanks DebbieFost...

Personally I do not like using a primary server to act as the router and DMZ its just a beef I have after the melissa.virus and a small client got hammered... Ever sense... I've just been very weary about it...

DebbieFost's suggestion will also work if you do not want the added cost of new hardware.

Cheers!

Marakush
0
 
margotskAuthor Commented:
Thank's for responding.
Before i post this thread, i was not aware of possibility to conect this device through the company's ISA firewall by opening certain ports. I guess DMZ is an option as well since the device has its own firewall, but problem is that it has to be conected directly, but in the office where the videophone, has only on jack for PC and VideoPhone. So at this time the best bet seems to be opening ports. I would still like to split the points, but 400 since i haven't solve the problem yet and I encourage you to get rest of 100 points by helping me open the range of ports posted in thread http://www.experts-exchange.com/Security/Q_21169826.html
Marakush 300p and DebbieFost 100p
Thank you one more time
m
0
All Courses

From novice to tech pro — start learning today.