Solved

Connecting device directly bypassing ISA

Posted on 2004-10-13
7
359 Views
Last Modified: 2013-11-16
Hi there,
I was just hired by non-profit organization to do tech staff and one of the problems is that i am new to Microsoft ISA(internet security and Acces..) and to network overall. One of the users wants to use broadband videoPhone on LAN, which is device with its own firewall and needs to be connect directly to internet. However, there is simple ISA setup and Cisco 675 router configured in server side. I have been trying to figure out what would be the best way to conect only this paricular device directly to internet bypassing filters
Thank's
makapacs
P.S there is idea on conecting between the ISA external interface and the LAN interface of the Cisco router, but in office where the device and user PC is placed, has only one jack in use. So we are using a switch to connect PC and device. I guess i could connect that particular jack to external subnet, but then the user PC will not be in business domain any more. Is there a way around?
0
Comment
Question by:margotsk
  • 3
  • 2
  • 2
7 Comments
 
LVL 8

Expert Comment

by:Marakush
ID: 12299087
margotsk,

The easyiest way to do this is to add the device to the DMZ of the firewall and open the needed ports to the device. You need to check the documentation of the device and make sure you have the port numbers on the firewall open to that device. Also by putting in the DMZ you can assign it a real IP address.

Marakush
0
 

Author Comment

by:margotsk
ID: 12300753
Thank's Marakush for getting back,
I wonder if you could list step-by-step that i have to take in order to make it work. All of the servers are runing on one mashine which is conected to Cisco 675 router. I will have port numbers that vidiophone uses tommorow.
thank's
margotsk
0
 
LVL 8

Assisted Solution

by:Marakush
Marakush earned 350 total points
ID: 12300987
margotsk,

Okay first things first... you are going to need another piece of hardware, a firewall.. It will need a DMZ option. Frankly you should have one in place even if you weren't doing this thing with the video, just to protect your office.

What is your IP address scheme like? (depending, you might have to request a small IP address block from your ISP, which is going to be another hardware change, but that depends on a few factors)

Here is a listing of a few firewall appliances on the market.

http://www.nextag.com/serv/main/buyer/OutPDir.jsp?search=firewall&x=0&y=0&node=0

You might want to consider a PIX 501 or Sonicwall pro series, both will fit your needs. The 501 is nice but expencive and not the easyiest thing in the world to configure, but secure if its configured correctly. The Sonicall is a nice middle of the road in price, protection and ease of configuration.

Okay get back to me on the configuration of your IP addressing, your current router / current router configuration, and check out a firewall appliance.

(Depending on your router, we might be able to just do a pass though on the needed ports to the devices LAN address)

Marakush
0
NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

 

Accepted Solution

by:
DebbieFost earned 150 total points
ID: 12310094
if you want to create a DMZ with an ISA server it reqires that the DMZ have its own network card that is connected directly to the videophone. for a better understanding check out this website : http://www.isaserver.org/tutorials/ISA_Server_DMZ_Scenarios.html

Thats the only way to create a direct conneciton to the internet with an ISA server (that i know of). The route that Marakush was explaining would involve just removing ISA and relying directly on the hardware firewall/router that you would install, which isnt that bad of an idea either.
0
 

Expert Comment

by:DebbieFost
ID: 12310122
EDIT: "it reqires that the DMZ have its own network card" is supposed to read: "it requires the server running the ISA to have a dedicated NIC card that will be directly connected to the video phone."
0
 
LVL 8

Expert Comment

by:Marakush
ID: 12310248
Thanks DebbieFost...

Personally I do not like using a primary server to act as the router and DMZ its just a beef I have after the melissa.virus and a small client got hammered... Ever sense... I've just been very weary about it...

DebbieFost's suggestion will also work if you do not want the added cost of new hardware.

Cheers!

Marakush
0
 

Author Comment

by:margotsk
ID: 12338662
Thank's for responding.
Before i post this thread, i was not aware of possibility to conect this device through the company's ISA firewall by opening certain ports. I guess DMZ is an option as well since the device has its own firewall, but problem is that it has to be conected directly, but in the office where the videophone, has only on jack for PC and VideoPhone. So at this time the best bet seems to be opening ports. I would still like to split the points, but 400 since i haven't solve the problem yet and I encourage you to get rest of 100 points by helping me open the range of ports posted in thread http://www.experts-exchange.com/Security/Q_21169826.html
Marakush 300p and DebbieFost 100p
Thank you one more time
m
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question