Solved

Licensing for SBS, 2k Server, and W2k3 Server w/ ISA

Posted on 2006-11-21
8
357 Views
Last Modified: 2010-04-19
I currently have a SBS 2003 server with 30 user CALs installed along with a Windows 2000 server running TS.  My plan is to install a third server, Windows 2003 Standard, that will run ISA Server 2004 or 2006 on it to act as our firewall.  The ISA server will be connected directly to the DSL coming in and then control the traffic to the DMZ (where the TS server is) and the LAN.

My question is - Will I need to purchase additional licensing for the Windows 2003 server that has the ISA running on it?  Does my SBS 2003 CALs cover those licenses?  I have the Microsoft Action Pack so I have 10 licenses for the Win2k3 server already.


Please let me know if you need any more information than what I am giving.  Thanks.
0
Comment
Question by:jsvor
  • 4
  • 3
8 Comments
 
LVL 74

Accepted Solution

by:
Jeffrey Kane - TechSoEasy earned 500 total points
ID: 17990699
Your SBS CALs would cover the additional Server 2003, but I don't really understand why you would deploy a separate server for ISA when SBS integrates it so nicely!  If you install the premium component ISA Server 2004 on your SBS, everything will be configured automatically with SBS's wizards.  

I really don't quite understand your reasoning here.

Jeff
TechSoEasy
0
 
LVL 8

Author Comment

by:jsvor
ID: 18157718
The reason I will be having the ISA server on a separate server than the SBS is because I don't like the idea of having my DC being connected directly to the internet.
0
 
LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 18172292
Your absolutely right that a DC shouldn't be directly connected to the Internet... unless it's SBS with ISA and/or a hardware firewall.

It's important to realize that properly configured, SBS is a secure server.  When you go away from the proven configuration which has been deployed by hundreds of thousands of small businesses, you run a much greater risk of having an insecure environment because you're basically on your own to know if a threat would be applicable to your environment.

One thing I should point out is that if you bought the Premium Edition of SBS, licensing prohibits installing ISA on a separate machine.  So you would need to purchase a separate ISA which runs $1,499.00 PER PROCESSOR in addition to the $999.00 for the Standard Server 2003 license needed for it to run on.

Now granted you are using the Action Pack which makes this initial cost irrelevant, but the ongoing upkeep will definitely be costly.  You won't find many, if any, resources for your configuration.

Jeff
TechSoEasy
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 8

Author Comment

by:jsvor
ID: 18172481
OK.  With the configuration you are suggesting (ISA installed on SBS) would/should I create a DMZ for a published TS or will the ISA server provide enough protection to have the TS in the internal network?  I am concerned that the extra traffic going to the SBS may slow it down - is that something to worry about?  I just don't want to run into any performance issues.

Thanks for all the input.
0
 
LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 18172634
ISA will handle it just fine.  I've never seen an SBS slow down because of this... as long as you've got a proper machine to begin with.  You'll overcome any performance issues by having the correct hardware.  If anything err on the side of more than you think you need.  These days, that may only be a difference of $400 or $500 which if divided by your total users may only be pennies per day per user.

Jeff
TechSoEasy
0
 
LVL 8

Author Comment

by:jsvor
ID: 18172842
The machine is pretty beefy so then I guess I'll be all set there.  Are there any concerns I should have installing ISA on an established SBS that is running Exchange, SQL, and tape backups?

How about the TS on the DMZ?  Would it be OK to have the TS on the internal network for remote users to connect to?  Or will it be secure enough just being behind the ISA?
0
 
LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 18185020
Putting the TS in a DMZ means that you have to separately manage the logins for it... you lose all the benefit of having everything under one control.  Once you start making separate this and that logins you will have a much more unsecure environment.  Keep it under Active Directory and your Domain's control.

See http://sbsurl.com/sbstss for the how-to for adding a terminal server to an SBS network.

As for adding ISA?  It's almost always added after-the-fact.  So just follow the instructions to install the premium technologies.  http://sbsurl.com/premium

Jeff
TechSoEasy
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

I’m often asked about newer and larger USB drives connected to SBS2008 and 2011 failing Windows Server Backup vs the older USB drives not failing. As disk space continues to grow and drive technology change SBS2008 and some SBS2011 end up with the f…
You may have discovered the 'Compatibility View Settings' workaround for making your SBS 2008 Remote Web Workplace 'connect to a computer' section stops 'working around' after a Windows 10 client upgrade.  That can be fixed so it 'works around' agai…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now