• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 368
  • Last Modified:

Licensing for SBS, 2k Server, and W2k3 Server w/ ISA

I currently have a SBS 2003 server with 30 user CALs installed along with a Windows 2000 server running TS.  My plan is to install a third server, Windows 2003 Standard, that will run ISA Server 2004 or 2006 on it to act as our firewall.  The ISA server will be connected directly to the DSL coming in and then control the traffic to the DMZ (where the TS server is) and the LAN.

My question is - Will I need to purchase additional licensing for the Windows 2003 server that has the ISA running on it?  Does my SBS 2003 CALs cover those licenses?  I have the Microsoft Action Pack so I have 10 licenses for the Win2k3 server already.


Please let me know if you need any more information than what I am giving.  Thanks.
0
jsvor
Asked:
jsvor
  • 4
  • 3
1 Solution
 
Jeffrey Kane - TechSoEasyPrincipal ConsultantCommented:
Your SBS CALs would cover the additional Server 2003, but I don't really understand why you would deploy a separate server for ISA when SBS integrates it so nicely!  If you install the premium component ISA Server 2004 on your SBS, everything will be configured automatically with SBS's wizards.  

I really don't quite understand your reasoning here.

Jeff
TechSoEasy
0
 
jsvorAuthor Commented:
The reason I will be having the ISA server on a separate server than the SBS is because I don't like the idea of having my DC being connected directly to the internet.
0
 
Jeffrey Kane - TechSoEasyPrincipal ConsultantCommented:
Your absolutely right that a DC shouldn't be directly connected to the Internet... unless it's SBS with ISA and/or a hardware firewall.

It's important to realize that properly configured, SBS is a secure server.  When you go away from the proven configuration which has been deployed by hundreds of thousands of small businesses, you run a much greater risk of having an insecure environment because you're basically on your own to know if a threat would be applicable to your environment.

One thing I should point out is that if you bought the Premium Edition of SBS, licensing prohibits installing ISA on a separate machine.  So you would need to purchase a separate ISA which runs $1,499.00 PER PROCESSOR in addition to the $999.00 for the Standard Server 2003 license needed for it to run on.

Now granted you are using the Action Pack which makes this initial cost irrelevant, but the ongoing upkeep will definitely be costly.  You won't find many, if any, resources for your configuration.

Jeff
TechSoEasy
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
jsvorAuthor Commented:
OK.  With the configuration you are suggesting (ISA installed on SBS) would/should I create a DMZ for a published TS or will the ISA server provide enough protection to have the TS in the internal network?  I am concerned that the extra traffic going to the SBS may slow it down - is that something to worry about?  I just don't want to run into any performance issues.

Thanks for all the input.
0
 
Jeffrey Kane - TechSoEasyPrincipal ConsultantCommented:
ISA will handle it just fine.  I've never seen an SBS slow down because of this... as long as you've got a proper machine to begin with.  You'll overcome any performance issues by having the correct hardware.  If anything err on the side of more than you think you need.  These days, that may only be a difference of $400 or $500 which if divided by your total users may only be pennies per day per user.

Jeff
TechSoEasy
0
 
jsvorAuthor Commented:
The machine is pretty beefy so then I guess I'll be all set there.  Are there any concerns I should have installing ISA on an established SBS that is running Exchange, SQL, and tape backups?

How about the TS on the DMZ?  Would it be OK to have the TS on the internal network for remote users to connect to?  Or will it be secure enough just being behind the ISA?
0
 
Jeffrey Kane - TechSoEasyPrincipal ConsultantCommented:
Putting the TS in a DMZ means that you have to separately manage the logins for it... you lose all the benefit of having everything under one control.  Once you start making separate this and that logins you will have a much more unsecure environment.  Keep it under Active Directory and your Domain's control.

See http://sbsurl.com/sbstss for the how-to for adding a terminal server to an SBS network.

As for adding ISA?  It's almost always added after-the-fact.  So just follow the instructions to install the premium technologies.  http://sbsurl.com/premium

Jeff
TechSoEasy
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now