?
Solved

ISA Server Basic Configuration Cont??

Posted on 2008-06-10
10
Medium Priority
?
277 Views
Last Modified: 2010-04-21
I followed the explanation by keith_alabaster on question ID  22454299 on the basic configuration on ISA server 2006, the server has two nic cards, one is for internet access and the other is for handling internal traffic to our programs. The server allows users access to the internet depending on the proxy configuration or denies it by proxy misconfiguration on group policies, but now we want to use ISA server to allow limited access. What kind of network template should I use when configuring ISA? As soon as I install it the server loses internet access because I only declare the internal network the nic card without gateway nor dns info. I don't know how to declare the other card that allows the internet and has all the router info. Is there a second part to that question?
0
Comment
Question by:carloslaso
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 5
10 Comments
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 21754852
Depends on your configuration - If there is another firewall between ISA and the Internet then select the back-end firewall. If ISA is the first firewall that traffic will hit as it comes in through your router/gateway then select front-end.

The main difference is that as a front-end firewall ISA will provide the NAT function to 'hide' the internal IP addresses by default. To be honest, this is the option I always use when I do not have DMZ interfaces involved on the ISA itself.

Keith
0
 

Author Comment

by:carloslaso
ID: 21754879
So I should not declare the nic I use to handle internal traffic? Should I declare the one that has internet access as the internal and use the Front-end template?
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 21754921
??

The NIC that has internet access is the external, the other is the internal. When you run the template, you will be asked to give ip addresses on the internal card only - and MUST include ALL internal addresses. So do NOT add all private addresses, just enter those relevant to your internal network.

For example, if you have 192.168.10.200 as the ip address on the uinternal nic, you would enter 192.168.10.0 - 192.168.10.255. All addresses includes the Network ID and the broadcast address. ALL IP addresses NOT entered into the LAT, when it prompts, will be treated as external from your inside network.
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:carloslaso
ID: 21755797
I configures ISA using the EDGE network template and i am able to ping yahoo and google but i cannot do anything more, i noticed that the DHCP server disconnects as soon as i close that window.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 21757004
The internal nic MUST have dns info - it must point to the internal dns server.
The internal nic does not have a default gateway.

The external nic MUST NOT have dns info
The external nic WILL have a default gateway of the external router.

The Internal DNS server MUST have its forwarders set to point at the external (ISP) dns servers.

What DHCP server? ISA nics (internal & external) should have static ip addresses or their respective subnets.
0
 

Author Comment

by:carloslaso
ID: 21757177
I will try some of those MUSTs and WILLs, I may have put something wrong there.

As for the DHCP server, is that needed to assign IPs to the PCs being protected or controlled by ISA Server or they also have to have Static IP Addresses?

I only have one server where I installed Windows 2003 and ISA 2006, is that allowed or should I have a different server just for ISA? If so, can it be installed on a virtual pc or a separate box (server) is required?
0
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 2000 total points
ID: 21757201
OK - the dhcp server can set the internal client IP's - thats fine. I read your post as saying that the dhcp server was supplying the ISA server withis internal ip address.

ISA should not be run on a domain controller unless you are using windows SBS server. Best practice states that ISA should not be run on a virtual machine in a production environment but i have seen it done and it seems to work OK. MS will not support that installation though. Personally I always use a separate box for customers as it is best practice. In my test labs though? - always on Virtual PC (not virtual server).

0
 

Author Comment

by:carloslaso
ID: 21757215
I forgot to mention that I got Internet explorer to work on the server (not on the PCs), using the info on the last post of the following link: http://tinyurl.com/6cxgsm , but not firefox, tzo  and some other apps.  I still need to check some of the IPs that I may have put wrong in the DNS of the nics
0
 

Author Closing Comment

by:carloslaso
ID: 31465921
I'm accepting this as an answer because all of what the author posted helped me get Internet to the server, Internet access to the rest of the programs can be investigated on different questions on this forum or using the search option.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 21761851
Thanks :)
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I'm a big fan of Windows' offline folder caching and have used it on my laptops for over a decade.  One thing I don't like about it, however, is how difficult Microsoft has made it for the cache to be moved out of the Windows folder.  Here's how to …
An article on effective troubleshooting
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Do you want to know how to make a graph with Microsoft Access? First, create a query with the data for the chart. Then make a blank form and add a chart control. This video also shows how to change what data is displayed on the graph as well as form…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question