Solved

Perimeter network access to internal network in a Back firewall configuration (ISA 2006)

Posted on 2008-10-07
5
655 Views
Last Modified: 2008-11-17
Hello,

I have a server in the perimeter network that requires access to the internal network.  Temporarily I want all traffic from this server to the internal network permitted.  I have setup a firewall rule to allow this, but it doesnt seem to work.  I have setup logging and access is denied to the internal network by the default deny rule.  

Do I need to setup any additional Network rules, other then the default rules?
0
Comment
Question by:AC_Nova
  • 3
  • 2
5 Comments
 
LVL 11

Expert Comment

by:EricTViking
ID: 22664416
The sort of rule you probably need is allow all outbound traffic, from server in perimeter network, to internal for all users. That should be the only rule you need.
0
 
LVL 5

Author Comment

by:AC_Nova
ID: 22666870
Thats what I have, but its not working.
0
 
LVL 11

Expert Comment

by:EricTViking
ID: 22694654
Could you describe the topology of your network in a bit more detail? What networks do you have and what are their IP ranges? And where abouts on the network are your servers?
0
 
LVL 5

Author Comment

by:AC_Nova
ID: 22700745
ISA
Ethernet adapter External:
   IP Address. . . . . . . . . . . . : 10.58.9.5
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 10.58.9.1
Ethernet adapter Internal:
   IP Address. . . . . . . . . . . . : 10.59.69.1
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . :
   DNS Servers . . . . . . . . . . . : 10.59.57.46
                                       10.59.57.47

server that I wish to access in the dmz
10.59.9.7
255.255.255.0
10.59.9.1

10.58.9.1 is a hardware firewall.

dns servers are internal:

10.59.57.46
 10.59.57.47

0
 
LVL 5

Accepted Solution

by:
AC_Nova earned 0 total points
ID: 22701826
Dont worry I've sorted it.  It was a network route combined with a host add on the cisco kit.

cheers
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In Africa (and potentially where you live…), reliability of ISPs is questionable.  With the increased reliance on e-mail as one of the primary forms of communication, the costs to business are significant based on interuption of ISP Connectivity.  T…
Common practice undertaken by most system administrators is to document the configurations and final solutions of anything performed by them for their future use and reference. So here I am going to explain how to export ISA Server 2004 Firewall pol…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question