Best place to install ISA 2006 Enterprise ?

Posted on 2009-02-21
Last Modified: 2012-06-27
Hi guies
I installed and configured a stand alone IS 2006 EE server on win 2003 server and could publish all the sites.
now I want to install in the corpoprate network: with AD and cluster and nlb win 2003 servers.
I have a DMZ network, Internal network  and WFE server sin the Internal netowork.
what is best practice : should I install ISA 2006 in the dmz serevers or should I install inside the network on some servers.
Where do you think is the best place for CSS server. ?

I have a WFE NLB cluster in one sub net, can i install ISA css in this subnet to can i choose  to have another subnet server have css and other array in adifferent subnet.

Question by:Audi08
    LVL 15

    Accepted Solution

    CSS server internally.
    ISA with one interface internally (each, and load balanced) and the external interface in the DMZ.
    Forward a couplke of IP's from the external firewall to the external interface(s) of the the ISA NLB cluster
    CSS can basically be placed anywhere - as long as the nodes can contact the CSS... its fine.
    LVL 51

    Expert Comment

    by:Keith Alabaster
    You can do either but a numbr of things need to be considered.
    Although the CSS can go on any subnet, it really should be a subnet local to the ISA Site location. Latency can cause some real issues.
    Make sure the location of the CSS has a DC available - again, really painful otherwise.
    LVL 1

    Author Comment

    so to get the idea clarified
    this is what I am planning to do after seeing your comments
    a) install CSS in some server where dc is avaliable and  add the dmz computer and another internal server  into the array
    b)install ISA serveices on the server in the dmz  and the other one.

    internal traffic can will hit the internal server and external trafic /internet traffic will hit the server in isa, or in other words dmz isa intance will handle external networks and the internal network server will handle internal traffic.

    hey guies I am trying to get the  web interface login which ISA provides. where do I get it show ulr ?should I  install any other software for this.
    i am plannin for Sing Signon services.


    Featured Post

    Better Security Awareness With Threat Intelligence

    See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

    Join & Write a Comment

    In all versions of ISA Server and the current version of FTMG, the default https protocol uses TCP port 443 and 563 only. This cannot be changed within the ISA or FTMG GUI and must be completed from a Windows cmd prompt on the ISA Server itself. …
    In Africa (and potentially where you live…), reliability of ISPs is questionable.  With the increased reliance on e-mail as one of the primary forms of communication, the costs to business are significant based on interuption of ISP Connectivity.  T…
    This video is in connection to the article "The case of a missing mobile phone (". It will help one to understand clearly the steps to track a lost android phone.
    In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

    731 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    15 Experts available now in Live!

    Get 1:1 Help Now