Solved

ISA Server implementation

Posted on 2009-07-09
11
476 Views
Last Modified: 2012-05-07
I'm not particularly good with ISA Server but having given the task i have to accomplish it. I managed to install the ISA Server as per the installation guide. Configured the interfaces as told and it looks like this:

Internal: 172.10.0.1
          255.255.0.0
          No default gateway
          Preferred DNS Server IP

External: 10.10.10.2
          255.255.0.0
          10.10.10.1 - is the default gateway

This connection is like this
Internal Network (192.168.x.x) ---> L3 interface(172.10.0.2) connects to the Firewall Internal Ethernet port (IP 172.10.0.1)

Firewall External Ethernet port (10.10.10.2) forwards all traffic to Router's internal Ethernet interface (IP 10.10.10.1)

I don't have an option but only 15-20 minutes(downtime) to put the ISA server onto the live network. So i have a route on my L3 switch that forwards all traffic to the internal interface of the ISA Server. The entries on the L3 switch are:

interface Vlan1
 ip address 172.10.0.2 255.255.255.0

ip classless
ip route 0.0.0.0 0.0.0.0 172.10.0.1
ip http server

The router is all set to receive traffic from 10.10.10.2 on 10.10.10.1 and the router has the below entries:

interface FastEthernet0/1
 ip address 10.10.10.1 255.255.255.252

interface Vlan1
ip route 0.0.0.0 0.0.0.0 210.194.x.x
ip route 192.168.0.0 255.255.0.0 10.10.10.2

ip access-list extended NAT-Allow-All
 permit ip 10.10.10.0 0.0.0.3 any

ip access-list extended nat-allow-all
!
access-list 101 permit ip 192.168.0.0 0.0.255.255 any
access-list 101 permit ip 10.10.10.0 0.0.0.255 any

I connected the ISA server on the network and this is what happens:

1. I cannot reach a website on the ISA Server although i'm able to ping to the router from the ISA Server
2. From my internal LAN i'm not able to reach 172.10.0.1, although i can telnet to the L3 switch on IP 172.10.0.2

I'm not able to figure out where the problem lies and how to fix it. Please help. Hope i explained the issue properly.
0
Comment
Question by:vinsenapati
  • 5
  • 4
  • 2
11 Comments
 
LVL 1

Expert Comment

by:mkamranjaved
ID: 24812823
hi

have u configured any rule in ASA. if not then create a rule in which select source any destination any and services also any then c the behaviour.....
0
 
LVL 1

Expert Comment

by:mkamranjaved
ID: 24812893
0
 
LVL 1

Author Comment

by:vinsenapati
ID: 24813667
I'm having ISA Server 2006 Standard.
I have created a rule in the ISA GUI --> configuration --> networks --> internal (select properties) and in the LAT i have entries for 192.168.100.x - 192.168.200.255 and 172.10.0.0 - 172.10.0.255, but still no luck.
I know this is just a routing issue and I'm expecting someone to guide me on the entries done on the L3 switch, ISA and Router.

Please help..
0
Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

 
LVL 8

Expert Comment

by:pgolding00
ID: 24813809
can you describe better the network from internal user land to the internet router, in terms of the ip addresses and mask of each interface and the routes configured, in each box in the path? its a bit difficult to see the full picture without this info. e.g. it looks like the router you mention must have a 210.192.x.x address but its not mentioned in your question.

also, just noticed you seem to have the mask for 10.10.10 network set to 16 bits on the isa but 30 bits on the router - if this is the same subnet then the mask needs to match on all the hosts in the subnet.
0
 
LVL 1

Author Comment

by:vinsenapati
ID: 24837951
Existing without ISA Firewall:
internal traffic comes to the L3 switch with a IP of 192.168.x.x and mask 255.255.255.0. The L3 switch (IP 10.10.10.2 mask 255.255.255.252) then forwards all traffic to the router (IP 10.10.10.1) which forwards traffic to the Internet.

Setup with ISA (which i'm planning to implement now):
Internal traffic comes to the L3 switch with a IP of 192.168.x.x and mask 255.255.255.0. The L3 switch (interface vlan1 IP is 172.10.0.2) then forwards all traffic to the ISA Server internal interface (IP 172.10.0.2 mask 255.255.0.0 and no default gateway). The ISA Server is supposed to route the traffic to the external interface which has a IP 10.10.10.2 mask 255.255.255.0 gateway 10.10.10.1. The IP of internal interface of the router is 10.10.10.1.

Problem:

I'm able to reach the L3 switch but not the ISA  Server. And if i try to browse the Internet from the ISA server i still can't do it.


0
 
LVL 8

Expert Comment

by:pgolding00
ID: 24849232
the l3 switch needs to have an interface vlan ? with address in the 192.168 network - you have not mentioned if that has been done. it also needs a default route pointing to the isa server, which i think you have set to 172.10.0.1/255.255.0.0 - please confirm?

the isa server has outside interface 10.10.10.2/255.255.0.0, the outside router has inside interface 10.10.10.1/255.255.255.252 - please verify? this wont work - the masks on these devices need to be the same, either 255.255.0.0 or 255.255.255.252.

the same goes for all other interfaces on all devices. all devices on the same vlan must have the same mask and all devices must have a default route or default gateway, including the isa server.

correct these things and then test again to see how it goes.
0
 
LVL 1

Author Comment

by:vinsenapati
ID: 24869529
What do you mean by this : the L3 switch needs to have an interface vlan with address in the 192.168 network
Ok, read carefully, I have the below in the running configuration of L3 switch:

interface Vlan1
 ip address 172.10.0.2 255.255.255.0

AND

ip classless
ip route 0.0.0.0 0.0.0.0 172.10.0.1
ip http server
(This is the default route pointing to the ISA Server)
Is it correct?

I'll correct the masks and try again

0
 
LVL 8

Expert Comment

by:pgolding00
ID: 24904669
i mean that the l3 switch needs to have an interface configured in each subnet for it to route between the subnets. from your second last comment it looks like you want the switch to route between 192,168 and 172.10 networks? it was not clear that you have two such interfaces configured in the switch, so can you confirm that you do have one interface is each of these subnets please.
0
 
LVL 1

Author Comment

by:vinsenapati
ID: 24905046
I have attached my L3 switch config. Please have a look at suggest where do i make changes.
L3-config.txt
0
 
LVL 8

Accepted Solution

by:
pgolding00 earned 250 total points
ID: 24922095
all the switch ports are configured for vlan1, so they are all in the 10.10.10.0/30 subnet - assuming you have provided all the interface config from the switch? (i.e. not deleted any lines from under each "interface FastEthernet0/xx" line).

to put the switch ports into other vlans, which i guess is what you want, you would configure this -
interface fast0/x
switchport access vlan xxx

and you can get rid of the switchport trunk allow commands as they only have effect when the port is configured as a trunk.

do you really need one subnet per switch port? are there hundreds of pc's at this site?

now once you have all the interface masks corrected and you have the switch ports attached to some vlan other then vlan1, test again from a pc. try to ping the 192.168.subnet.1 address of the switch, if that works try 172.10.0.1 or 10.10.10.2, depending on if you have the isa installed or not.

my limited understanding of isa proxy/firewall is that you would have to allow icmp before you could ping through the isa.

fyi, 172.10.0.1 is not a valid address to use as its a valid internet address. the valid range is 172.16.0.0 to 172.31.255.255, as per rfc1918. this should not present a huge problem unless someone tries to access the real 172.10.x.x network on the internet from this site.
0
 
LVL 1

Author Comment

by:vinsenapati
ID: 25096254
Ok, Now i having done these changes it still doesn't work.
Changes done:

Internal network 192.168.x.x
L3 switch IP remains at 10.10.10.2
ISA Server Internal interface 10.10.10.1 mask 255.255.255.252
ISA Server Internal interface 10.10.11.2 maks 255.255.255.252 gateway 10.10.11.1
default route on the L3 is all traffic from internal goes to 10.10.10.1
In the ISA Server command prompt i have added a route : route -p 192.168.0.0 mask 255.255.255.252 10.10.10.2

I can ping from ISA server to the L3 switch but i can ping to a 192.168.x.x
I can ping from L3 to ISA server but can't ping from 192.168.x.x to the ISA server
So from the Internal network i can ping to L3 switch but not to the ISA Server but i can ping to the ISA server from L3 and from the ISA Server i can ping to the L3 switch but not to the internal network.

Sorry for the delay in response.
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I wanted to share this with fellow Experts, who might not know. How often have you wanted to learn something, only to be set back by either restrictions imposed on "trial" or "evaluation" software?  How often have you had to rebuild a home networ…
We were having a lot of "Heartbeat Alerts" in our SCOM environment, now "Heartbeat" in a SCOM environment for those of you who might not be familiar with SCOM is a packet of data sent from the agent to the management server on a regular basis, basic…
The view will learn how to download and install SIMTOOLS and FORMLIST into Excel, how to use SIMTOOLS to generate a Monte Carlo simulation of 30 sales calls, and how to calculate the conditional probability based on the results of the Monte Carlo …
The viewer will learn how to create a normally distributed random variable in Excel, use a normal distribution to simulate the return on an investment over a period of years, Create a Monte Carlo simulation using a normal random variable, and calcul…

822 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question