I'm implementing a ISA 2006 in a PIX DMZ configuration. I've attached a image to display the configuration.
First, I would appreciate any comments on this configuration.
Second, I have some concerns.
1. The ISA in this config is sitting in the DMZ on the front end and on the LAN on the back end. My concern is if the ISA get's compromised, they will have access tot he LAN network.
I'm setting this up to publish OWA/OMA/ActiveSync. Is it that I'm only allowing those protocols through the pix so that limits the security vulnerabilities of the ISA, or should I be concerned about the LAN access.
Thanks in advance.