Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

ISA server tri-homed DMZ web publishing

Thread Tools
 
Search this Thread
 
Old 14 October 2002, 11:05 AM
  #1  
DominicA
Scooby Regular
Thread Starter
 
DominicA's Avatar
 
Join Date: Aug 2000
Posts: 1,771
Likes: 0
Received 0 Likes on 0 Posts
Question

Is anyone doing this?? Any points or routing issues I should be aware of??

I have the 3 network cards installed. Webserver connected via xover cable. Can ping the DMZ network card on ISA server. Can't ping the ISA server external card tho. Can load webpage from internal network.

Is it just a case of setting up a web publishing rule now??

thanks
Dom
Old 14 October 2002, 11:17 AM
  #2  
ChristianR
Scooby Regular
iTrader: (1)
 
ChristianR's Avatar
 
Join Date: May 2001
Location: Europe
Posts: 6,329
Likes: 0
Received 1 Like on 1 Post
Post

Dom,

This may be helpful:

http://www.isaserver.org/pages/article.asp?id=221

Regards,
Christian
Old 14 October 2002, 12:06 PM
  #3  
DominicA
Scooby Regular
Thread Starter
 
DominicA's Avatar
 
Join Date: Aug 2000
Posts: 1,771
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

thanks, i have this already...
Old 14 October 2002, 12:41 PM
  #4  
Ga22ar
Scooby Regular
 
Ga22ar's Avatar
 
Join Date: Dec 2001
Posts: 436
Likes: 0
Received 0 Likes on 0 Posts
Post

set up a server publishing rule from the external nic IP and point it at the IIs servers IP, accept connections from anywhere and specify http server.



to ping you need to set up IP routing, go to Access Policy then IP Packet Filters and select properties. check packet filtering and then ip routing. Having done all that you will need to add icmp packet filters as well..

cheerio
Old 15 October 2002, 10:07 AM
  #5  
DominicA
Scooby Regular
Thread Starter
 
DominicA's Avatar
 
Join Date: Aug 2000
Posts: 1,771
Likes: 0
Received 0 Likes on 0 Posts
Question

publishing worked fine, however, since obviously making port80 available out on the internet, we're seeing large numbers of spoof attacks from 2 ip addresses... how do i ban the packets for these 2 ips completely..... i have been digging out the books and searching the web, no luck yet...
Old 15 October 2002, 10:44 AM
  #6  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Buy a Firewall and don't trust Microsoft Proxy Server (or ISA)....


Jeff
Old 15 October 2002, 11:14 AM
  #7  
DominicA
Scooby Regular
Thread Starter
 
DominicA's Avatar
 
Join Date: Aug 2000
Posts: 1,771
Likes: 0
Received 0 Likes on 0 Posts
Question

Jeff, what would you suggest we replace it with??? we need VPN access... if this effects the choice...

Trending Topics

Old 15 October 2002, 11:18 AM
  #8  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

Budget, how many users, number of concurrent connections, VPN throughput???

Me, I'm a SonicWall fan...
Old 15 October 2002, 11:18 AM
  #9  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Depends on your budget....

SonicWALL at the cheaper end (700-3500 UKP)
Netscreen
Checkpoint (big bucks)

How many hosts do you have (ie machines that need protecting) and what type of VPN do you need (IPSec ??)


Jeff
Old 15 October 2002, 11:21 AM
  #10  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

I would suggest that you look at my profile, but that would be advertising.....Hi Chris .....runs for cover


Jeff
Old 15 October 2002, 02:18 PM
  #11  
Ga22ar
Scooby Regular
 
Ga22ar's Avatar
 
Join Date: Dec 2001
Posts: 436
Likes: 0
Received 0 Likes on 0 Posts
Post

Depends on the size of your environment, cost of support, availability of in-house expertise.. The big firewalls are superb if your a large/huge org that can buyin the skills when it needs it.

With ISA you can create a rule to drop all packets inbound from a specific IP, which of course you can do with all the other firewalls as well..

VPN with ISA can be either PPTP or L2TP(ipsec) which is pretty robust (excusing the recent pptp hole found - oops!!) Checkpoint does provide secureID ability which is about as secure as you can( reasonbly) get.. However you can buy secureID seperate from Checkpoint Firewall if you require it..

Bascially you pays your money and you take you choice - or you pays a consultant to do it all for you - end of day its cost not functionality which decides...

cheerio

Old 15 October 2002, 03:55 PM
  #12  
DominicA
Scooby Regular
Thread Starter
 
DominicA's Avatar
 
Join Date: Aug 2000
Posts: 1,771
Likes: 0
Received 0 Likes on 0 Posts
Question

what i'm after is....

Firewall to connect to ethernet ISP and ethernet LAN
20 user VPN access
DMZ for publishing web and ftp servers
Old 15 October 2002, 04:06 PM
  #13  
DominicA
Scooby Regular
Thread Starter
 
DominicA's Avatar
 
Join Date: Aug 2000
Posts: 1,771
Likes: 0
Received 0 Likes on 0 Posts
Question

SonicWall Pro100 seems to be quite the ticket...???
Old 15 October 2002, 04:24 PM
  #14  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Dominic

The Pro-100 would work well....

Call me if you wish to talk about costs (or look at the web page)

Cheers


Jeff
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Rbon91
ScoobyNet General
49
21 November 2018 03:23 PM
Scott@ScoobySpares
Full Cars Breaking For Spares
55
05 August 2018 07:02 AM
south_scoob
ScoobyNet General
22
03 October 2015 01:05 PM
oilman
Trader Announcements
15
01 October 2015 11:55 AM
TimberTronics
Subaru
0
17 September 2015 08:46 PM



Quick Reply: ISA server tri-homed DMZ web publishing



All times are GMT +1. The time now is 04:24 PM.