Re: LATDMZ

  • From: "Thomas W Shinder" <tshinder@xxxxxxxxxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Fri, 7 Mar 2003 09:23:48 -0600

Hi Jeffrey,
 
Hmmm. I was hoping you would have said something else. OK, enable RRAS
and LAN routing. Best way to do this is to run the VPN Server Wizard
from the ISA Management console. If you don't want to allow inbound VPN
connections, just disable the packet filters the Wizard creates.
 
HTH,
Tom

Thomas W Shinder 
www.isaserver.org/shinder 
ISA Server and Beyond: http://tinyurl.com/1jq1 
Configuring ISA Server: http://tinyurl.com/1llp 

        -----Original Message-----
        From: Zhangjb2 [mailto:zhangjb2@xxxxxxxxxxx] 
        Sent: Friday, March 07, 2003 9:21 AM
        To: [ISAserver.org Discussion List]
        Subject: [isalist] Re: LATDMZ
        
        
        http://www.ISAserver.org
        
        
        clients' default gateway is internal network card IP address on
ISA server.
        Jeffrey

                ----- Original Message ----- 
                From: Thomas W Shinder
<mailto:tshinder@xxxxxxxxxxxxxxxxxx>  
                To: [ISAserver.org Discussion List]
<mailto:isalist@xxxxxxxxxxxxx>  
                Sent: Friday, March 07, 2003 10:03 AM
                Subject: [isalist] Re: LATDMZ

                http://www.ISAserver.org
                
                
                Hi Jeffrey,
                 
                How to the clients know the route to remote networks?
                 
                (HINT)
                 
                HTH,
                Tom

                Thomas W Shinder 
                www.isaserver.org/shinder 
                ISA Server and Beyond: http://tinyurl.com/1jq1 
                Configuring ISA Server: http://tinyurl.com/1llp 

                        -----Original Message-----
                        From: Jeffrey Zhang
[mailto:zhangjb2@xxxxxxxxxxx] 
                        Sent: Thursday, March 06, 2003 10:48 PM
                        To: [ISAserver.org Discussion List]
                        Subject: [isalist] Re: LATDMZ
                        
                        
                        http://www.ISAserver.org
                        
                        
                        Hi Tom,
                         
                        Yes, you got the right network structure, a
tri-homed ISA server, two different subnets for internal and DMZ, an
external network to internet, web server and FTP server is in DMZ.
                         
                        I'd like to let clients in internal network to
access web and FTP server in DMZ, and external clients can also access
them.
                         
                        I read your chapter 4 and understand 3 methods
to control the traffic between internal network and LATDMZ, but my
problem is before the first step, you describe that if I connect two
subnets to ISA and enable the IP Routing, they can communicate each
other. I did but I can not access DMZ from internal net. 
                         
                        Where do I need to check?
                         
                        thanks 
                        Jeffrey

                                ----- Original Message ----- 
                                From: Tom Mendelboim
<mailto:tomerm1@xxxxxxx>  
                                To: [ISAserver.org Discussion List]
<mailto:isalist@xxxxxxxxxxxxx>  
                                Sent: Thursday, March 06, 2003 6:00 PM
                                Subject: [isalist] Re: LATDMZ

                                http://www.ISAserver.org
                                
                                
                                
                                This is a multi-part message in MIME
format.
                                

                                
  _____  


                                

                                Let me get it straight.
                                
                                You have three interfaces on the ISA.
One with "Legal" IP on the internet, one with local IP as the DMZ brench
and one with a different local IP (or different subnet) on the last
interface.
                                
                                What type of communications you are
trying to establish between the Local network and the Local DMZ network?
                                
                                Who is initiating the traffic?
                                
                                Tom
                                > 
                                > From: "Zhangjb2"
<zhangjb2@xxxxxxxxxxx>
                                > Date: 2003/03/06 Thu PM 04:54:43 EST
                                > To: "[ISAserver.org Discussion List]"
<isalist@xxxxxxxxxxxxx>
                                > Subject: [isalist] Re: LATDMZ
                                > 
                                > http://www.ISAserver.org
                                > 
                                > 
                                > MessageHi Tom,
                                > 
                                > I created the IP packet filters, but I
can not access LATDMZ. Actually when just created internal, LATDMZ and
external networks, I can not access LATDMZ, but I can access external
network (internet). Could you give any suggestion on how to check?
                                > 
                                > thanks
                                > Jeffrey
                                >   ----- Original Message ----- 
                                >   From: Zhangjb2 
                                >   To: [ISAserver.org Discussion List] 
                                >   Sent: Wednesday, March 05, 2003 4:57
PM
                                >   Subject: LATDMZ
                                > 
                                > 
                                >   Hi Tom,
                                > 
                                >   I created a LATDMZ behind ISA
server, I enabled IP routing in ISA, but my internal clients cannot
access server in LATDMZ. Can you give any suggestion to figure out this
problem?
                                > 
                                >   Thanks
                                >   Jeffrey
                                > 
                                >
------------------------------------------------------
                                > List Archives:
http://www.webelists.com/cgi/lyris.pl?enter=isalist
                                > ISA Server Newsletter:
http://www.isaserver.org/pages/newsletter.asp
                                > ISA Server FAQ:
http://www.isaserver.org/pages/larticle.asp?type=FAQ
                                >
------------------------------------------------------
                                > Exchange Server Resource Site:
http://www.msexchange.org/
                                > Windows Security Resource Site:
http://www.windowsecurity.com/
                                > Windows 2000/NT Fax Solutions:
http://www.ntfaxfaq.com
                                >
------------------------------------------------------
                                > You are currently subscribed to this
ISAserver.org Discussion List as: tomerm1@xxxxxxx
                                > To unsubscribe send a blank email to
$subst('Email.Unsub')
                                > 
                                > 
                                

                                
  _____  


                                

                                http://www.ISAserver.org
                                
                                
                                Hi Tom,
                                 
                                I created the IP packet filters, but I
can not access LATDMZ. Actually when just created internal, LATDMZ and
external networks, I can not access LATDMZ, but I can access external
network (internet). Could you give any suggestion on how to check?
                                 
                                thanks
                                Jeffrey

                                ----- Original Message ----- 
                                From: Zhangjb2
<mailto:zhangjb2@xxxxxxxxxxx>  
                                To: [ISAserver.org Discussion List]
<mailto:isalist@xxxxxxxxxxxxx>  
                                Sent: Wednesday, March 05, 2003 4:57 PM
                                Subject: LATDMZ

                                
                                Hi Tom,
                                 
                                I created a LATDMZ behind ISA server, I
enabled IP routing in ISA, but my internal clients cannot access server
in LATDMZ. Can you give any suggestion to figure out this problem?
                                 
                                Thanks
                                Jeffrey

        
------------------------------------------------------
                                List Archives:
http://www.webelists.com/cgi/lyris.pl?enter=isalist
                                ISA Server Newsletter:
http://www.isaserver.org/pages/newsletter.asp
                                ISA Server FAQ:
http://www.isaserver.org/pages/larticle.asp?type=FAQ
        
------------------------------------------------------
                                Exchange Server Resource Site:
http://www.msexchange.org/
                                Windows Security Resource Site:
http://www.windowsecurity.com/
                                Windows 2000/NT Fax Solutions:
http://www.ntfaxfaq.com
        
------------------------------------------------------
                                You are currently subscribed to this
ISAserver.org Discussion List as: tomerm1@xxxxxxx
                                To unsubscribe send a blank email to
$subst('Email.Unsub') 

                                
  _____  


                                

        
------------------------------------------------------
                                List Archives:
http://www.webelists.com/cgi/lyris.pl?enter=isalist
                                ISA Server Newsletter:
http://www.isaserver.org/pages/newsletter.asp
                                ISA Server FAQ:
http://www.isaserver.org/pages/larticle.asp?type=FAQ
        
------------------------------------------------------
                                Exchange Server Resource Site:
http://www.msexchange.org/
                                Windows Security Resource Site:
http://www.windowsecurity.com/
                                Windows 2000/NT Fax Solutions:
http://www.ntfaxfaq.com
        
------------------------------------------------------
                                You are currently subscribed to this
ISAserver.org Discussion List as: zhangjb2@xxxxxxxxxxx
                                To unsubscribe send a blank email to
$subst('Email.Unsub')
                                

        
------------------------------------------------------
                        List Archives:
http://www.webelists.com/cgi/lyris.pl?enter=isalist
                        ISA Server Newsletter:
http://www.isaserver.org/pages/newsletter.asp
                        ISA Server FAQ:
http://www.isaserver.org/pages/larticle.asp?type=FAQ
        
------------------------------------------------------
                        Exchange Server Resource Site:
http://www.msexchange.org/
                        Windows Security Resource Site:
http://www.windowsecurity.com/
                        Windows 2000/NT Fax Solutions:
http://www.ntfaxfaq.com
        
------------------------------------------------------
                        You are currently subscribed to this
ISAserver.org Discussion List as: tshinder@xxxxxxxxxxxxxxxxxx
                        To unsubscribe send a blank email to
$subst('Email.Unsub') 

                ------------------------------------------------------
                List Archives:
http://www.webelists.com/cgi/lyris.pl?enter=isalist
                ISA Server Newsletter:
http://www.isaserver.org/pages/newsletter.asp
                ISA Server FAQ:
http://www.isaserver.org/pages/larticle.asp?type=FAQ
                ------------------------------------------------------
                Exchange Server Resource Site:
http://www.msexchange.org/
                Windows Security Resource Site:
http://www.windowsecurity.com/
                Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
                ------------------------------------------------------
                You are currently subscribed to this ISAserver.org
Discussion List as: zhangjb2@xxxxxxxxxxx
                To unsubscribe send a blank email to
$subst('Email.Unsub') 

        ------------------------------------------------------
        List Archives:
http://www.webelists.com/cgi/lyris.pl?enter=isalist
        ISA Server Newsletter:
http://www.isaserver.org/pages/newsletter.asp
        ISA Server FAQ:
http://www.isaserver.org/pages/larticle.asp?type=FAQ
        ------------------------------------------------------
        Exchange Server Resource Site: http://www.msexchange.org/
        Windows Security Resource Site: http://www.windowsecurity.com/
        Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
        ------------------------------------------------------
        You are currently subscribed to this ISAserver.org Discussion
List as: tshinder@xxxxxxxxxxxxxxxxxx
        To unsubscribe send a blank email to
$subst('Email.Unsub') 

Other related posts: