I have a couple of test beds that work quite well. With DSL I plug directly into my (Line2 EXT ISA) box. All port type of information is directly passed through to the ISA machine so it can Deal with ports and attacks. With CABLE on my second line I plug my (Line1 EXT ISA) into the DMZ plug on a linksys and forward all traffic into the ISA machine. The extra ports on the link sys are then used to keep my VOIP outside the firewalls. I also keep my WAP stuff inside the honey pot dmz zones and use Mac address for security. And only outgoing access at best towards external ISA's. Each of the second NIC's on my external firewalls connect to switches for a honey pot DMZ zone and then from the honey pot DMZ traffic Move along to my INTERNAL ISA machines. Both INTERNAL ISA machines share resources on the INTERNAL(DMZ) Web sites and MAIL forwarding. My honey pot DMZ's contain sun boxes that do sniffing and additional monitoring. Thank you, Joseph _____ From: MrClasik [mailto:mrclasik@xxxxxxxxxxxx] Sent: Saturday, January 22, 2005 3:52 PM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Trouble with ISA and SMS server http://www.ISAserver.org Not the ISP router.. I have a cable modem. Wondering should I connect the cable modem directly to the firewall box with one nic card and cable and run the other nic to the router.? John Tolmachoff (Lists) wrote: http://www.ISAserver.org ISP routers are always before the firewall, otherwise what are you going to connect to... John Tolmachoff Engineer/Consultant/Owner eServices For You -----Original Message----- From: MrClasik [mailto:mrclasik@xxxxxxxxxxxx] Sent: Saturday, January 22, 2005 3:20 PM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Trouble with ISA and SMS server http://www.ISAserver.org Thanks John.. Trying a new email client and didn't realize that my posts where defaulting to the bottom.. Fixed that.. Okay, I have setup a dedicated box to act as the firewall. Before, I was using ISA just as a normal everyday firewall. I am trying to set it up now. I have two nics in this box. I think this might solve my problem. I pose this question, is it better to have my router in front of the firewall box or behind it. My thought is behind. Traffic hits the firewall box, is then sent from the machine to the router and wherever it has to go then. Is this the correct setup. Thanks for any help... ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: World of Windows Networking: http://www.windowsnetworking.com Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: mrclasik@xxxxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: World of Windows Networking: http://www.windowsnetworking.com Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: josephk@xxxxxxxxxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx