[isalist] Re: ASA 5500 in front of ISA 2006

  • From: "Thomas W Shinder" <tshinder@xxxxxxxxxxx>
  • To: <isalist@xxxxxxxxxxxxx>
  • Date: Thu, 6 Sep 2007 16:57:08 -0500

http://www.ISAserver.org
-------------------------------------------------------

I was wondering what the ASA bug box was doing there too. Adding a level
of complexity to help increase the risk of misconfiguration?

Thomas W Shinder, M.D.
Site: www.isaserver.org
Blog: http://blogs.isaserver.org/shinder/
Book: http://tinyurl.com/3xqb7
MVP -- Microsoft Firewalls (ISA)

 

> -----Original Message-----
> From: isalist-bounce@xxxxxxxxxxxxx 
> [mailto:isalist-bounce@xxxxxxxxxxxxx] On Behalf Of Jim Harrison
> Sent: Thursday, September 06, 2007 3:40 PM
> To: isalist@xxxxxxxxxxxxx
> Subject: [isalist] Re: ASA 5500 in front of ISA 2006
> 
> http://www.ISAserver.org
> -------------------------------------------------------
>   
> Make it easy for yourself.
> Lose the Cisco or sell it to some unsuspecting victim.
> Add another NIC to ISA and create a third-leg DMZ.
> This way, only ISA has access to the traffic between these networks.
> 
> -----Original Message-----
> From: isalist-bounce@xxxxxxxxxxxxx 
> [mailto:isalist-bounce@xxxxxxxxxxxxx]
> On Behalf Of Robert Wolff
> Sent: Thursday, September 06, 2007 1:27 PM
> To: isalist@xxxxxxxxxxxxx
> Subject: [isalist] ASA 5500 in front of ISA 2006
> 
> All,
> 
>  
> 
> Does anyone know any tricks or have any experience with 
> configuration in
> the following scenario:
> 
>  
> 
> Inet Router => Cisco ASA firewall => DMZ => ISA 2006 Firewall 
> =>Internal
> network
> 
>  
> 
> The current network layout is just a single ISA 2006 firewall.  I'm
> looking to create a new DMZ segment between the ISA and ASA for future
> web, DNS, and email servers.  
> 
>  
> 
> Inet Router => ISA 2006 Firewall => Internal Network
> 
>  
> 
> One of the last problems I have is getting OWA to work.  I can get the
> initial login screen to appear, but after logon I get page cannot be
> displayed after several seconds of waiting.   
> 
>  
> 
> Thanks,
> 
> -Bob-
> 
> 
> All mail to and from this domain is GFI-scanned.
> 
> ------------------------------------------------------
> List Archives: //www.freelists.org/archives/isalist/  
> ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp 
> ISA Server Articles and Tutorials: 
> http://www.isaserver.org/articles_tutorials/ 
> ISA Server Blogs: http://blogs.isaserver.org/ 
> ------------------------------------------------------
> Visit TechGenix.com for more information about our other sites:
> http://www.techgenix.com 
> ------------------------------------------------------
> To unsubscribe visit http://www.isaserver.org/pages/isalist.asp 
> Report abuse to listadmin@xxxxxxxxxxxxx 
> 
> 
> 
------------------------------------------------------
List Archives: //www.freelists.org/archives/isalist/
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server Articles and Tutorials: http://www.isaserver.org/articles_tutorials/
ISA Server Blogs: http://blogs.isaserver.org/
------------------------------------------------------
Visit TechGenix.com for more information about our other sites:
http://www.techgenix.com
------------------------------------------------------
To unsubscribe visit http://www.isaserver.org/pages/isalist.asp
Report abuse to listadmin@xxxxxxxxxxxxx

Other related posts: