RE: Creating packet filters for TZO in ISA

  • From: "Thomas W Shinder" <tshinder@xxxxxxxxxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Tue, 8 Jul 2003 19:56:07 -0500

Hi Marv,

You use a single IP address on the external interface of the ISA Server
firewall to publish multiple sites.

It's the miracle of the Web Proxy service and the Incoming Web Requests
listener. It sees the host header and routes the request based on the
settings in your Web Publishing Rules.

Check the domain name in my email address. I'm a BIG fan of TZO.

Thanks!
Tom

Thomas W Shinder 
www.isaserver.org/shinder 
ISA Server and Beyond: http://tinyurl.com/1jq1 
Configuring ISA Server: http://tinyurl.com/1llp 



-----Original Message-----
From: marvc [mailto:marvc@xxxxxxxxxxxxx] 
Sent: Tuesday, July 08, 2003 5:34 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Creating packet filters for TZO in ISA


http://www.ISAserver.org


Thanks for that reply as it clears up a few of the questions I had. It
almost appears as though ISA totally ignores the TZO service that's
running on the server whose sole purpose is to manage multiple web sites
on a single dynamic interface. Or am I missing the point? 
You wrote: 
"If you have 3 websites published on a single unix server, how is ISA
recognizing where to send the request to."

Maybe I'm still thinking in linksys mode where as long as you forward
the port on a given server that has the proper virtual & dns hosts
configured, you should have access to whatever sites are made public.
Otherwise it seems like I have to either have separate IP's assigned to
each website or end up with each website being accessed on different
ports. I don't mind assigning a different internal IP to each of the
websites and publishing them so long as I don't have to have to change
the port and end up with something like www.nubiint.com:81. 

You wrote: 
"If the unix server only has 1 ip address, then you will need to publish
them on isa, by using the ip address and a different port no for each
site,"

I've published this server and it's initial ip on port 80. You're saying
publish site#2 on port81 & site#3 on port82 using the same internal ip?
Then go to the unix server and make the changes there....hmmm. That's a
toughy. 
Am I understanding right or am I again missing the point. 

I'll definitely be getting all of dr. shin's books in the near future.
Unable to now due to budgeting restraints. So I'm forced to learn
online, the lists, or the help. 

Thanks


Other related posts: