DMZ - The Hell

  • From: "Alex Decarli" <decarli@xxxxxxxxxxxxx>
  • To: <isalist@xxxxxxxxxxxxx>
  • Date: Thu, 26 Sep 2002 10:46:29 -0300

Hi all,
 
Again, I come to list to find help to implement DMZ.
I read "DMZ Scenarios" on isaserver. rg and "HOW To: Publish Web Server in 
Perimeter Network - q313562". ALL RECOMENDATIONS ARE APLLIED.
 
 
My problem is:  I can't to connect my webserver on DMZ from internet.
But, i can connect my webserver from internal network and ISA Computer (the 
connections has proxy configured, either).
 
My Scenario is:
===========
 
[ ISP ROUTER ] -------------------------------- ** ISA External NIC **
(subnet1 e subnet2)                             Defaut gateway is router subnet 
1
                                                         |
                                                         | 
                                                       ISA SERVER 
------------------------------------------------------------------------------------------------------------
 [ INTERNAL NETWORK]
                                                         |                      
                                                                                
                                   LAT: 10.1.1.x                   
                                                         |                      
                                                                                
                                      
                                                         ** ISA DMZ NIC **
                                                         IP Public (subnet2)
                                                         Diferent Subnet of ISA 
External NIC
                                                         No  Defaut Gateway     
                                                     |
                                                          |  
                                                          |
                                                          |
                                                          |
                                                         [ WEB SERVER ]
                                                         IP Public (subnet 2)
                                                         Defaut gateway is ISA 
DMZ NIC
                                                         
I've configured a "IP Packet Filters Rule" called "Allow webserver on DMZ" , IP 
routing and IP Packet filters are enabled, with pre-defined HTTP 80 Port , 
applied to IP address of webserver. exactly q313562
 
My ISA Server is Standalone Server, SP1, Windows is Server Standard, SP3, no 
more.
 
Any help is apprecied !
 
Alex Decarli.

Other related posts: