http://www.ISAserver.org ------------------------------------------------------- I've been asked to put a webserver online on an SBS2k3 (premium) installation. Obviously id prefer this webserver to be in a dmz, but the topology for sbs seems to not like this concept? 3 nics in sbs = wizard-killer? Or sbs-killer? As the company is growing in size (and surface), it seems like now's a good time to review there attack surface also. What I'm looking at is placing a front-end isa2k4 infront of sbs2k3 (with isa2k4), and using the front-end isa to direct the webserver traffic to a perimeter network, and the rest to the sbs box. I've had a look round and cant find many articles on this setup. I did read an article on isainsbs written by Amy, though there wasn't any info on how this scenario may affect the sbs box or its wizards. Anyway my reasoning for going this route is to get a couple of extra servers in there to reduce the one time cost of ditching sbs and separating the severs out, also having a dedicated (uncastrated isa) firewall will help me sleep better at night. The company has a server that's suitably specd to carry out the job, so the costs going to be isa (single proc). And they can live with that. So is this a viable solution, can sbs (premium) live behind a dedicated isa box without freaking out ? Or is there a better solution for them. Steve ------------------------------------------------------ List Archives: //www.freelists.org/archives/isalist/ ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server Articles and Tutorials: http://www.isaserver.org/articles_tutorials/ ISA Server Blogs: http://blogs.isaserver.org/ ------------------------------------------------------ Visit TechGenix.com for more information about our other sites: http://www.techgenix.com ------------------------------------------------------ To unsubscribe visit http://www.isaserver.org/pages/isalist.asp Report abuse to listadmin@xxxxxxxxxxxxx