[isalist] Re: SME LAN and ISA

  • From: "Egyptian Mind" <innocent_angel_eng@xxxxxxxxxxx>
  • To: isalist@xxxxxxxxxxxxx
  • Date: Mon, 22 May 2006 06:25:06 -0800



Gene,

1- There is two kind of DSL service from the ISP to broad band router in your case; The first is that the DSL router has a dynamic IP from the ISP and all network behind will be also dynamic from that range... the Seconed is that the DSL router has a dynamic IP from the ISP but the inside interface (( as ALl DSL router has at least two interfaces ; one to the telecom company, and the other is RJ 45 to your entire network )) ; I say that the inside interface should have a static IP from a different subnet or even different IP class, and there will be a entire nating mechanism between the two interface inside the router....

Anyway, easily... your network has a default gateway , right? let's say it is (( acording to your diagram )) 10.11.1.1/24.. ok? this Ip should be on the inside interface of the DSL router...

So, in order to not damage your entire network and rebuild it's IP schema again, , simply login to the DSL router and change the entire interface IP to 192.168.1.1...... as example

Then give the outside interface of the ISA server IP from that range, let's say .. 192.168.1.20

and the inside interface of the ISA server ofcourse should be 10.11.1.1 as it will be the gateway of all your network....

 

2- about the rules and how you can do it, I think somewhere in ISA you will find a link to make a rule.. it's simple as it will be a wizard...

it was simple in ISA 2000 and getting easier in 2004...

I think you can do all configuration by wizard in 2004 , even the routing... so I think it will be much easier with ISA 2006.......

but about the rule configuration, I extports some configuration from my ISA and save it as Excel Sheets..

It's attached here , so review it and hope it help you




    Best Regards
   Mohamed Saleh
   
    Senior Network Administrator 
   
College of Business Administration, CBA
    Jeddah, Saudi Arabia
    Tel: +966-02-6563199 ext 2521
    Cell: - +966-50-2953591

 
 
!~` Yesterday is a History` ~!
!~` Tomorrow is a Mystery` ~!
!~` Today is a Gift` ~!
!~` So we call it ...............` ~!
!~` Present .......Simple` ~!
 
 

From: Gene Sibbs <gen_sib@xxxxxxxxx>
Reply-To: isalist@xxxxxxxxxxxxx
To: isalist@xxxxxxxxxxxxx
Subject: [isalist] Re: SME LAN and ISA
Date: Sun, 21 May 2006 10:41:28 -0700 (PDT)

Thanks a stack Egyptian Mind, I am busy acid testing the solution you're proposing. I will let you know how it holds.
 
If you may; I will be happy if you can expand a bit for me bulletin 5 and 6...it is a little bit unclear?
 
5. ISP is DHCP pushing IP addresses down my ADSL router throat. How may I go about assigning IP address to the Outside interface?
 
6. shed light a bit by means of showing me an example?
 
Thanks once again for the proposed solution..
 
Kindest regards,
 
Gene Sibbs 

Egyptian Mind <innocent_angel_eng@xxxxxxxxxxx> wrote:
http://www.ISAserver.org -------------------------------------------------------



1- install the ISA server after the adsl router and before the switch.
2- put two interface cards in the server
3- attach one interface with the adsl router ( outside ) and the other to the unmanged switch ( inside )
4- assign an IP from your local lan to the inside interface
5- assign any IP of the range that given from the ISP ( after the router nat ) to the ouside interface
6- make ur own rules on the ISA server
 
BASIC SME NETWork SETUP
Internet Cloud
 |
 |
 | 
 |
ADSL (AZTECH ETHERNET USB) Broadband Router
 DHCP
 |    _____________________________
 |   |                                                  |
 |___outside interface ( 10.11.1.1/24)    |   ISA Server
  ___insdie interface ( 192.168.1.1/24 )  |
 |   |_____________________________|
 |
|______________________
LoCAL AREA NETWORK (Unmanaged Switch)
LAN IP Address 192.168.1.0/24
______________________________
 
SBS2003-BOX (HP DL3*)  LINUX-Box (HP DL3*)
 
AD   OpenSource Helpdesk System
DHCP   OpenSource Network Monitoring(nagios, nmis)
DNS   SMS Pager    
Intranet  AV(clamWin Free AV)
Accounting
MAILs (Pulled from ISP thru pop3 connector)
CRM
WSUS
AV (clamWin Free AV + AVG)

 
!~` Yesterday is a History` ~!
!~` Tomorrow is a Mystery` ~!
!~` Today is a Gift` ~!
!~` So we call it ...............` ~!
!~` Present .......Simple` ~!
Mob : +966 50 2953591
 

From: Gene Sibbs <gen_sib@xxxxxxxxx>
Reply-To: isalist@xxxxxxxxxxxxx
To: isalist@xxxxxxxxxxxxx
Subject: [isalist] SME LAN and ISA
Date: Sun, 21 May 2006 02:25:59 -0700 (PDT)

Greetings,
 
I have attached a basic LAN setup diagram and I would like to pick your brains as far as the security is concerned.
 
My objective is that the In/Outbound traffic must pass thru ISA box
 
Base on the attached design I feel that the security is lacking. I have downloaded ISA 2006 BETA version...and I want to introduce ISA Server as a member of the family to beef-up security.
 
How can I make ISA Server 2006 beta play with this basic design, bearing in mind that I don't have a static IP address from my ISP. My ADSL is dhcp obtaining the IP address from ISP.
 
I want to run ISA2006 on a separate box completely.
 
With many thanks!
 
Gene Sibbs
 

New Yahoo! Messenger with Voice. Call regular phones from your PC and save big.

Feel free to call! Free PC-to-PC calls. Low rates on PC-to-Phone. Get Yahoo! Messenger with Voice
>BASIC SME NETWork SETUP
>
>Internet Cloud
> |
> |
> |
> |
>ADSL (AZTECH ETHERNET USB) Broadband Router
> DHCP
> |
> |
> |
>________|______________________
>LoCAL AREA NETWORK (Unmanaged Switch)
>LAN IP Address 10.11.1.0/24
>
>______________________________
>
>SBS2003-BOX (HP DL3*) LINUX-Box (HP DL3*)
>
>AD OpenSource Helpdesk System
>DHCP OpenSource Network Monitoring(nagios, nmis)
>DNS SMS Pager
>Intranet AV(clamWin Free AV)
>Accounting
>MAILs (Pulled from ISP thru pop3 connector)
>CRM
>WSUS
>AV (clamWin Free AV + AVG)
>______________________________
>
>Security is an issue here...
>
------------------------------------------------------ List Archives: //www.freelists.org/archives/isalist/ ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server Articles and Tutorials: http://www.isaserver.org/articles_tutorials/ ISA Server Blogs: http://blogs.isaserver.org/ ------------------------------------------------------ Visit TechGenix.com for more information about our other sites: http://www.techgenix.com ------------------------------------------------------ To unsubscribe visit http://www.isaserver.org/pages/isalist.asp Report abuse to listadmin@xxxxxxxxxxxxx


Yahoo! Messenger with Voice. PC-to-Phone calls for ridiculously low rates.


Yahoo! Messenger with Voice. PC-to-Phone calls for ridiculously low rates.
Name Scope Description Action Applies To Schedule Destination Content
Syamntec Update Array Redirect to: http://www.cba.edu.sa/deny.asp Client Sets: ASP-SMS,Dahban ELAB,Dahban Employees,Dahban LAB,Dahban Wireless,DBLAB-002-04,Donn,Donn_laptop Except: laptop Work hours Symatec Live Update All
passport Array Deny Accounts: CBA\Domain Users Except: CBA\arazek,CBA\hossam,CBA\iris,CBA\mtawfiq,CBA\shady Always passport.net All
Library Array Redirect to: http://www.cba.edu.sa/deny.asp Accounts: CBA\library Always All except library All
http download After Business Hours Array Allow Accounts: CBA\Domain Users Except: CBA\donn,CBA\ghada,CBA\heba,CBA\malik,CBA\masood,CBA\msaleh,CBA\mtawfiq,CBA\reem after business hours All destinations http Download for faculties
http download Array Redirect to: http://www.cba.edu.sa/deny.asp Accounts: CBA\Domain Users,CBA\library Except: CBA\donn,CBA\ghada,CBA\halah,CBA\heba,CBA\kaleem,CBA\magid,CBA\malik,CBA\masood,CBA\msaleh,CBA\mtawfiq,... Work hours All destinations HTTP Download,http Download for faculties
Hotmail Array Redirect to: http://www.cba.edu.sa/Deny Temp.asp Accounts: CBA\Domain Users Except: CBA\msaleh Always Hotmail All
Gmail Array Redirect to: http://www.cba.edu.sa/Deny Temp.asp Accounts: CBA\Domain Users Except: CBA\mtawfiq Always gmail All
Deny Vedio Array Redirect to: http://www.cba.edu.sa/deny.asp Accounts: CBA\Domain Users Except: CBA\donn,CBA\mtawfiq,CBA\Sari Faculty Staff Work hours All external destinations Video
Deny Sus or Users Array Redirect to: http://www.cba.edu.sa/deny.asp Accounts: CBA\Domain Users Except: CBA\mtawfiq Always Windows Update All
Deny Rule Array Deny Spreaded Viruses and Video Redirect to: http://www.cba.edu.sa/deny.asp Any request Always All destinations Commonly Used to spread viruses
deny for dblab-002-04 Array Deny Client Sets: DBLAB-002-04 Always All external destinations All
Deny e-Messneger Array Deny Accounts: CBA\Domain Users Except: CBA\arazek,CBA\donn,CBA\hakami,CBA\hossam,CBA\malaise,CBA\malik,CBA\msaleh,CBA\mtawfiq,CBA\shady Work hours Restricted All
Deny Audio Array Redirect to: http://www.cba.edu.sa/deny.asp Accounts: CBA\Domain Users Except: CBA\Administrator,CBA\maqsood,CBA\msaleh,CBA\mtawfiq,CBA\shady Work hours All destinations Audio
Audio Download after Business Hours Array Allow Accounts: CBA\ahajar,CBA\Domain Users,CBA\hassan,CBA\magid after business hours All destinations All
Allow Rule Array Allow Accounts: CBA\Domain Users Always All destinations All
Allow MSN after busniss hour Array Allow Accounts: CBA\Domain Users after business hours Restricted All
Allow for sus Array Deny Client Sets: ASP-SMS,CBA DCs,Dahban ELAB,Dahban Employees,Dahban LAB,Dahban Servers,Dahban Wireless,DMZ,GWCLS,GWSRV1+2,... Except: Donn,Donn_laptop,laptop,MAT,SUS Server Work hours Windows Update All


Name Description Clients
CBA DCs "10.1.40.10 - 10.1.40.11, 10.2.32.10, 10.4.40.10 - 10.4.40.11"
Dahban ELAB 10.4.24.31 - 10.4.24.254
Dahban Employees 10.4.8.31 - 10.4.8.254
Dahban LAB 10.4.16.31 - 10.4.16.254
Dahban Servers 10.4.40.1 - 10.4.40.254
Dahban Wireless 10.4.32.31 - 10.4.32.254
DMZ 172.31.13.1 - 172.31.13.254
GWCLS 192.168.113.10
GWSRV1+2 192.168.13.11 - 192.168.13.12
JB Employees 10.2.8.21 - 10.2.8.254
JB Lab 10.2.16.21 - 10.2.16.254
JB Severs 10.2.32.1 - 10.2.32.254
JB Wireless 10.2.24.21 - 10.2.24.254
Mukhmal 10.3.8.21 - 10.3.8.254
Mukhmal Server 10.3.32.10
Sary Employees 10.1.8.21 - 10.1.8.254
Sary LAB 10.1.16.21 - 10.1.16.254
Sary Network Managment Workstations "10.1.8.37,10.1.8.40"
Server Farme 10.1.40.1 - 10.4.40.254
SMTP Relay "172.31.13.101, 172.31.13.20 - 172.31.13.21"
Storage 10.1.48.10
VPN Admins "10.1.64.10, 10.1.66.1 - 10.1.66.254"
VPN Clients 10.1.254.1 - 10.1.254.254


Name Description Destinations
Restricted 65.54.239.1 - 65.54.239.254,68.142.231.1 - 68.142.231.254,87.248.104.1 - 87.248.104.254,207.46.245.220,65.54.213.30,64.4.23.29,webmessenger.msn.com,65.54.183.226,62.116.83.62,62.115.121.242,...


Name Scope Description Protocol Action Applies To Schedule
ALL Traffic Array "All IP traffic except: SMTP,SMTP Server" Allow "Accounts: CBA\mazen,CBA\shady" Always
ASP-SMS Array ASP-SMS Allow "Accounts: CBA\ahajar,CBA\Ali,CBA\ashary,CBA\hakami,CBA\kaleem,CBA\khaled,CBA\mazenmero" Always
FTP Only Array "FTP,FTP Download only" Allow Accounts: CBA\Domain Users Always
HTTP & HTTPS only Array "HTTP,HTTPS" Allow Accounts: CBA\Domain Users Always


Name Description Destinations
Restricted "65.54.239.1 - 65.54.239.254, 68.142.231.1 - 68.142.231.254, 87.248.104.1 - 87.248.104.254, 207.46.245.220, 65.54.213.30, 64.4.23.29, webmessenger.msn.com, 65.54.183.226, 62.116.83.62, 62.115.121.242,..."



Name Description Clients
CBA DCs "10.1.40.10 - 10.1.40.11, 10.2.32.10, 10.4.40.10 - 10.4.40.11"
Dahban ELAB 10.4.24.31 - 10.4.24.254
Dahban Employees 10.4.8.31 - 10.4.8.254
Dahban LAB 10.4.16.31 - 10.4.16.254
Dahban Servers 10.4.40.1 - 10.4.40.254
Dahban Wireless 10.4.32.31 - 10.4.32.254
DMZ 172.31.13.1 - 172.31.13.254
GWCLS 192.168.113.10
GWSRV1+2 192.168.13.11 - 192.168.13.12
JB Employees 10.2.8.21 - 10.2.8.254
JB Lab 10.2.16.21 - 10.2.16.254
JB Severs 10.2.32.1 - 10.2.32.254
JB Wireless 10.2.24.21 - 10.2.24.254
Mukhmal 10.3.8.21 - 10.3.8.254
Mukhmal Server 10.3.32.10
Sary Employees 10.1.8.21 - 10.1.8.254
Sary LAB 10.1.16.21 - 10.1.16.254
Sary Network Managment Workstations "10.1.8.37,10.1.8.40"
Server Farme 10.1.40.1 - 10.4.40.254
SMTP Relay "172.31.13.101, 172.31.13.20 - 172.31.13.21"
Storage 10.1.48.10
VPN Admins "10.1.64.10, 10.1.66.1 - 10.1.66.254"
VPN Clients 10.1.254.1 - 10.1.254.254



Name Description Content Types
Application Applications "application/hta,application/x-internet-signup,application/x-pkcs7-certificates,application/x-sv4crc,application/octet-stream,application/x-pkcs7-certreqresp,application/pkcs7-signature,application/x-cpio,application/set-registration-initiation,application/x-dvi,..."
Application Data Files Files containing data for applications "application/x-mscardfile,application/x-perfmon,application/x-msclip,application/x-msmoney,application/winhlp,application/x-mswrite,application/x-msterminal,application/x-msmetafile,.crd,.clp,..."
Audio Audio files "audio/*,.ra,.ram,.rmi,.au,.snd,.aif,.aifc,.wav,.m3u,..."
commonly used to spread viruses ".bat,.pif ,.scr ,.vbs"
Compressed Files Compressed Files "application/x-gzip,application/x-tar,application/x-gtar,application/x-compress,application/x-compressed,application/x-zip-compressd,.gtar,.gz,.tar,.tgz,..."
Documents Documents "text/tab-separated-values,text/xml,text/h323,application/postscript,application/pdf,.ai,.323,.eps,.pdf,.ps,..."
HTML Documents HTML Documents "text/webviewhtml,text/html,.htm,.html,.htt,.stm,.xsl"
Images All known types of images ".cod,.cmx,.ief,.pbm,.pnm,.ppm,.gif,.bmp,.jfif,.jpe,..."
Macro Documents Documents that may contain macros "application/msword,application/vnd.ms-excel,application/x-msaccess,application/vnd.ms-project,application/vnd.ms-powerpoint,application/vnd.ms-works,application/rtf,.doc,.dot,.mpp,..."
Text Text content ".txt,.h,.c,.htc,.vcf,.etx,.uls,.css,.bas,.rtx,..."
Video Video files "video/*,.asf,.asr,.asx,.avi,.ivf,.lsf,.lsx,.mov,.movie,..."
VRML VRML "x-world/x-vrml,.flr,.wrl,.wrz,.xaf,.xof"


Other related posts: