RE: Thanks alot ISA now working BUT Exchange behind ISA

  • From: Phill Hardstaff <phillh@xxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Wed, 7 Jan 2004 08:22:04 +1100

Glenn, don't you mean "you should know that ISA uses the Primary IP address
assignment when used in conjunction with Protocol Rules"  where you said
"you should know that ISA uses the Primary IP address assignment when used
in conjunction with Publishing rules" ?
 
Cheers
 
Phill

   _____  

From: Glenn Maks [mailto:gmaks@xxxxxxxxx] 
Sent: Wednesday, 7 January 2004 6:12 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Thanks alot ISA now working BUT Exchange behind ISA


http://www.ISAserver.org


Rolland - you should know that ISA uses the Primary IP address assignment
when used in conjunction with Publishing rules, if you have multiple IP
addresses on your External interface and published your MX server using some
secondary IP assignment then YES, you will send, but not receive, make sure
in your Publishing rules that you are using your Primary IP address on your
External NIC.

 Glenn 




-----Original Message----- 
From: Rolland Basi [HYPERLINK
"mailto:basi948@xxxxxxxxxxx"mailto:basi948@xxxxxxxxxxx] 
Sent: Tuesday, January 06, 2004 2:38 AM 
To: [ISAserver.org Discussion List] 
Subject: [isalist] Thanks alot ISA now working BUT Exchange behind ISA 


HYPERLINK "http://www.ISAserver.org"; \nhttp://www.ISAserver.org 

Jim & Kevin, 

Thanks alot for your assistance. 

I am now able to ping from SNAT Clients after excluding my external NICs 
from the LAT. 
As per my configuration I excluded my Router & ISAs Ext NIC from the LAT and

then configured my ICMP Outbound Packet Filter. 

Here's a small problem I still encounter. I can send email from my Exchange 
2000 Server which is behind the ISA.  BUT I can't receive from outside. 

I also enabled SMTP Packet Filter. Is there something I missed out to enable

receiving emails from outside. 

Thanks in advance 
Rolland 


>From: "Jim Harrison" <jim@xxxxxxxxxxxx> 
>Reply-To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx> 
>To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx> 
>Subject: [isalist] Re: ISA is still not working 
>Date: Fri, 2 Jan 2004 15:43:21 -0800 
> 
>HYPERLINK "http://www.ISAserver.org"; \nhttp://www.ISAserver.org 
> 
>Your ISA has the same subnet internally as externally: 
>ISA Ext. NIC:   199.245.180.29 
>     Sub. Mask:  255.255.255.0 
> 
>ISA Int. NIC:  199.245.180.28 
>     Sub.Mask:  255.255.255.0 
> 
>This is non-functional. 
>Either use non-routable IPs internally or use an entirely separate subnet. 
> 
>  Jim Harrison 
>  MCP(NT4, W2K), A+, Network+, PCG 
>  HYPERLINK "http://www.microsoft.com/isaserver";
\nhttp://www.microsoft.com/isaserver 
>  HYPERLINK "http://isaserver.org/Jim_Harrison";
\nhttp://isaserver.org/Jim_Harrison 
>  HYPERLINK "http://isatools.org"; \nhttp://isatools.org 
> 
>  Read the help, books and articles! 
>----- Original Message ----- 
>From: "Rolland Basi" <basi948@xxxxxxxxxxx> 
>To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx> 
>Sent: Friday, January 02, 2004 15:19 
>Subject: [isalist] ISA is still not working 
> 
> 
>HYPERLINK "http://www.ISAserver.org"; \nhttp://www.ISAserver.org 
> 
>Hello ISA Profs; 
> 
>Happy New year to you all. 
> 
>I am still having problem with my ISA Server. ie with pinging from 
>SecureNAT 
>clients. 
> 
>Here are my configurations: 
> 
>ISP IP Address: 202.1.59.8 
>mask:              255.255.255.248 
>Gateway:        202.1.59.10 
> 
>Router Ip Add: 199.245.180.18 
> 
>ISA Ext. NIC:   199.245.180.29 
>     Sub. Mask:  255.255.255.0 
>     DGateway: 199.245.180.18 
> 
>ISA Int. NIC:  199.245.180.28 
>     Sub.Mask:  255.255.255.0 
>     DGateway: none 
> 
>SecureNAT Clients with Static IP Addresses: 
>eg.  IP Add:    199.245.180.19 
>        Mask:       255.255.255.0 
>        Gateway: 199.245.180.28 
> 
>       DNS: 199.245.180.28 
> 
>The ISA Server's Ext NIC is plugged into the Router's Ethernet port. The 
>Router is then connected to the ISA via a Leased Line. 
> 
>Can someone figure out where my problem is. I mean what's blocking my SNAT 
>clients from pinging the ISP Server. I've enable IP filtering and ICMP 
>outbound but still doesn't work. 
>As I mentioned in my previous emails, Web browsing is fine. 
> 
>Please, this has taken me almost a month to get this working, I really need

>your help. 
> 
>Thanks alot. 
>Rolland 
> 
>_________________________________________________________________ 
>The new MSN 8: smart spam protection and 2 months FREE* 
>HYPERLINK "http://join.msn.com/?page=features/junkmail";
\nhttp://join.msn.com/?page=features/junkmail 
> 
> 
>------------------------------------------------------ 
>List Archives: HYPERLINK
"http://www.webelists.com/cgi/lyris.pl?enter=isalist";
\nhttp://www.webelists.com/cgi/lyris.pl?enter=isalist 
>ISA Server Newsletter: HYPERLINK
"http://www.isaserver.org/pages/newsletter.asp";
\nhttp://www.isaserver.org/pages/newsletter.asp 
>ISA Server FAQ: HYPERLINK
"http://www.isaserver.org/pages/larticle.asp?type=FAQ";
\nhttp://www.isaserver.org/pages/larticle.asp?type=FAQ 
>------------------------------------------------------ 
>Other Internet Software Marketing Sites: 
>Leading Network Software Directory: HYPERLINK "http://www.serverfiles.com";
\nhttp://www.serverfiles.com 
>No.1 Exchange Server Resource Site: HYPERLINK "http://www.msexchange.org";
\nhttp://www.msexchange.org 
>Windows Security Resource Site: HYPERLINK "http://www.windowsecurity.com/";
\nhttp://www.windowsecurity.com/ 
>Network Security Library: HYPERLINK "http://www.secinf.net/";
\nhttp://www.secinf.net/ 
>Windows 2000/NT Fax Solutions: HYPERLINK "http://www.ntfaxfaq.com";
\nhttp://www.ntfaxfaq.com 
>------------------------------------------------------ 
>You are currently subscribed to this ISAserver.org Discussion List as: 
>jim@xxxxxxxxxxxx 
>To unsubscribe send a blank email to $subst('Email.Unsub') 
> 
> 
>------------------------------------------------------ 
>List Archives: HYPERLINK
"http://www.webelists.com/cgi/lyris.pl?enter=isalist";
\nhttp://www.webelists.com/cgi/lyris.pl?enter=isalist 
>ISA Server Newsletter: HYPERLINK
"http://www.isaserver.org/pages/newsletter.asp";
\nhttp://www.isaserver.org/pages/newsletter.asp 
>ISA Server FAQ: HYPERLINK
"http://www.isaserver.org/pages/larticle.asp?type=FAQ";
\nhttp://www.isaserver.org/pages/larticle.asp?type=FAQ 
>------------------------------------------------------ 
>Other Internet Software Marketing Sites: 
>Leading Network Software Directory: HYPERLINK "http://www.serverfiles.com";
\nhttp://www.serverfiles.com 
>No.1 Exchange Server Resource Site: HYPERLINK "http://www.msexchange.org";
\nhttp://www.msexchange.org 
>Windows Security Resource Site: HYPERLINK "http://www.windowsecurity.com/";
\nhttp://www.windowsecurity.com/ 
>Network Security Library: HYPERLINK "http://www.secinf.net/";
\nhttp://www.secinf.net/ 
>Windows 2000/NT Fax Solutions: HYPERLINK "http://www.ntfaxfaq.com";
\nhttp://www.ntfaxfaq.com 
>------------------------------------------------------ 
>You are currently subscribed to this ISAserver.org Discussion List as: 
>basi948@xxxxxxxxxxx 
>To unsubscribe send a blank email to $subst('Email.Unsub') 

_________________________________________________________________ 
Help STOP SPAM with the new MSN 8 and get 2 months FREE*  
HYPERLINK "http://join.msn.com/?page=features/junkmail";
\nhttp://join.msn.com/?page=features/junkmail 


------------------------------------------------------ 
List Archives: HYPERLINK
"http://www.webelists.com/cgi/lyris.pl?enter=isalist";
\nhttp://www.webelists.com/cgi/lyris.pl?enter=isalist 
ISA Server Newsletter: HYPERLINK
"http://www.isaserver.org/pages/newsletter.asp";
\nhttp://www.isaserver.org/pages/newsletter.asp 
ISA Server FAQ: HYPERLINK
"http://www.isaserver.org/pages/larticle.asp?type=FAQ";
\nhttp://www.isaserver.org/pages/larticle.asp?type=FAQ 
------------------------------------------------------ 
Other Internet Software Marketing Sites: 
Leading Network Software Directory: HYPERLINK "http://www.serverfiles.com";
\nhttp://www.serverfiles.com 
No.1 Exchange Server Resource Site: HYPERLINK "http://www.msexchange.org";
\nhttp://www.msexchange.org 
Windows Security Resource Site: HYPERLINK "http://www.windowsecurity.com/";
\nhttp://www.windowsecurity.com/ 
Network Security Library: HYPERLINK "http://www.secinf.net/";
\nhttp://www.secinf.net/ 
Windows 2000/NT Fax Solutions: HYPERLINK "http://www.ntfaxfaq.com";
\nhttp://www.ntfaxfaq.com 
------------------------------------------------------ 
You are currently subscribed to this ISAserver.org Discussion List as:
gmaks@xxxxxxxxx 
To unsubscribe send a blank email to $subst('Email.Unsub') 

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
phillh@xxxxxxx
To unsubscribe send a blank email to $subst('Email.Unsub') 


---
Incoming mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.556 / Virus Database: 348 - Release Date: 26/12/2003



---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.556 / Virus Database: 348 - Release Date: 26/12/2003
 

Other related posts: