RE: Use two NICs? Convince me.

  • From: "Ball, Dan" <DBall@xxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Mon, 29 Aug 2005 14:25:46 -0400

In that configuration, you can drop "firewall" from the title, all you've got 
is a caching server.  Almost all of the really neat and useful features of ISA 
are disabled in that mode.

 

It's like buying the biggest, baddest, sports car you could find, then putting 
it up on blocks outside your window so you could listen to its sound system.

 

 

________________________________

From: Alexandre Gauthier [mailto:gauthiera@xxxxxxxxxxxxxxxxx] 
Sent: Monday, August 29, 2005 1:56 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] Use two NICs? Convince me.

 

http://www.ISAserver.org

Greetings,

 

Would anyone be so kind as to attempt to convince me that I *need* two network 
cards in my ISA 2004 firewall over here?

 

(now please note that I did not design this network.)

 

The configuration is made like this. The servers and the local LAN share one 
subnet (192.168.10.0/24) and are all behind a netscreen firewall. Somewhere 
among the servers is a single nic ISA 2004 server with a gateway (the 
netscreen). The client workstations use the Firewall client to connect to the 
internet, for they have no gateway, and even if they did, the netscreen is 
configure to only NAT out specific IPs.

 

So far, it works. With a few hitches, but it works. We can add filtering rules 
for the client workstations, and restrict what we want.

 

Why should I add another card and redesign part of the network that is already 
working?

 

(I honestly did not do such a thing. I'd redesign it, but my client is not 
necessarily happy about this, and I need arguments.)

 

--

Alexandre Gauthier

Analyste Réseau/Network Analyst

Québec Loisirs

 

 

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Visit TechGenix.com for more information about our other sites:
http://www.techgenix.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as: 
dball@xxxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist
Report abuse to listadmin@xxxxxxxxxxxxx 

Other related posts: