Re: NAT question



On Wed, 2006-09-06 at 13:15 -0700, K.J. 44 wrote:
I am running a router connected to a firewall connected to a single
server running Windows Server 2003, Exchange, and ISA. I want to use
ISA as another layer of defense so the server is multihomed. the Lan
is connected to one NIC and the other NIC is connected to the firewall.

wan___router___firewall___isa___lan

Really bad to depend on windows for network connectivity. Suppose you'll
be learning that lesson the hard way.

My question is this. No matter what traffic is sent, whether it is
from the server or a PC on the other side of the server, it will have a
source address of the NIC connected to the firewall right? because ISA
is a proxy, it makes all requests on behalf of the clients?

If I recall, ISA has proxy support for http/https and limited support
for ftp. Be aware that proxy implementation will likely break certain
features of both protocols. Other traffic will probably traverse isa as
routed.

having a static NAT translation to pass information to Exchange doesn't
make sense because all traffic will have the same source IP when it
gets to the firewall.

Like I say, probably not. Put a packet sniffer on it and find out for
yourself. You still need to get public traffic to the exchange server
somehow. Nat it or route it... doesn't matter. They both work.

.



Relevant Pages

  • [fw-wiz] Exchange 2003 OWA compromise reached
    ... Thanks to all for your answers to my questions regarding Exchange 2003 OWA. ... Since we also want to move our ftp server onto a separate DMZ away from our ... we will attach the Microsoft ISA server outside interface to the ...
    (Firewall-Wizards)
  • RE: Front End/Back End communication
    ... MVP -- ISA Firewalls ... There is no such thing as security perfection. ... single front-end/back-end Exchange Server will find this setup to be ...
    (Focus-Microsoft)
  • Re: ISA 2004 and Exchange 2003 Error
    ... > I may make my Exchange server the only active directory computer and then ... > have the ISA server only for ISA. ... The System Policy exists on all ISA2004 machine, ...
    (microsoft.public.isa)
  • Re: AAAAAHHHH! ISA is making me crazy
    ... I recreated owa publishing rule. ... ISA shows ... This started when I changed the exchange default GW to the IP of the ... This ISA server will be used to publish OWA (currently the only thing ...
    (microsoft.public.isa)
  • RE: Relaying
    ... Disabled SMTP filter and things seem to be working. ... Is this the correct configuration with ISA and Exchange ... information is not sent to the Exchange server. ...
    (microsoft.public.isa)