Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

2 Internet lines on one ISA?

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> Network Infrastructure >> 2 Internet lines on one ISA? Page: [1]
Login
Message << Older Topic   Newer Topic >>
2 Internet lines on one ISA? - 21.Sep.2006 9:28:13 PM   
rbandion

 

Posts: 13
Joined: 21.Sep.2006
From: Austria
Status: offline
Hi all,

following Problem:

One of my customers wants to split traffic over 2 internet lines. One should be used for traffic coming from the internal network (surfing...), the other one should be used exclusively for the company's extranet webserver.

You ask why?

Well, it's a problem of the availability of bandwidth. The ISP can offer only lines with 4098down/512up or 2048/2048.

Internal users are used to the 4098k downstream, but external users suffer of the slow uplink.

Now the question: Is it possible to realize this with only ONE ISA Server?

The only idea that I had was to use 2 default gateways on the ISA machine. But I'm pretty sure that ISA will not send back the answer via the interface where the request came from. Does anybody have a clue on how Windows/ISA behaves in a config with 2 default gateways?

I'm looking forward to your responses!

Many thanks in advance,

Richard
Post #: 1
RE: 2 Internet lines on one ISA? - 22.Sep.2006 4:23:40 PM   
spouseele

 

Posts: 12782
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Richard,

not possible! Neither ISA 2004 nor ISA 2006 supports more than one default gateway. In other words, you have to solve that problem external to ISA server.

HTH,
Stefaan

(in reply to rbandion)
Post #: 2
RE: 2 Internet lines on one ISA? - 22.Sep.2006 4:30:47 PM   
rbandion

 

Posts: 13
Joined: 21.Sep.2006
From: Austria
Status: offline
Thanks Stefaan,

I tought that I will get this answer...

Do you have any idea what I need to buy/do/change that my scenario could work? I asked my ISP and the only thing they could offer are boxes that bundle identical lines to appear as one. Seems to be sime kind of load balancing, but I don't get more bandwidth per session.

Richard

(in reply to spouseele)
Post #: 3
RE: 2 Internet lines on one ISA? - 22.Sep.2006 4:51:37 PM   
spouseele

 

Posts: 12782
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Richard,

I've heard that some 'cheap' Cisco routers and SonicWall firewalls can handle multiple default gateways. Of course, using two ISA servers, one for outbound access and one for inbound access (publishing and VPN), can solve that problem too.

HTH,
Stefaan

(in reply to rbandion)
Post #: 4
RE: 2 Internet lines on one ISA? - 22.Sep.2006 5:16:59 PM   
rbandion

 

Posts: 13
Joined: 21.Sep.2006
From: Austria
Status: offline
But wouldn't this mean that I will have to waive some comfortable ISA features like server publishing and do this on the new device?

Because: If I route the traffic forward to ISA server the device would have to decide which futher gateway to use based on the source address of the ISA server reply... What leads to the next problem: How to tell ISA which source IP to use with only one default gateway on ISA...

What do the Cisco specialists out there think about the problem?

Richard




(in reply to spouseele)
Post #: 5
RE: 2 Internet lines on one ISA? - 22.Sep.2006 6:35:05 PM   
spouseele

 

Posts: 12782
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Richard,

quote:

But wouldn't this mean that I will have to waive some comfortable ISA features like server publishing and do this on the new device?

No, ISA would just see one default gateway. It's up to the upstream device to decide how to distribute that traffic further.

HTH,
Stefaan

(in reply to rbandion)
Post #: 6
RE: 2 Internet lines on one ISA? - 22.Sep.2006 6:40:35 PM   
rbandion

 

Posts: 13
Joined: 21.Sep.2006
From: Austria
Status: offline
But how does the upstream device know where the initial request came from?

The problem is that it should use a specific line depending on the line where the request came in. (Answers on incoming web requests over the line with the high uplink, outgoing web requests over the other one)

Richard

(in reply to spouseele)
Post #: 7
RE: 2 Internet lines on one ISA? - 22.Sep.2006 7:42:19 PM   
spouseele

 

Posts: 12782
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Richard,

I didn't study the SonicWall or Cisco solutions yet! So I can't comment on them.

However I do know how Rainfinity did solve that problem and the key was a special DNS server agent. Unfortunately, Rainfinity was buyed up by EMC and than the ISA add-on productline was dropped.

HTH,
Stefaan

(in reply to rbandion)
Post #: 8

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> Network Infrastructure >> 2 Internet lines on one ISA? Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts