• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Discussion of Name Resolution for SecureNAT clients article

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 Firewall] >> SecureNAT Client >> Discussion of Name Resolution for SecureNAT clients article Page: [1]
Login
Message << Older Topic   Newer Topic >>
Discussion of Name Resolution for SecureNAT clients art... - 5.Aug.2003 6:13:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
This thread is for discussion of the Supporting Internet Host Name Resolution for ISA Server SecureNAT Clients article at http://isaserver.org/articles/snatdns.html.

Thanks!
Tom

[ August 06, 2003, 08:26 AM: Message edited by: tshinder ]
Post #: 1
RE: Discussion of Name Resolution for SecureNAT clients... - 7.Aug.2003 6:01:00 PM   
BaanMan

 

Posts: 20
Joined: 15.Apr.2002
From: Germany
Status: offline
Hello Tom,

I've made a posting in Forum: ISA Server General - Installation - Caching DNS on ISA - today.

I can't get this Packetfilter DNS(TCP) running

The Caching DNS running fine with UDP Port:53
So I can use only my ISA and my Mail/Web/Time/Virus-Server to go Outside.
The Servers with DNS have nomore need to go Outside because I use the DNS on ISA as Forwarder.

That's fine for securety.

Greetings BaanMan

(in reply to tshinder)
Post #: 2
RE: Discussion of Name Resolution for SecureNAT clients... - 8.Aug.2003 3:52:00 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi BaanMan,

Great! The caching only DNS server is the best option from a security point of view.

Thanks!
Tom

(in reply to tshinder)
Post #: 3
RE: Discussion of Name Resolution for SecureNAT clients... - 12.Aug.2003 11:59:00 PM   
skipster

 

Posts: 550
Joined: 12.Oct.2001
From: newport beach
Status: offline
Quick question.

If i use DHCP on the internal network to hand out the ip address of my internal DNS server, and i have configured a DNS caching server on ISA, then which DNS server do i point my clietns to in order to resolve internal names and FQDN on the internet? The clients cant use the DNS server on ISA for name resolution on the internal network, wouldnt thsi be a problem?

I have always just configured my internal AD DNS server to use my ISP as a forwarder, and i never ran into a problem with name resolution on the internal network, or resolving names on the internet.

I guess I'm a bit confused.

Thanks

Skip

Skip

(in reply to tshinder)
Post #: 4
RE: Discussion of Name Resolution for SecureNAT clients... - 13.Aug.2003 9:57:00 AM   
BaanMan

 

Posts: 20
Joined: 15.Apr.2002
From: Germany
Status: offline
Hey skipster,

for your clients use your internal DNS-Servers - roll out with DHCP - !
Use only the Caching DNS on ISA as forwarder in the settings of your internal DNS-Servers.
In the Caching DNS on ISA use your ISP-DNS as forwarder.
So the Caching DNS on ISA is the only DNS-Server seeing the Outside !

Greetings BaanMan

(in reply to tshinder)
Post #: 5
RE: Discussion of Name Resolution for SecureNAT clients... - 13.Aug.2003 5:08:00 PM   
skipster

 

Posts: 550
Joined: 12.Oct.2001
From: newport beach
Status: offline
Gotcha! Thanks Bro for clearing that up for me.

When i was reading this particular article, I just got done tring to install a Lotus Notes server, this is why I think i got so confused reading Toms article. [Smile]

(in reply to tshinder)
Post #: 6
RE: Discussion of Name Resolution for SecureNAT clients... - 18.Aug.2003 5:39:00 AM   
lilhalf9

 

Posts: 1
Joined: 18.Aug.2003
Status: offline
i'm having the same problem with my 2003srv and isa timeing out after it's idle for several hours. the only way i've been able to fix it is reboot the isa box and all is well. Is there a way to avoid this or work around it? i also don't understand why it times out after being idle. all clients are secureNat clients and isa box is forwarder to isp for dns cacheing. please help

lilhalf

(in reply to tshinder)
Post #: 7
RE: Discussion of Name Resolution for SecureNAT clients... - 30.Oct.2003 10:47:00 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Tom,

did you already checked out Support WebCast: Microsoft Windows Server 2003 DNS: Stub Zones and Conditional Forwarding ? A nice addition to your article about a caching only DNS server.

HTH,
Stefaan

(in reply to tshinder)
Post #: 8
RE: Discussion of Name Resolution for SecureNAT clients... - 4.May2004 9:18:00 PM   
ftoddt

 

Posts: 9
Joined: 31.Mar.2004
Status: offline
The Installation Write Up looks great but I am pretty new at this and I am unsure of what is meant in #2. "click on an address not bound to the internal interface of the ISA Server Firewall"
I don't know what bound means in this. My Isa server has 1 internal IP on the LAN and 3 routable IP's on the WAN of which two are used for listeners for a web server and exchange server behind the ISA server. What IP do I select in this write up? Please help!

(in reply to tshinder)
Post #: 9
RE: Discussion of Name Resolution for SecureNAT clients... - 25.Jun.2004 7:16:00 PM   
Guest
Great article! Can you tell me how can I obtain the same result with isa server 2004?
I don't know how to replicate ip packet filters in 2004...

Thanks a lot.

Ricky

(in reply to tshinder)
  Post #: 10
RE: Discussion of Name Resolution for SecureNAT clients... - 9.Jul.2004 12:43:00 PM   
robh

 

Posts: 44
Joined: 4.Oct.2002
From: UK
Status: offline
Hi I posted in the wrong place before I found this thread can anybody help me with my problem see this thread

http://forums.isaserver.org/ultimatebb.cgi?ubb=get_topic;f=8;t=000674

(in reply to tshinder)
Post #: 11
RE: Discussion of Name Resolution for SecureNAT clients... - 25.Sep.2006 5:53:39 PM   
heathbain

 

Posts: 1
Joined: 25.Sep.2006
Status: offline
Hello:

Tried this on ISA 2004, but am having problems finding the right place in the interface to set the DNS zone xfer packet filter (port53)

Can you point me in the right direction?

I fear that this forum might be dead now that ISA 2006 is popping up.

Please advise.

(in reply to robh)
Post #: 12
RE: Discussion of Name Resolution for SecureNAT clients... - 30.Jul.2007 7:03:27 AM   
mehdi_alipour

 

Posts: 3
Joined: 22.Jun.2007
Status: offline
hi everyone
Our Platform
clients were connected to the internet using a router without Valid IP.
I installed ISA server 2004 and now everybody in connected to the internet with webproxy though ISA server also without valid IP.
Clients-ISA-Router-ISP-Internet
I configured DNS for SecurNAT clients du to the tom's instruction .
Both DNS and ISA are in the same Machine.
DNS forwarder IP = Router Internal IP.
Clients TCP/IP configuration :
Dynamic IP From DHCP
Default Gateway : ISA Internal IP
Primary DNS          : ISA Internal IP
aslo add DNS server publishing rule in firewal policy.
But I'm not able to access internet from clients with this configuration .

(in reply to heathbain)
Post #: 13
RE: Discussion of Name Resolution for SecureNAT clients... - 30.Jul.2007 12:43:25 PM   
elmajdal

 

Posts: 6022
Joined: 16.Sep.2004
From: Lebanese in Kuwait
Status: offline
quote:

DNS forwarder IP = Router Internal IP.


The Internal DNS Server should forward requests to your ISP DNS Servers, remove the Router IP and put your ISP DNS Servers

_____________________________

Tarek Majdalani

Windows Expert - IT Pro MVP
Facebook : https://www.facebook.com/ElMajdal.Net

(in reply to mehdi_alipour)
Post #: 14

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 Firewall] >> SecureNAT Client >> Discussion of Name Resolution for SecureNAT clients article Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts