Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

How-to route all tunneled traffic via internal network interface

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Firewall] >> Network Infrastructure >> How-to route all tunneled traffic via internal network interface Page: [1]
Login
Message << Older Topic   Newer Topic >>
How-to route all tunneled traffic via internal network ... - 20.May2008 10:58:47 AM   
dani.wenger

 

Posts: 3
Joined: 20.May2008
Status: offline
Hi everbody,

great forum, excellent moderated , congratulations! Keep it up!

As many others I have a problem which I could not solve so far:

I am using ISA Server 2006 with two network interfaces (one public, one private) for terminating remote access VPN connections from remote workers. All the traffic of the remote users is forwarded through the VPN tunnels ("use default gateway on remote network"). So far everything works fine.
However, I would like to route all tunneled traffic (not only web traffic) via the internal network for further inspection. At the moment traffic destined to the internet is routed in the ISA-Server through the public interface because the default route must be configured this way for remote access.

Such behaviour normally requires "policy based routing" or "source based routing".

Does ISA support such features?

I've read already some threads and realised that ISA is "perfect" firewall but not a core router (follwing some statements from Tom ). I read as well that new versions offer much more flexibility regarding networking. Does Server 2008 support such networking features? Do futhure ISA server versions support "policy based routing"?

Many thanks for your hints and helpful replies.
Kind regards
Dani
Post #: 1
RE: How-to route all tunneled traffic via internal netw... - 30.Jun.2008 9:39:39 AM   
tshinder

 

Posts: 47181
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Dani,

Is it that you want the VPN clients to connect to the Internet through another firewall, and not the one that they've established the VPN connection to?

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to dani.wenger)
Post #: 2
RE: How-to route all tunneled traffic via internal netw... - 30.Jun.2008 10:16:14 AM   
dani.wenger

 

Posts: 3
Joined: 20.May2008
Status: offline
Hi Tom,
Yes, that's right.
I want the VPN-clients to access the internet through another firewall (incl. IDS,IPS,...).

Thanks
Dani

(in reply to tshinder)
Post #: 3
RE: How-to route all tunneled traffic via internal netw... - 1.Jul.2008 7:12:03 AM   
tshinder

 

Posts: 47181
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Dani,

You can take advantage of the Web Proxy and Firewall client configuration on the VPN clients to route requests to another ISA firewall, which could then route the requests to another Internet gateway.

That's the only way I know where you can reroute remote access VPN client connections.

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to dani.wenger)
Post #: 4
RE: How-to route all tunneled traffic via internal netw... - 1.Jul.2008 7:25:10 AM   
dani.wenger

 

Posts: 3
Joined: 20.May2008
Status: offline
Hi Tom,
I assume that the Web Proxy and Firewall feature only applies to web browsing and not for general traffic such as VoIP or dedicated application traffic.
Is that right?
If yes, it does not seem to fit for me...

Thanks
Dani

(in reply to tshinder)
Post #: 5
RE: How-to route all tunneled traffic via internal netw... - 1.Jul.2008 7:42:53 AM   
tshinder

 

Posts: 47181
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Dani,

The Web Proxy client configuration takes care of forwarding HTTP/HTTPS traffic from applications that are configured to use the Web Proxy configuration.

The Firewall client will forward requests from any Winsock application transparently. So, if your applications are written to the Winsock interface, the Firewall client will pick them up and forward the connections to the ISA firewall that you designate the Firewall client to use.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to dani.wenger)
Post #: 6

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Firewall] >> Network Infrastructure >> How-to route all tunneled traffic via internal network interface Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts