Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Subnet internet access

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> Access Policies >> Subnet internet access Page: [1]
Login
Message << Older Topic   Newer Topic >>
Subnet internet access - 22.Aug.2006 3:31:12 AM   
tbryantasas

 

Posts: 8
Joined: 22.Aug.2006
Status: offline
I am trying to introduce a subnet for internet access only. I have added the subnet as an address range in the internal network and am able to ping the proxy NIC from the subnet and visa versa. I am unable to get out through the firewall to the internet. When we disable the firewall there is no problem with access to the internet. I assumed once the address range was added to the internal network in the firewall rules in ISA2004 all of the rules associated with the internal network would apply to to the new subnet. Am I wrong with this assumption? Any help would be greatly appreciated.
Notes: main internal address range - 172.16.0.0,  subnet range - 192.168.0.0.

Thanks.
Tony.
Post #: 1
RE: Subnet internet access - 30.Aug.2006 2:40:28 PM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
What is a "proxy NIC"?

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to tbryantasas)
Post #: 2
RE: Subnet internet access - 31.Aug.2006 3:43:25 AM   
tbryantasas

 

Posts: 8
Joined: 22.Aug.2006
Status: offline
The proxy NIC is the network card of our proxy server in the 172.16 range. I am able to ping it from the 192.168 subnet and visa versa. When I try to ping the novell website it cannot reach the destination. In short, it is getting as far as the inside of our firewall but can't get out.

Thanks,

Tony.

(in reply to tbryantasas)
Post #: 3
RE: Subnet internet access - 31.Aug.2006 1:09:39 PM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
What are you using for a proxy server?

Where is it located relative to the ISA Firewall?

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to tbryantasas)
Post #: 4
RE: Subnet internet access - 5.Sep.2006 2:00:41 AM   
tbryantasas

 

Posts: 8
Joined: 22.Aug.2006
Status: offline
ISA is installed on the Proxy server and we use the proxy server internal NIC as our default gateway for computers in the 172.16 range (same subnet). For the new subnet we use the address of a proxy server with DHCP installed to give out addresses to its clients. That proxy server has 2 network cards, 1 with a 192.168 address and one with a 172.16 address. On our main proxy with ISA installed, there is a route table entry which represents traffic coming from the 192.168 subnet via the 172.16 NIC of the subnet proxy server, this points to the same interface as our normal default gateway (internal NIC of our main proxy/firewall server).

Thanks again,

Tony.


(in reply to tshinder)
Post #: 5
RE: Subnet internet access - 5.Sep.2006 2:51:40 PM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Tony,

OK, I'm still unclear where the ISA Firewalls are and the proxy servers you're using are.

Maybe you have a network diagram? Make sure to call out the ISA Firewalls and the proxy servers and how the ISA Firewalls are communiticating with the proxy servers.

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to tbryantasas)
Post #: 6
RE: Subnet internet access - 6.Sep.2006 1:51:28 AM   
tbryantasas

 

Posts: 8
Joined: 22.Aug.2006
Status: offline
Here is a visio diagram of the setup. I hope this helps clarify things. I'm pretty new to this sort of project so might have jumbled things up a bit. Please use the link below.

Thanks for persisting,

Tony.

http://intranet.asas.qld.edu.au/public/staff/tbryant/subnet_map.gif

(in reply to tshinder)
Post #: 7
RE: Subnet internet access - 6.Sep.2006 2:46:45 PM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Tony,

Is this a trihomed ISA firewall configuration?

It's hard to tell how many NICs the ISA firewall on the right has.

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to tbryantasas)
Post #: 8
RE: Subnet internet access - 7.Sep.2006 3:33:25 AM   
tbryantasas

 

Posts: 8
Joined: 22.Aug.2006
Status: offline
It is an edge firewall. The subnet proxy is not directly connected to the ISA firewall, it is connected to a switch in our internal network. The ISA firewall computer has 3 NIC's (Internal(Internal LAN and subnet), External(Internet), Wireless LAN(out of this equation)).

Cheers,

Tony.

(in reply to tshinder)
Post #: 9
RE: Subnet internet access - 7.Sep.2006 3:13:49 PM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Tony,

So, the one on the right is trihomed? I don't see the three IP addresses bound to that ISA firewall.

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to tbryantasas)
Post #: 10
RE: Subnet internet access - 8.Sep.2006 2:48:10 AM   
tbryantasas

 

Posts: 8
Joined: 22.Aug.2006
Status: offline
Hi Tom,
I have changed the diagram to show all of the connections to the ISA server, you can use the same link above. I hope this helps. The wireless is configured as a seperate network which was one of the reasons we upgraded to 2004 for that multiple network functionality. Apart from that, the subnet setup is one we had going successfully under ISA2000 with the same design and a route table entry on the ISA server. There must be some kind of rule we have missed and unfortunately we can't refer back to it. The ISA 2004 import utlity didn't really help us with the importing of our old settings from ISA2000, so we rebuilt the rule set. This subnet is our only stumbling block.

Regards,

Tony.

(in reply to tshinder)
Post #: 11
RE: Subnet internet access - 10.Sep.2006 6:01:38 PM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Tony,

OK, this is the Network within a network scenario. You need to include those 192.168 addresses in the definition of the ISA Firewall's default Internal Network and include a routing table entry on the ISA Firewall pointing to the back-end device as its gateway.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to tbryantasas)
Post #: 12
RE: Subnet internet access - 12.Sep.2006 4:40:24 AM   
tbryantasas

 

Posts: 8
Joined: 22.Aug.2006
Status: offline
Thanks Tom,
We already have those things in place. I double checked the settings in the route table and in the definition of the internal network on the ISA server. Still no luck.
In the diagram there is a text box below the ISA server with the route table entry that is put in, it refers to traffic coming from 172.16.1.180 under the 192.168.0 range.

Regards,

Tony.

(in reply to tbryantasas)
Post #: 13

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> Access Policies >> Subnet internet access Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts