Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Web publishing in DMZ with one NIC card

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 General ] >> Web Publishing >> Web publishing in DMZ with one NIC card Page: [1]
Login
Message << Older Topic   Newer Topic >>
Web publishing in DMZ with one NIC card - 21.Aug.2005 9:19:00 PM   
yaott

 

Posts: 4
Joined: 19.May2005
Status: offline
We have a firewall, a DMZ, and internal network. ISA2K4 is in DMZ with one NIC card. We want to publish securely an internal web site using ISA using SSL bridging. The web publishing rule accepts any HTTPS traffic from External to www.xxx.com (a local host entry on ISA resolves this address to web server internal IP address). Web site public name is also www.xxx.com. The web listener accepts HTTPS request from all networks.

This configure does not appear to be working. ISA log shows connection from External to local host is established on port 443, but immediately terminated.

Why? Does one NIC card support web publishing?
Post #: 1
RE: Web publishing in DMZ with one NIC card - 22.Aug.2005 9:16:00 AM   
tshinder

 

Posts: 47668
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Tony,

The ISA firewall is a firewall. Sure, it has a Web proxy *filter* and a Firewall client Winsock proxy component, but you can turn both of those off easily. You CAN'T turn off the ISA firewall's firewall components. That's because the ISA firewall is a firewall first, second and last.

Yes, you can Web publish with a unihomed ISA firewall, but it breaks a lot of the ISA firewall's firewall model. Get a second NIC in that ISA firewall and all the standard procedures will work fine.

HTH,
Tom

(in reply to yaott)
Post #: 2
RE: Web publishing in DMZ with one NIC card - 22.Aug.2005 4:43:00 PM   
yaott

 

Posts: 4
Joined: 19.May2005
Status: offline
Thanks Tom,

I did not make myself clear enough. We have a PIX firewall, a DMZ where the ISA2K4 box sits, and internal network.

Do I have to have another NIC installed on ISA box to make this work?

Thanks,

Tony

(in reply to yaott)
Post #: 3

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 General ] >> Web Publishing >> Web publishing in DMZ with one NIC card Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts