Arcesilaus -> RE: Discussion about article on configuring ISA firewall in Netscreen DMZ (11.Aug.2008 2:33:34 PM)
|
Hi Tom Thanks for the info! I've been thinking it over: a 'simple' Route relationship won't work, since the Netscreen Firewall also has access to the DMZ 2, with subnet 192.168.200.0. A MIP or VIP towards the actual IP of the mailserver thus would not be sent to the ISA in DMZ 1, but directly to the mailserver in DMZ 2. That leaves me with three options: It seemed to me that a Route relationship was preferred since the reverse-proxy would took care of the problem for web-publishing rules, but that indeed won't not work for non-web-servers. Is any of the three solutions above preferred over the others? For now, I will first have to configure the ISA server a bit further so I can set the mailserver as a SecureNAT client while keeping the existing setup working (I've been bypassing the ISA server so far for incoming e-mail) and keep the ability to manage it over RDP. It will probably have to wait for a while (priorities are set by others), but I'll keep this thread posted!
|
|
|
|