• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Can't publish servers

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 General ] >> Web Publishing >> Can't publish servers Page: [1]
Login
Message << Older Topic   Newer Topic >>
Can't publish servers - 23.Mar.2006 5:09:27 AM   
tomyergs

 

Posts: 3
Joined: 23.Mar.2006
Status: offline
I'm relatively new to ISA Server 2004 so I may be completely misunderstanding what it is capable of, but I hope not.

I'm trying to publish some servers (DNS, FTP, etc) from our DMZ to the outside.

I go through the server publishing wizard and configure ISA to listen on a specific external interface.  I set it to forward to the server I wish to publish.

Honestly, it just doesn't work. It works great for web servers, but anything else, it does not work at all.

I'm baffled.

Please help! :-)

Thanks,
Tom
Post #: 1
RE: Can't publish servers - 23.Mar.2006 4:01:20 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Tom,

Are the published servers configured as SecureNAT clients?

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to tomyergs)
Post #: 2
RE: Can't publish servers - 23.Mar.2006 10:41:55 PM   
tomyergs

 

Posts: 3
Joined: 23.Mar.2006
Status: offline
No, they're not SecureNAT clients.  Our network is managed by our corporate parent and we have a packet filtering firewall in place that they manage.  We set up ISA mainly to more securely publish web sites to the internet, and it has been doing a great job of it.

Now I'd like to expand that to other protocols, esp. protecting our DNS server.

So basically the architecture I'm shooting for is:

Internet -> External IP -> NAT firewall -> internal IP ISA firewall -> inspect packet -> forward to DNS server (Linux/BIND)

Is this possible to do?

Thanks!

Tom

(in reply to tshinder)
Post #: 3
RE: Can't publish servers - 24.Mar.2006 2:45:37 AM   
ClintD

 

Posts: 1848
Joined: 26.Jan.2001
From: Keller, TX
Status: offline
If the servers you're publishing don't point to ISA for the default route, then you'll need to set the option in the rule to make requests appear to come from the ISA Server (I believe its on the From tab) . This is the default for Web Publishing rules, but an option for Server Publishing rules.

(in reply to tomyergs)
Post #: 4
RE: Can't publish servers - 24.Mar.2006 10:29:59 PM   
tomyergs

 

Posts: 3
Joined: 23.Mar.2006
Status: offline
I do have it set to have the connection appear to come from the ISA server, and it doesn't work.

I'm thinking something else is amiss though.  I turned on monitoring for live traffic on port 53 to see what was happening.  The traffic is being denied by the default rule.  It's as if the publishing rule doesn't exist.


(in reply to ClintD)
Post #: 5

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 General ] >> Web Publishing >> Can't publish servers Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts