• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

ISA AD architecture and multiple independent subnets

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 General] >> Installation and Planning >> ISA AD architecture and multiple independent subnets Page: [1]
Login
Message << Older Topic   Newer Topic >>
ISA AD architecture and multiple independent subnets - 2.Nov.2007 3:37:18 AM   
lanaro@mindthegap.it

 

Posts: 5
Joined: 15.Apr.2005
Status: offline
Hi everyone.
I need an architecture opinion.
 
In out test environment, the internal AD structure is a forest with ROOT domain and several CHILD domains.
 
I need to set up an ISA architecture on 2 levels: front end (edge) which leads to a dmz where there are web servers and terminal servers; bck end (separating the dmz from the real infrastructure) where there are the domain controllers, the db servers...

Both front end nd back end ISAs need to be configured in NLB (for high availability).

Some questions:
1) Active Directory: 3 possible options
- Create a domain for ISA in the actual (a child for ROOT)
- Create a domain for ISA as separate and set up a trust
- Create a domain for isa as separate and access current domains via LDAP (as far s I understood a new feature in ISA 2006)

Which is the best option, i.e. the most secure and flexible.

2) After the edge ISA there are several subtnets, belonging to different environments, which should not route among themselves, but only on specific conditions (protocols) managed by ISA.
All of these needtworks need to talk to the "public" internet.

Which option is best: have several phisical nics on the edge firewall or just one nic with several IPs (note: edge is a VM on ESX 3, so there are no issues on adding more Vnics).

Thank you very much for ideas and suggestions.
Post #: 1
RE: ISA AD architecture and multiple independent subnets - 5.Nov.2007 7:43:44 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
What types of connections require authentication?

Do you need a record of all application usage, user names, and sites that users use to connect to the Internet?

Do you require User Certificate authentication?

Do you require Kerberos authentication?

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to lanaro@mindthegap.it)
Post #: 2
RE: ISA AD architecture and multiple independent subnets - 6.Nov.2007 8:09:50 AM   
Jason Jones

 

Posts: 4663
Joined: 30.Jul.2002
From: United Kingdom
Status: offline
Can see where Tom is heading here...I will also defer my response until you get chance to answer.

As for the NICs, ISA needs a NIC per network definition so you will need seperate NICs for each of thre security zones you are planning on using. This is a nice setup that provides a good "least privilege" approach...

Cheers

JJ



_____________________________

Jason Jones | Forefront MVP | Silversands Ltd
My Blogs: http://blog.msedge.org.uk/ and http://blog.msfirewall.org.uk/

(in reply to tshinder)
Post #: 3

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 General] >> Installation and Planning >> ISA AD architecture and multiple independent subnets Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts