|
Eptalofos75 -> RE: Discussion about article on teaching the boss about the ISA Firewall (8.Mar.2008 7:56:33 AM)
|
Hi Thomas, Your article is really great! I use the ISA 2004 as a back-end firewall behind the Netscreen, the Netscreen has 3 interfaces, Trust (192.x.x.x), Untrust (Internet) and DMZ (172.x.x.x). The ISA has 2 NIC, one connected to the internal LAN and one external connected to DMZ. I have a policy on the Netscreen thats allows everything from Untrust to DMZ, i have only the ISA in my DMZ. The clients can use the ISA or the Netscreen for Internet access. I have to say here that i have used the network template of Edge firewall on the ISA. It works fine but i have 1 question: I have published a Mailserver to provide OWA access over the internet, i have created a VIP on the Untrust interface of the Netscreen to port SSL requests to the 172.x.x.x ip adrress of the ISA Nic connected to DMZ. This doesn`t work, the external clients receive a DNS error. To give more details: When the clients type www.companyname.com/webmail then they get redirected to https://publicipaddress/owa The Netscreen knows, because of the VIP, that it has to port it to 172.x.x.x which is the address of the NIC ISA uses for internet access. ISA should know, because i have published the Mail server, that SSL requests with /owa will be redirected to the Exchangeserver/owa folder? Do you think that ISA denies the request because it comes from publicaddress/owa instead of www.companyname.com? Thank you very much!
|
|
|
|