Setup 2-node Array with 3-Leg Perimeter (Full Version)

All Forums >> [ISA 2006 General] >> Installation and Planning



Message


IZ -> Setup 2-node Array with 3-Leg Perimeter (23.Jul.2008 8:28:17 AM)

3 machines are all joined to internal domain:
CSS: 1 internal nic
ISA1: 3 nics, external nic has DG and internal nic has DNS
ISA2: 3 nics, external nic has DG and internal nic has DNS
After setup as following, I can see ISA1&2 have green icons in Servers folder but internal machines cannot access Internet. Any sugguted troubleshoot? Thanks.

On CSS, 
1. Install Configuration Storage Server and Configure a new ISA Server enterprise

2. Create New array named ISA, Add ISA1 and ISA2 in Managed ISA Server Computers of Computer Sets
 
On ISA1 and ISA2,
1. Install ISA server services
2. Use CSS machine as Configuration Storage Server
3. Join an existing Array - ISA, using Windows Authentication and Add the internal Adapter
4. Setup 3-leg Perimeter in Networks | Templates, Add Range for Perimeter and select Block all
5. Enable Network Load Balencing Integration and Set Virtual IP on each Network
6. Create a Web Access Rule:
Arrays | ISA | Firewall Policy | Action | New | Access Rule | Web Access | Next | Allow | Next | Add | Common protocols | HTTP and HTTPS | Next | Add Source | Networks | Internal | Next | Add Destination | Networks | External | Next | Next | Finish | Apply




IanC -> RE: Setup 2-node Array with 3-Leg Perimeter (24.Jul.2008 11:10:37 AM)

Have you configured your client machines as either Web proxy or SecureNAT (default gateway = ISA's internal VIP address) client?

Ian




IZ -> RE: Setup 2-node Array with 3-Leg Perimeter (24.Jul.2008 11:19:28 AM)

Yes, I did try SecureNAT (default gateway = ISA's internal VIP address) and Firewall Client as well. Did you see anything wrong in my setup? Thanks.




IanC -> RE: Setup 2-node Array with 3-Leg Perimeter (24.Jul.2008 11:40:17 AM)

The general setup looks fine to me.   Assuming that there are no alerts generated,  I would start by making sure that the array members can successfully resolve external DNS names.  If all your internet bound traffic goes via the ISA array, you would obviously need to create an outbound rule allowing DNS traffic from your internal DNS servers.

Ian




Page: [1]