Hi, We're busy replacing a separate firewall and proxy server by a single ISA-server. In the first step I'm replacing the firewall, and keep the current proxy server. The external side of the firewall is actually a WAN-system.
One of the issues I have, is caused by 'SecureNAT', as we used to connect via systems on the other side of the WAN, but based on the IP-Address from the proxy-server (which is an internal address), and now ISAserver is NAT-ting this to the external IP-Address.
Is there a way to really route the Proxy-server, or is it necessary to modify all the settings of the firewalls on the other edges of the WAN to allow the ISA-external address ?
When bypassing the 'web-proxy' for http this is improving, but this will than not be possible as soon I use the ISA-server proxy. Or is it possible to make a setup in which the ISA-proxy is working on an "internal address" ?
I looked at several settings for Webchaining, but like I understand it, this would require ISA-servers on the other side as well ...