• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

RE: Install ISA 2006 on DC

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 General] >> Installation and Planning >> RE: Install ISA 2006 on DC Page: <<   < prev  1 2 3 [4] 5   next >   >>
Login
Message << Older Topic   Newer Topic >>
RE: Install ISA 2006 on DC - 20.May2009 11:30:00 AM   
Intasar

 

Posts: 102
Joined: 19.Nov.2007
Status: offline
quote:

,can ping DC, but can't ping client1.


u have not allowed the ping from local to Internal then how can u ping from local to Internal OR Internal To Local ?

follow the instruction to allow ping from ISA Policy

ISA>Firewall Policy>Right Click and select Edit System Policy>In The Remote Management Option Click The ICMP (Ping)>Select From Tab>Click Add And Chose The Internal From Networks.

Apply All Settings and check client have successfully Pinging to ISA Machine

(in reply to OTO_777)
Post #: 61
RE: Install ISA 2006 on DC - 20.May2009 11:58:05 AM   
SteveMoffat

 

Posts: 1130
Joined: 29.Jun.2001
From: Hamilton, Bermuda
Status: offline
Your gateway is wrong. How many times does that need to be pointed out to you???

The gateway of client1 should be the IP address of the internal nic on your ISA VM.....

_____________________________

Thanks
Steve

ISA 2006 Book! - http://tinyurl.com/2gpoo8
TMG Bible - http://tinyurl.com/ykv85hr
www.isaserver.bm

The built in ISA help is likely the most comprehensive help built into an application anywhere. USE it!!! Search it!!! RTFM

(in reply to OTO_777)
Post #: 62
RE: Install ISA 2006 on DC - 20.May2009 12:14:03 PM   
OTO_777

 

Posts: 63
Joined: 3.Jan.2009
Status: offline
Thanks,After that I can ping client1 from ISA server,but can't ping ISA server from client1.
Here's my rule:


Anyway,nobody knows why can't client1 surf in internet?

(in reply to Intasar)
Post #: 63
RE: Install ISA 2006 on DC - 20.May2009 12:15:53 PM   
OTO_777

 

Posts: 63
Joined: 3.Jan.2009
Status: offline
@Steve:
ISA's Internal NIC IP address is 192.168.0.100.
So why it's wrong?

Thanks

(in reply to OTO_777)
Post #: 64
RE: Install ISA 2006 on DC - 20.May2009 2:18:04 PM   
SteveMoffat

 

Posts: 1130
Joined: 29.Jun.2001
From: Hamilton, Bermuda
Status: offline
They are on different subnets......

client 1 192.168.1......

ISA internal 192.168.0........

They both need to be on the same subnet....

_____________________________

Thanks
Steve

ISA 2006 Book! - http://tinyurl.com/2gpoo8
TMG Bible - http://tinyurl.com/ykv85hr
www.isaserver.bm

The built in ISA help is likely the most comprehensive help built into an application anywhere. USE it!!! Search it!!! RTFM

(in reply to OTO_777)
Post #: 65
RE: Install ISA 2006 on DC - 20.May2009 2:40:17 PM   
OTO_777

 

Posts: 63
Joined: 3.Jan.2009
Status: offline
yeah.I know that,but how can I configure it can you tell me?

If I'll configure External NIC with another subnet(i.e 192.168.5.0/24) and set DG 192.168.1.1(My Gateway) - It tells me that thay are in different subnet.

So I've configured External NIC with 192.168.1.0/24 with DG 192.168.1.1(My Gateway).

And Internal with 192.168.0.0/24 Subnet
In such situation what can I don't know.

< Message edited by OTO_777 -- 20.May2009 2:45:51 PM >

(in reply to SteveMoffat)
Post #: 66
RE: Install ISA 2006 on DC - 20.May2009 3:02:40 PM   
SteveMoffat

 

Posts: 1130
Joined: 29.Jun.2001
From: Hamilton, Bermuda
Status: offline
Dear Dear dear....

Please read all the advice you have been given....

Your ISA VM's external facing NIC should be your in your physical networks subnet range......192.168.1.whatever..DG 192.168.1.1

Your Virtual network, including your virtual ISA's internal network card should be of a different subnet....

Just like you have been told on numerous posts.....

_____________________________

Thanks
Steve

ISA 2006 Book! - http://tinyurl.com/2gpoo8
TMG Bible - http://tinyurl.com/ykv85hr
www.isaserver.bm

The built in ISA help is likely the most comprehensive help built into an application anywhere. USE it!!! Search it!!! RTFM

(in reply to OTO_777)
Post #: 67
RE: Install ISA 2006 on DC - 20.May2009 3:04:40 PM   
SteveMoffat

 

Posts: 1130
Joined: 29.Jun.2001
From: Hamilton, Bermuda
Status: offline
There are 66 replies to this thread, many of then showing you what to do....I for one am not going to add any more replies. I suggest you buy an ISA book, a networking book & read them thoroughly before attempting another ISA install.

_____________________________

Thanks
Steve

ISA 2006 Book! - http://tinyurl.com/2gpoo8
TMG Bible - http://tinyurl.com/ykv85hr
www.isaserver.bm

The built in ISA help is likely the most comprehensive help built into an application anywhere. USE it!!! Search it!!! RTFM

(in reply to SteveMoffat)
Post #: 68
RE: Install ISA 2006 on DC - 20.May2009 3:26:16 PM   
OTO_777

 

Posts: 63
Joined: 3.Jan.2009
Status: offline
I've read all replies.
Thanks to all.

But I have Internal NIC is in 192.168.0.0 /24 subnet.
Isn't it different subnet?


BTW I have already bought
Syngress Dr Tom Shinders Isa Server 2006 Migration Guide Aug 2007
&
Sams Microsoft ISA Server 2006 Unleashed Dec 2007 Books.

(in reply to SteveMoffat)
Post #: 69
RE: Install ISA 2006 on DC - 21.May2009 3:51:51 PM   
OTO_777

 

Posts: 63
Joined: 3.Jan.2009
Status: offline
Anybody ?

(in reply to OTO_777)
Post #: 70
RE: Install ISA 2006 on DC - 26.May2009 9:38:22 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Sorry, I'm behind.

What's not working?

Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to OTO_777)
Post #: 71
RE: Install ISA 2006 on DC - 26.May2009 6:32:45 PM   
OTO_777

 

Posts: 63
Joined: 3.Jan.2009
Status: offline
Hello Tom.
First of all,as you know I've configured ISA server's NICs settings in VMware like you said me.

Internal:
IP: 192.168.0.100
SM: 255.255.255.0
DG: ------------------
DNS: 192.168.1.2 - My Internal DNS with forwarders to ISP DNS.

External:
IP: 192.168.1.100 - 192.168.1.0/24 is my Internal Network Subnet.
SM: 255.255.255.0
DG: 192.168.1.1
DNS: -------------

After that,I've created rule to allow ISA surf in internet.
That's fine.
I can surf in internet from ISA.

I've created the rule to allow client1 surf in internet.


After that I've configured client1's(which is in 192.168.1.0/4 Subnet) NIC's settings like this:
XP(client1)settings with secureNAT:
IP: 192.168.1.50
SM: 255.255.255.0
DG: 198.168.0.100 - ISA Server's Internal IP Address(I think it's correct).
DNS: 192.168.1.2(It doesn't work even if I delete the DNS from TCP/IP Properties)

Also it doesn't work if I change client1's IP address to 192.168.0.50 .

I can't browse in internet from client1's machine by using secureNAT.

I've tried all solution posted here without any luck.

First of all I need solution and also I have such questions:
1.Are my NICs settings correct at least or not?
2.Are my XP machine NIC's settings correct or not?

Thanks in advance.
OTO

< Message edited by OTO_777 -- 26.May2009 6:41:05 PM >

(in reply to tshinder)
Post #: 72
RE: Install ISA 2006 on DC - 27.May2009 10:05:16 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Your IP address settings are correct.

The problem is that you don't have a DNS server yet. Create a domain controller VM on VMNet2 and join the client to that domain. Then your domain controller can do DNS name resolution for Internet host names for the client computer.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to OTO_777)
Post #: 73
RE: Install ISA 2006 on DC - 27.May2009 10:24:01 AM   
OTO_777

 

Posts: 63
Joined: 3.Jan.2009
Status: offline
Hello Tom.
I have domain controller(test.com domain) with DNS on it.
It's IP address is 192.168.1.2
On this DC I have VMware installed.
Client1 and ISA Server are joined in this domain.

< Message edited by OTO_777 -- 27.May2009 10:27:37 AM >

(in reply to tshinder)
Post #: 74
RE: Install ISA 2006 on DC - 27.May2009 1:01:19 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
The DC for your virtual environment must all be a VM -- not a live physical server. Create a new virtual machine DC on a new domain, and join the TMG VM and the client VM to that domain.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to OTO_777)
Post #: 75
RE: Install ISA 2006 on DC - 27.May2009 3:45:17 PM   
OTO_777

 

Posts: 63
Joined: 3.Jan.2009
Status: offline
Thanks,and what IP address do I need for my DC?
192.168.1.0 /24 subnet or 192.168.0.0 /24 subnet?

Thanks

Anyway Tom,If I don't have DNS,how ISA server surf in internet?

< Message edited by OTO_777 -- 27.May2009 7:53:56 PM >

(in reply to tshinder)
Post #: 76
RE: Install ISA 2006 on DC - 28.May2009 8:29:54 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
You got to have DNS, that's not an optional component.

So put the virtual DNS/DC server on the same VMNet as the client system and join the ISA VM and the Client VM to the DC VM's domain.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to OTO_777)
Post #: 77
RE: Install ISA 2006 on DC - 28.May2009 9:25:55 AM   
OTO_777

 

Posts: 63
Joined: 3.Jan.2009
Status: offline
Ok Tom.
Thanks.
I am installing DC in Vmware now.
Let you know about the result.

(in reply to tshinder)
Post #: 78
RE: Install ISA 2006 on DC - 28.May2009 3:28:30 PM   
OTO_777

 

Posts: 63
Joined: 3.Jan.2009
Status: offline
The same problem.
I've installed DC and DNS in VMWare with abc.com domain(192.168.1.200 IP address)
After that I've joined ISA server and Client1 in this domain.
Then I've created the rule to surf in internet.
ISA can do it.
Then I've created the rule for internal clients to External.
But Client1 unable to surf in internet.

The same problem.

Here's client1 IP configuration(It doesn't work if I delete DNS from TCP/IP Properties):

After I've configured Client1's NIC with this setting, I can't ping 192.168.1.200(Internal DNS).

Also I've disabled Web Proxy in Internal network in my ISA console.

Any idea?

< Message edited by OTO_777 -- 28.May2009 3:32:07 PM >

(in reply to OTO_777)
Post #: 79
RE: Install ISA 2006 on DC - 29.May2009 9:56:28 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Don't disable the Web proxy listener on the internal network -- you want that enabled.

The client and the DC have to be on the same network ID. I don't see how you were able to join it to the domain when they are on different network IDs.

Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to OTO_777)
Post #: 80

Page:   <<   < prev  1 2 3 [4] 5   next >   >> << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 General] >> Installation and Planning >> RE: Install ISA 2006 on DC Page: <<   < prev  1 2 3 [4] 5   next >   >>
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts