• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

How Many IP Addresses Do I need to support DirectAccess?

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [Forefront Unified Access Gateway 2010] >> DirectAccess >> How Many IP Addresses Do I need to support DirectAccess? Page: [1]
Login
Message << Older Topic   Newer Topic >>
How Many IP Addresses Do I need to support DirectAccess? - 5.May2010 11:52:24 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
On the external interface of the UAG DA server, you need two consecutive public IP addresses. The requirement for two consecutive public IP addresses is to support Teredo, which is an IPv6 transition protocol. While you do have the ability to turn off Teredo support, the UAG DA wizard will not allow you to complete the configuration of the UAG DA server without meeting this requirement. Note that you can put a firewall in front of the UAG DA server, just as along as you have a route relationship (and not a NAT relationship) between the Internet and the external interface of the UAG DA server.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Post #: 1
RE: How Many IP Addresses Do I need to support DirectAc... - 5.May2010 5:16:21 PM   
Jason Jones

 

Posts: 4663
Joined: 30.Jul.2002
From: United Kingdom
Status: offline
Also, if you are planning to use a two node DirectAccess array with NLB (the entry level) you will need at least FOUR public IP addresses:

One public addressed DIP for each array member (=2 min)
Two public addressed VIPs for the DirectAccess needs

Cheers

JJ

< Message edited by Jason Jones -- 5.May2010 5:17:23 PM >


_____________________________

Jason Jones | Forefront MVP | Silversands Ltd
My Blogs: http://blog.msedge.org.uk/ and http://blog.msfirewall.org.uk/

(in reply to tshinder)
Post #: 2
RE: How Many IP Addresses Do I need to support DirectAc... - 6.May2010 10:47:39 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Jason,

Thanks!

I'm thinking that maybe I'll creating some posts that have mistakes in them so that we can drum up more conversations on this board ;)

Also - if you have any hints, ideas, tips, tricks ANYTHING you can think of that we can do to make more people interested in trying out DirectAccess, let me know. It's such as great technology I'm surprised that we don't have more input in this forum.

Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to Jason Jones)
Post #: 3
RE: How Many IP Addresses Do I need to support DirectAc... - 13.Jun.2010 7:17:29 PM   
RazorBlade

 

Posts: 1
Joined: 13.Jun.2010
Status: offline
I am an IT pro, and I work for a smaller company (about 200 employees). We need a new firewall and I am looking at the possibilities of UAG. What I usually do before we take something in production is test it at home. Unfortunately I canít get 2 public IP addresses (at least not IPv4) so I need UAG with DA working with only one public IP. The problem is that everybody is telling me it canít be done, but nobody seems to know why. What I understand is that 2 public IP addresses are required for toredo. I also understand that you donít have to use toredo. Then I get the answer that you canít get past the wizard without giving two public IP addresses. When I reply that the wizard only generates Powershell and that you can therefore also configure UAG without wizard, I get no further answers. I hope somebody here can give me some insight.

I can probably get a block of public IPv6 addresses from my provider and my provider can also tunnel IPv6 into IPv4 and the other way around. My provider is testing IPv6, and customers can join these tests. So I probably really donít need toredo.

(in reply to tshinder)
Post #: 4
RE: How Many IP Addresses Do I need to support DirectAc... - 21.Jun.2010 11:28:33 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi RazorBlade,
If you need a new firewall, UAG isn't really the right option for you. UAG is a remote access gateway and DirectAccess server, that you can put on the edge because TMG is installed on it, but the firewall on the UAG server is to protect the UAG server itself and the network behind it. It won't enable any outbound access at all. For that, you might want to consider TMG - which is a network firewall that you can configure for inbound and outbound access - but TMG is not a very good option for DirectAccess.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to RazorBlade)
Post #: 5
RE: How Many IP Addresses Do I need to support DirectAc... - 28.Mar.2013 8:47:39 PM   
jofil

 

Posts: 2
Joined: 28.Mar.2013
Status: offline
Hi Everyone,
I'm kind of stuck with my deployment and I would like some clarification regarding the number of IPs required to properly deploy Direct Access within UAG, as I cannot activate the Direct Access. I get a message ďA timeout occurred. The Teredo network interface cannot be enabled.Ē I do have Exchange 2013 working fine (OWA, activesysnc) deployed via UAG.
Here is my network in a nut shell:
1. From my ISP I have one internet IP (222.222.222.222)
2. Cisco router with NAT connected to TMG for port 80 and UAG for port 443
3. The TMG has one internal adapter & IP of (100.100.100.10) and one external adapter and IP of (192.100.100.10)
4. The UAG has one internal adapter & IP of (100.100.100.20) and one external adapter with four defined and consecutive IPs (192.100.100.20 -23)
5. Both TMG and UAG are domain joined
Is this a valid setup?
Your help is much appreciated!!!

(in reply to tshinder)
Post #: 6
RE: How Many IP Addresses Do I need to support DirectAc... - 23.May2013 1:24:30 AM   
Montgomery

 

Posts: 2
Joined: 23.May2013
Status: offline
Most stores will save the items you put in your cart, which means you can come by and check for price drops regularly.


www.arm2teeth.com
Cheap RS Gold

(in reply to jofil)
Post #: 7

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [Forefront Unified Access Gateway 2010] >> DirectAccess >> How Many IP Addresses Do I need to support DirectAccess? Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts