RE: Discussion on the Edge Firewall Network Template - 19.Feb.2004 1:20:00 PM
Guest
On a similar topic, i think in ISA2000 if you set up a tri-homed server ie external-DMZ-LAN you had to use public addresses for the DMZ. Is this correct and if so is it still the case with isa2004 beta? I have Firewall-1 setup with public ip's on external interfaces and private addresses on the DMZ and LAN eg DMZ 192.168.3.0 LAN 192.168.1.0 and it works fine. I am trying to do this with ISA2004 and not having much luck. I can publish a web server from DMZ but can't get anything much else to work regars the DMZ. eg can't ping internal network from DMZ even if i create a rule to allow all traffic from DMZ to LAN. Any ideas?
You can create DMZs from public or private addresses now, firewall policy is applied to all communications. You should be able to define your networks, create the network relationship, and then create Access Policy to control the traffic you can to move between the networks.
The template does simplify the setup to a great extent! However, users will still need to configure DNS correctly on the interfaces. I'll do an article for DNS on ISA 2004 so that everyone knows how to setup their DNS servers correctly.