Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

RE: I WILL PAY YOU TO HELP ME FIX my PERIMETER ISA 2004 network

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> DMZ >> RE: I WILL PAY YOU TO HELP ME FIX my PERIMETER ISA 2004 network Page: <<   < prev  1 [2]
Login
Message << Older Topic   Newer Topic >>
RE: I WILL PAY YOU TO HELP ME FIX my PERIMETER ISA 2004... - 8.Mar.2005 5:12:00 AM   
WyldWolf

 

Posts: 246
Joined: 3.Mar.2005
From: Wisconsin
Status: offline
Sorry Tom I misunderstood, I thought he was trying to publish servers which you probably wouldn't want to do with all public addresses. So you should be able to simply re-cable.

But evps, as I saw in the route table you posted was a mis-masking as your subnet of servers was masked the same as the block of IP addresses on the external ISA nic, hence it won't know how to route the traffic. If you fix that so that the public server IP's and your external ISA nic are masked properly (and recable) you should be good to go!

[ March 08, 2005, 05:14 AM: Message edited by: WyldWolf ]

(in reply to evps)
Post #: 21
RE: I WILL PAY YOU TO HELP ME FIX my PERIMETER ISA 2004... - 8.Mar.2005 2:45:00 PM   
evps

 

Posts: 13
Joined: 5.Mar.2005
Status: offline
Tom says "and the upstream router is configured with the route to that block"

The ISP says "We don't add routes to our upstream routers"

Now what?

(in reply to evps)
Post #: 22
RE: I WILL PAY YOU TO HELP ME FIX my PERIMETER ISA 2004... - 9.Mar.2005 1:59:00 AM   
tshinder

 

Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
quote:
Originally posted by WyldWolf:
Sorry Tom I misunderstood, I thought he was trying to publish servers which you probably wouldn't want to do with all public addresses. So you should be able to simply re-cable.

But evps, as I saw in the route table you posted was a mis-masking as your subnet of servers was masked the same as the block of IP addresses on the external ISA nic, hence it won't know how to route the traffic. If you fix that so that the public server IP's and your external ISA nic are masked properly (and recable) you should be good to go!

Hi WW,

But that's the cool thing, you can publish servers even you configure a route relationship between the source and destination Network. You couldn't do that with ISA 2000.

Try it out, its cool!

HTH,
Tom

(in reply to evps)
Post #: 23
RE: I WILL PAY YOU TO HELP ME FIX my PERIMETER ISA 2004... - 9.Mar.2005 7:35:00 PM   
tcgeorge

 

Posts: 17
Joined: 10.May2001
From: Tacoma, WA USA
Status: offline
"Should I have plugged internet directly into the ISA box's External NIC?" - Absolutely.

You should have your internal facing nic plugged into the same switch as all of your other pcs/servers on your network.

You should have you external facing nic plugged directly into your internet connection.

You should have your DMZ facing nic plugged into another switch with those servers that you want the general public to have access to.

I do agree with WW that your subnet mask does not appear correct for a public address set. Verify your mask settings with what your ISP provided to you.

(in reply to evps)
Post #: 24

Page:   <<   < prev  1 [2] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> DMZ >> RE: I WILL PAY YOU TO HELP ME FIX my PERIMETER ISA 2004 network Page: <<   < prev  1 [2]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts