RE: [fw-wiz] Strange setup

From: Robert L. Wanamaker (bobw_at_avantsystems.com)
Date: 02/27/04

  • Next message: Gary Flynn: "[fw-wiz] Re: IPS"
    To: "'franco segna'" <fsegna@web.de>, <firewall-wizards@honor.icsalabs.com>
    Date: Thu, 26 Feb 2004 18:26:58 -0500
    
    

    Greetings.

    I agree with Paul that without knowing more about the rulesets, etc. it's
    really impossible to say. But I would say that since you haven't indicated
    the presence of any hosts on the ISA<->SonicWall segment, then it's not
    really functioning as a DMZ, but merely as a segment to connect the two
    devices.

    This architecture, IMO, can have significant advantages in an MS shop. As
    Mark indicated, ISA functions as an application layer proxy. I tend to
    disagree that you must have 2 NIC's and dual-home the server; I know that
    Microsoft indicates you must, but I have many sites operating with just one
    segment in MS-Proxy/ISA. It's a bit of torture setting one up the first
    time this way, but it works fine.

    The great advantage [IMO] of this architecture is that you can easily setup
    egress filtering to prohibit all client workstations from accessing the
    outside world directly, and permit only the ISA server such access. A great
    thing is that since ISA server is Active Directory aware, it becomes quite
    easy to manage users and groups at the application level, and restrict
    access to certain sites based on AD information. Not to mention logging of
    user activity, blah blah blah.

    The LAN-backbone<->SonicWall segment is in place to permit mail, and any
    other non-proxy aware applications to function as needed. If the ISA server
    was setup single-homed, the overall architecture would be simplified.

    If that "dmz" truly has no hosts, and is not doing anything, then I think
    this is a safe bet.

    Regards,

    Bob

    -----Original Message-----
    From: firewall-wizards-admin@honor.icsalabs.com
    [mailto:firewall-wizards-admin@honor.icsalabs.com] On Behalf Of franco segna
    Sent: Thursday, February 26, 2004 9:39 AM
    To: firewall-wizards@honor.icsalabs.com
    Subject: [fw-wiz] Strange setup

    Hi everybody,
    I'm being confronted with the following existing setup:

        T1 --------------------------------
    (Internet | LAN backbone |
     and VPNs) ------------+---+---+-+-+-+-+---
         | | | | | | | |
         | +-------+ local x.x.x.254/24 | | | | | | +-
         | | Sonic +---------------------+ | | | | +-
         +--+ Wall | | | | |
            | Pro +------+ | | | +- SQL
            +-------+ dmz | | | +-- mail
                      (?) | +--------+ | +--- etc.
                           | | MS ISA | |
                           +--+ 2000 +------+
                              | Server | x.x.x.251/24
                              +--------+

    The public web server is hosted elsewhere. The LAN comprises 30
    workstations.
    To complicate the matter, the LAN address family x.x.x. is NOT
    RFC1918-compliant (and is conflicting with existing Internet hosts).
    The system is up and running, but I cannot understand the bypassing of the
    ISA server through the direct connection firewall/LAN. And the meaning of
    DMZ seems to be lost.
    Anyone can help me to understand the matter ? Thanks in advance

    Franco Segna

    ---
    Franco Segna  -  fsegna@web.de
    via Dante Alighieri 60 - 31027 Spresiano TV - Italia phone +39 0422 725020
    -  fax +39 0422 888707
    Keys server wwwkeys.pgp.net
    Key fingerprint = 704C 3070 70A0 680A 760D  025E D849 02AB 2309 87A3
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Gary Flynn: "[fw-wiz] Re: IPS"

    Relevant Pages

    • Port Forwarding for Outbound Email
      ... I have recently moved my network from a Qwest DSL setup to a Eschelon ... For the past two years we have been running ISA server as our firewall ... exchange server for email. ... the past we have setup some of our remote locations with this same ISP ...
      (microsoft.public.isaserver)
    • Login Problem
      ... Win2003 Web Server/IIS6 ... ISA Server 2000 Enterprise Edition ... Part of my site is private and uses are challenged for a login. ... I am wondering if I have something setup improperly in IIS6. ...
      (microsoft.public.isa.enterprise)
    • Re: How To Use Multiple Internet Connections
      ... Array, and in the article it only mentions load-balancing for the VPN ... > ISA Server, which is included into SBS 2k3, can do> the fail over and load balancing, but it involves a server array and the> hell of setup ... It shouldn't be hard to configure small network with static IPs. ...
      (microsoft.public.windows.server.networking)
    • [EE] SP2 on Array Members in a Workgroup (CSS Authentication)
      ... Today I tried installing the new SP2 for Microsoft ISA Server 2004 ... My Configuration Storage Server is ... Setup failed while registering new events and alerts. ...
      (microsoft.public.isa.enterprise)
    • ISA 2004 Server Errors
      ... I have recently installed ISA Server 2004 in our network. ... I have setup my rules and i am able to get out to the internet using ... connection Attempts, and a good amount of these revolve around SSL ... Error Information: 0x88 ...
      (microsoft.public.isa)