Firewall setup help with DMZ

From: Aaron Humperdoomperdink (fasfjasiofasiofj_at_fasfsasfsf.com)
Date: 08/31/05


Date: Wed, 31 Aug 2005 15:59:29 +0100


One of my remote offices would like to connect to a server in our office.
The server will run Windows 2003 terminal server. I would like to only
allow certain internal LAN workstation access to this server via terminal
server. The remote office will connect to the server with terminal
services. I would also like to keep the server safe from the outside world.
Could I give the server the same IP address as the internal workstations on
my LAN?

There is a rough diagram below showing the above config:

Internal Network LAN (192.168.7.x)

¦

Internal Firewall (192.168.7.22 internal - 192.168.7.23 external)

            ¦

Terminal Server (192.168.7.53)

            ¦

External ISA 2004 Firewall (192.168.7.55 internal - 64.57.76.119 external)

I guess I can't do this as the terminal server will need to be on a
different subnet. Could this be a NAT address to help keep it secure in the
DMZ? Are there any better ways to do this and what would be the best way to
configure this? Also, do i need a router beteen my internal firewall and
terminal server and also one between the terminal server and external
firewall?

Thanks you for any help.

Aaron Humperdoomperdink



Relevant Pages

  • Re: terminal server that hands out licenese to other servers..
    ... I've worked in a lot of place but have never had a reason to allow 10 admins on one server at time. ... Microsoft MVP - Terminal Server ... Does that mean you have to install all terminal services in "application mode" on all servers that will need more than two connections? ... To provide licenses for the user connections, install the Terminal Server Licensing component on a domain controller and use the Terminal Server Licensing administration tool to activate your licenses. ...
    (microsoft.public.windows.terminal_services)
  • Re: cant connect to TS after install sp1 on SBS
    ... Deploying Windows Server 2003 Terminal Server to Host User Desktops ... Microsoft ISA Server 2004 Documentation ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: Terminal Server with SBS 2K3
    ... All of these problems only occur on the Terminal Server, there are others, ... > Microsoft CSS Online Newsgroup Support ... > |> policy and the local policy of the terminal server. ...
    (microsoft.public.windows.server.sbs)
  • RE: terminal server licensing issue.
    ... First, Cris is correct, we recommend to install the terminal server ... the SBS domain is different from the standard windows ... | did this the server started telling me I have a license issue. ...
    (microsoft.public.windows.server.sbs)
  • Re: Terminal Server with SBS 2K3
    ... when a normal user logs on the terminal server ... have enough permission to install and uninstall printer drivers. ... If the printer driver for Windows 2003 server is not ...
    (microsoft.public.windows.server.sbs)