TOTALLY O/T IT Question
Discussion
Dear PHers. Many of you, I know, are involved in a great many IT ventures involving networking. I need a little advice.
I am attempting to use Microsodit Internet Security and Acceleration Server (Firewall and Proxy server to you and me) to allow my little network to see the 'net. I have ONE static IP address but want browsing, Quake and all those good things to work on two or three boxes.
Now..after several hours of fiddling I got browsing to work on the machine with only an internal IP address. Sod all else. So..I reckon with enough fiddling I can get all protocols I want to work on client boxes...but can I get an internal network machine to be "published" to the outside world? Can I buggery.
Does anyone know the magic incantation that will make ISA Server actually work when it comes to routing HTTP requests to a different box? I've read the help. I've configured the machine - it just DFW.
Any ideas/comments gratefully received.
I am attempting to use Microsodit Internet Security and Acceleration Server (Firewall and Proxy server to you and me) to allow my little network to see the 'net. I have ONE static IP address but want browsing, Quake and all those good things to work on two or three boxes.
Now..after several hours of fiddling I got browsing to work on the machine with only an internal IP address. Sod all else. So..I reckon with enough fiddling I can get all protocols I want to work on client boxes...but can I get an internal network machine to be "published" to the outside world? Can I buggery.
Does anyone know the magic incantation that will make ISA Server actually work when it comes to routing HTTP requests to a different box? I've read the help. I've configured the machine - it just DFW.
Any ideas/comments gratefully received.
Hmm.. it's mildly complicated to set up but it's not that difficult.
Have you got it set up as an integrated firewall & caching server or just as a firewall or cache?
Have you tried making the internal IP of the ISA server the default gateway of the PCs you want to 'get out'?
For outgoing traffic, you will need to have firewall rules that allow the traffic to go out and receive responses. For this youi'll need to know the TCP/UDP/Ports info for the protocol. Then set up rules accordingly. For example, in the protocol definitions, define quake client, and set the port numbers etc, in IP Packet Filters add a rule allowing outbound Quake Client traffic.
The alternative is to use the firewall client and set protocol rules.
It might be a problem running more than one quake client from the one external IP address. Depends how clever the protocol is and how clever ISA server can be persuaded to be in handling the protocol. I could try to get it working but wouldn't want to promise.
Hmm.... difficult to explain with a beer in one hand and a keyboard in the other. I use ISA Server here though and at 'work' (aka main client site).
Try www.isaserver.org - they're very good.
edited to say for publishing an internal web server:
- In the tree in ISA management, goto Publishing, select Web Publishing and right click to create a new rule.
- Enter name etc for the rule
- Apply this rule to all destinations
- Apply the rule to any request
- Redirect the request to this internal Web server:...
- You'll probably want it to forward the original host header.
That should do it. Make sure you stop any default web services on the ISA server which would intercept port 80 calls on the outside interface before ISA could redirect them.
>> Edited by CarZee (moderator) on Tuesday 4th March 22:39
Have you got it set up as an integrated firewall & caching server or just as a firewall or cache?
Have you tried making the internal IP of the ISA server the default gateway of the PCs you want to 'get out'?
For outgoing traffic, you will need to have firewall rules that allow the traffic to go out and receive responses. For this youi'll need to know the TCP/UDP/Ports info for the protocol. Then set up rules accordingly. For example, in the protocol definitions, define quake client, and set the port numbers etc, in IP Packet Filters add a rule allowing outbound Quake Client traffic.
The alternative is to use the firewall client and set protocol rules.
It might be a problem running more than one quake client from the one external IP address. Depends how clever the protocol is and how clever ISA server can be persuaded to be in handling the protocol. I could try to get it working but wouldn't want to promise.
Hmm.... difficult to explain with a beer in one hand and a keyboard in the other. I use ISA Server here though and at 'work' (aka main client site).
Try www.isaserver.org - they're very good.
edited to say for publishing an internal web server:
- In the tree in ISA management, goto Publishing, select Web Publishing and right click to create a new rule.
- Enter name etc for the rule
- Apply this rule to all destinations
- Apply the rule to any request
- Redirect the request to this internal Web server:...
- You'll probably want it to forward the original host header.
That should do it. Make sure you stop any default web services on the ISA server which would intercept port 80 calls on the outside interface before ISA could redirect them.
>> Edited by CarZee (moderator) on Tuesday 4th March 22:39
Forums | General Gassing [Archive] | Top of Page | What's New | My Stuff


