I’m trying to use today as constructively as possible (being ill is no fun!) and I’ve decided to start playing about with ISA Server 2004.
Now as I understand from the MS Press book that you need to have two network adapters on the ISA box configured as follows:-
Internal Adapter
• No default gateway set
• Has an address routable internally (so in the 10.x.x.x – 172.x.x.x – 192.x.x.x ranges.)
• Has the internal DNS Servers specified (if you have them). In my case these are 10.0.0.100 and 10.0.0.101
Therefore my configuration can be seen here:
http://www.lukepotter.co.uk/ISA/Internal.JPG
External Adapter
• IP Address routable on the internet
• If the ISA Server is at the network edge, default gateway must be that of the ISP
• If ISA Server is doing web proxy DNS lookups on behalf of clients the DNS servers should be those of the ISP.
Currently my external adapter is configured as follows:
http://www.lukepotter.co.uk/ISA/External.JPG
This is all well and good but I have a perimeter router with an address of 10.0.0.138 therefore this is my network edge. Am I configuring the external adapter correctly and in the most secure configuration? The address I’ve currently given the adapter isn’t routable on the internet so I presume I need to obtain an IP from my ISP? Or should I just configure my router to forward all traffic to the ISA Server? Then configure my clients to use the ISA server as their gateway?
If possible I don’t want to change my current router. I need to try and keep my ‘home’ network and ‘study’ networks separate.
With limited resources I’m trying to replicate a commercial environment as best possible within Vmware (DNS, DCs etc.)
Thanks in advance and sorry for the long post!
Luke