Configuring company's network infrastructure.

Discussion in 'Networks' started by guess who, May 19, 2008.

  1. guess who

    guess who Bit Poster

    49
    0
    19
    Hi everyone,

    It's been a while since i've posted a something here. :biggrin Hope everyone's OK ! :thumbleft

    OK, so I've got some question regarding configuring mail and web server for my company and, of course, ISA server. I'm not sure about some part's of the configuration so I need you help ! :oops:

    Well anyway, this is my first configuration of this kind so be reasonable. :biggrin

    I will have mail and web server and ISA server will serve as firewall and DMZ zone for those two server's.

    Here's the picture of my infrastructure:

    [​IMG]

    So, I got three network card's on ISA server. One for internal network, one for external and one for DMZ. I have configured internal and DMZ cards withouth default gateway (hope that's OK ?) and external card must be configured with public IP adress, that i got from my ISP, and default gateway. But, what default gateway must be set ? If i put default gateway that i have for my network, 192.168.0.2, it says that it's not on the same subnet ?

    Now, as you see, my ISA server will be behind router that i got from my ISP. I don't know how to configure that router now ?

    Is there anything else i must be carefull about with this kind of configuration ?


    Thank's for your answers ! :D ;)
     
    Certifications: MCP, MCSA
    WIP: MCSE
  2. karl_lankford

    karl_lankford Byte Poster

    100
    0
    31
    we have an IP configured on our router that is in the same subnet and use that.
     
    Certifications: CISSP, MCP, MCDST, MCSA, MCSE, CCENT, CCNA
    WIP: MCSE Upgrade
  3. guess who

    guess who Bit Poster

    49
    0
    19
    Thank's for your answer. ;)

    So basically, i have to set exact same configuration on external network card as is on router ?
     
    Certifications: MCP, MCSA
    WIP: MCSE
  4. guess who

    guess who Bit Poster

    49
    0
    19
    And one more question. Can I run ISA server on virtual machine or it has to be on "live machine" ? :)
     
    Certifications: MCP, MCSA
    WIP: MCSE
  5. Finkenstein

    Finkenstein Kilobyte Poster

    378
    3
    59
    You can run it on a virtual server. Just make sure you throw enough power at it.
     
    Certifications: MCP, Network+, CCENT, ITIL v3
    WIP: 640-822
  6. guess who

    guess who Bit Poster

    49
    0
    19
    Thank's !

    I bit confused about network cards also. I know that this is gonna sound funny but where do I plug network cables ? :) I mean, for internal card i plug into switch, for external into router and for DMZ ? Is this how it's gonna or ?

    Sorry about stupid questions ! :biggrin
     
    Certifications: MCP, MCSA
    WIP: MCSE
  7. AJ

    AJ 01000001 01100100 01101101 01101001 01101110 Administrator

    6,897
    182
    221
    If you are putting more than 1 server in the DMZ then plug it into a separate switch, then your servers into that switch. ISA will be able to route ext-int-dmz.
     
    Certifications: MCSE, MCSA (messaging), ITIL Foundation v3
    WIP: Breathing in and out, but not out and in, that's just wrong
  8. Modey

    Modey Terabyte Poster

    2,397
    99
    154
    Yes you can as has already been answered. I would say RAM is more important than CPU power though as it will be a more limiting factor if you are running several machines at once. I am currently testing an ISA Server 2006 in a virtual lab to try and implement a new filtering system in our live environment. It's been a very useful tool for trying out different changes etc.. It's only 3-4 machines running at any one time which is probably the practical limit on my laptop anyway (2Ghz C2D and 2GB Ram).
     
    Certifications: A+, N+, MCP, MCDST, MCSA 2K3, MCTS, MOS, MTA, MCT, MCITP:EDST7, MCSA W7, Citrix CCA, ITIL Foundation
    WIP: Nada
  9. guess who

    guess who Bit Poster

    49
    0
    19
    Thank's for your answers.

    1 more question. I dont have 3 ethernet card's in my server that will run ISA so the question is, can i setup my virtual machine to use one card ?

    Like this:

    [​IMG]
     
    Certifications: MCP, MCSA
    WIP: MCSE
  10. kevicho

    kevicho Gigabyte Poster

    1,219
    58
    116
    Certifications: A+, Net+, MCSA Server 2003, 2008, Windows XP & 7 , ITIL V3 Foundation
    WIP: CCNA Renewal
  11. guess who

    guess who Bit Poster

    49
    0
    19
    Thank's kevicho ! :)

    Now, I have configured everything but i'm having problems with ISA.. :rolleyes:

    I have applied rule for sending mail to mail server, that is in DMZ, but i'm getting this error:

    "Description: Server publishing rule [my rule] failed because there was no valid network listener. For requests to reach the published server there must be a network relationship between the selected listener networks and the published server. Location 325.934.4.0.2167.887.
    For more information about this event, see ISA Server Help.
    The failure is due to error: 0x8007000d"

    I have created DMZ network and created network rule that says "Source Network - DMZ to Destination Network - External and Network Relationship - NAT".

    I dont know what i'm doing wrong ? :(
     
    Certifications: MCP, MCSA
    WIP: MCSE

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.