Maxell Posted March 19, 2009 Posted March 19, 2009 Hello, We are in the process of setting up Sharepoint within our school, and were wondering how to go about allowing external access to the site. Our network layout is as such: our LEA network is on a set IP range, but we opted out of sitting directly on their network so that we could keep our own IP range. Therefore, we have a gateway proxy server which sits on their network and NAT's over requests to our IP range as needed. Our Sharepoint server therefore, has a private IP address on our network and has no direct connection to the internet. Can we just set up forwarding on the proxy to point all Sharepoint traffic to the internal server address? We also need to allow single sign-on access from Sharepoint to our Exchange server and user home areas. For this we have been advised to install an ISA server. Would an ISA server be ok to sit behind our current gateway proxy, or would we be better to sit it directly on the LEA network with 2 NIC's installed? Alternatively, does anyone have their Sharepoint server installed with 2 NIC's to allow both internal and external access? Sorry for all the questions, I just can't get my head around the infrastructure layout...
apearce Posted March 19, 2009 Posted March 19, 2009 I've not seen anyone with 2 nic allowing that - but there is no reason why you couldnt as long a you have IIS set properly. You should look at ISA doing it really - as I was reading your post I was thinking you need ISA and you can set up the internal and extenal nic, routing, firewall, SSO etc A. 1
TheScarfedOne Posted March 19, 2009 Posted March 19, 2009 Another thumbs up for ISA here. Thats exactly how we have it set up here.
Maxell Posted March 19, 2009 Author Posted March 19, 2009 Thanks for the replies, so ISA on it's own rather than behind our current gateway proxy? That is fine, I don't see a reason why they can't both co-exist with ISA only being used for Sharepoint access (at least to start with).... Would we then just get the LEA to direct all requests for our sharepoint address to the IP of the ISA server, and it would take care of it from there if we set it all up correctly? Thanks again...
Sylv3r Posted March 19, 2009 Posted March 19, 2009 Thanks for the replies, so ISA on it's own rather than behind our current gateway proxy? That is fine, I don't see a reason why they can't both co-exist with ISA only being used for Sharepoint access (at least to start with).... Would we then just get the LEA to direct all requests for our sharepoint address to the IP of the ISA server, and it would take care of it from there if we set it all up correctly? Thanks again... Yes - they are specific Sharepoint rules and wizard you can setup on the ISA box to allow you to set this up relatively easily.
wesleyw Posted March 21, 2009 Posted March 21, 2009 You'd have an external IP address for the ISA the web listener would then forward all requests from this to the Sharepoint server. However if you want more than that you can have several external ip addresses and each can go to a specific internal server such as exchange/OWA, sharepoint, terminal services etc Wes
EduTech Posted March 21, 2009 Posted March 21, 2009 You can tell someone has been on a course for the past 3 days
wesleyw Posted March 22, 2009 Posted March 22, 2009 Yeah shame it wasn't an ISA course lol doing that in a couple of months. Wes
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now