Jump to content

Recommended Posts

Posted

We have just installed a Frog Server. It has two IP addresses. One for the standard web connection and the other for management.

 

Frog have asked that we open up port 8443 to the management IP address.

 

All our incoming traffic is sent through an ISA server sitting in a DMZ. The ISA is set up in Single NIC configuration and basically just forwards web requests to the relevent servers.

 

The only ports open between the Internet and the ISA are 80 and 443. Am I right in thinking that I can use the bridging options to accept requests on 443 and forward them to the Frog server on port 8443? Will this work?

 

I'm currently struggling but I think this maybe becuase the Frog server currently has a self signed (and therefore untrusted) certificate. Will ISA not work at all (with SSL) without a trusted certificate?

 

Sorry, my knowledge of ISA is very limited and I'm learning it as I go.

 

Tom.

  • 5 weeks later...
Posted
I dont believe this will work, because the ISA has only one NIC it cannot act as a firewall and therefore any publishing rules shouldnt work? It has to have a trusted and untrusted network to provide any protection.
Posted

ISA works at Layer 4 so it IS possible to have Web Publishing rules on a Single NIC ISA however not a simple task and certainly not an easy job for the uninitiated.

Frog have asked you to open ports to the server which is a Server Publishing rule and a job for a firewall.

 

I cant help you much beyond these few tips as without knowledge of your topology, firewalls, server configs etc I might make things worse.

 

As the ISA needs to present the Frogs URL to external users as though it was it's own the mismatched SSL or SSL pass thru settings are a contributory factor.

 

You probably have an existing https web publishing rule for email etc so I would make sure that you have backed up your ISA config files first and look at using this publishing rule as a template for your Frog Servers Web Publishing Rules.

If the Frog server can generate a self signed wildcard certificate similar to *.my domain.co.uk you might be able to export it out as a .cer file and use this in the ISA publishing rule.

 

This link has some useful stuff regarding ISA web publishing rules.

 

ISA 2006 Single Network Adapter Configuration and Publishing Mail Server

 

Best of luck you're going to need it...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...