Jump to content

Recommended Posts

Posted

We are using LGFL 1.0 internet and using our own ISA server 2006 and Websense filtering. Now we are configured with LGFL 2.0 services few days ago and would like to use LGFL's firewall & web filtering services. They configured CISCO Router + CiSCO Firewall on the site and gave us an IP range to use. Previously we had the connection from the extreme switch going into our ISA Server 2006 and then distribute to all the school through Group Policy. We got IP address range from LGFL to use and different DNS addresses, which I think will direcetly go into our switch and we will configure our DHCP settings? Can someone already using LGFL 2.0 services confirms thins please???

 

Now the second question how do we change our internal IP address? Domain controller, AV etc. We are currently using 172.x.x.x ip adress and received 10.8.x.x from LGFL for 2.0 services. Please advise how to change the all the internal IP addresses and what impact will it has on our network??

 

I hope this is possible as we do not have much time left for change over.

 

Please help ........................................................ help..........................................................

Please help ........................................................ help..........................................................

Posted

No need to change your internal addresses.

 

DOCUMENT EVERYTHING YOU CHANGE BEFORE YOU MAKE ANY CHANGES.

DOCUMENT YOUR CHANGES BEFORE YOU MAKE THEM

 

 

Make sure all your internal servers and clients use only your AD for DNS.

 

Physically isolate the 10 range from your LAN.

 

Plug your ISA into either the curriculum or admin port on the ASA as though it was the old Extreme.

Re-configure the EXTERNAL NIC on the ISA to have an address in the 10.8.x.x range (make sure it is in the correct admin / curriculum range)

Make sure that only the INTERNAL NIC on the ISA has DNS servers configured and make sure they are your DCs (assuming your DCs are running AD integrated DNS)

Remove the webchaining rule that points to proxy1; there is no explicit proxy required now.

 

Update the forwarders on ALL your AD DNS servers as per Atomwide documentation.

 

Job done.

 

(Assuming the default gateway of your internal network is your core switch and that the default gateway of your core switch is your ISA.)

 

Are you publishing any sites (do you host sims/eportal/exchange/sharepoint/moodle?) from your LAN? if so you will need to ensure that you have the correct MIPs in place.

 

Do you have any services that connect out on strange ports? Then as well as having them open on your ISA you will also need to have them configured on the ASA by Atomwide (though tell them that it's your ISA IP that is making the outbound connections - because from their persepective it is)

 

Finally where are you? I know someone who might be able to come to site to help if needed.

Posted

North London

 

 

No need to change your internal addresses.

 

DOCUMENT EVERYTHING YOU CHANGE BEFORE YOU MAKE ANY CHANGES.

DOCUMENT YOUR CHANGES BEFORE YOU MAKE THEM

 

 

Make sure all your internal servers and clients use only your AD for DNS.

 

Physically isolate the 10 range from your LAN.

 

Plug your ISA into either the curriculum or admin port on the ASA as though it was the old Extreme.

Re-configure the EXTERNAL NIC on the ISA to have an address in the 10.8.x.x range (make sure it is in the correct admin / curriculum range)

Make sure that only the INTERNAL NIC on the ISA has DNS servers configured and make sure they are your DCs (assuming your DCs are running AD integrated DNS)

Remove the webchaining rule that points to proxy1; there is no explicit proxy required now.

 

Update the forwarders on ALL your AD DNS servers as per Atomwide documentation.

 

Job done.

 

(Assuming the default gateway of your internal network is your core switch and that the default gateway of your core switch is your ISA.)

 

Are you publishing any sites (do you host sims/eportal/exchange/sharepoint/moodle?) from your LAN? if so you will need to ensure that you have the correct MIPs in place.

 

Do you have any services that connect out on strange ports? Then as well as having them open on your ISA you will also need to have them configured on the ASA by Atomwide (though tell them that it's your ISA IP that is making the outbound connections - because from their persepective it is)

 

Finally where are you? I know someone who might be able to come to site to help if needed.

Posted (edited)

It depends on your local requirements. Who set up your ISA and what were their reasons? Also do you have mulitple subnets?

 

Keeping your internal ranges as-is and making a small change to your DNS servers and ISA will take a few minutes (after an hour of thinking and planning).

 

Re-addressing your entire lan will require the retesting of every single service on the network.

 

You've 'officially' got 72hrs to make the switch, so you don't have time to plan for implement and test a complete reconfig.

Edited by psydii
Posted
You've 'officially' got 72hrs to make the switch, so you don't have time to plan for implement and test a complete reconfig.

 

That 72 hours is a very variable thing, my main site migrated back in mid-march. I went to the cabinet where the old LGfL1 connection came in and noticed that there still was a link light on the media converter, so plugged in a laptop and sure enough, it's still live. So it looks like I have a redundant circuit for the time being ;)

Posted (edited)

We are using ISA 2006 with Websense filtering. On our external ISA NIC an ip 212.85.x.x is configured. We are hosting eportal and Moodle on two 212.85.x.x ip address. I think you were assuming that we are using the proxy 1 from LGFL.

I think we need to do NAT on our ISA and don't need to change our internal IP. If anyone did NAT before please explain the process. Eventually we will change all our internal IPs?

Another question. On our ASA only one port is open for both admin and curriculum . How can have two different policies for staff and student? Do we need request to open 2nd port on ASA? And use the different solution for staff. What other schools are using?

What will be the configuration?

Edited by techy32
Posted
You cannot use the ip lgfl2 filtering behind your own NAT/firewall. You will need to move all your machines that were behind the firewall to the other side of your isa server. you can still use logon based filtering however. When you hit a blocked page you should get a login button which you put in your USO credentials which (depending on your policies) may let you view the page. It's all well documented on the support.lgfl.org.uk site, logon there and hit the help link (top right).
Posted

I don't think you get that option either if you are running your own firewall. It's assumed your firewall can differentiate between your users.

 

Upgrading to TMG + Web Protection subscription gives this functionality, but if it is important for your school you may already have a third party addo-on for ISA?

 

Broadly speaking if you run your own firewall/proxy then your options for Web Filtering remain mostly unchanged under LGFL2.

  • 2 weeks later...
Posted

It's true if you have a local firewall or ISA that’s doing NAT then normally you can't do per user filtering or for that matter per workstation filtering - the whole network goes out as one ip so it's the same as Opt2 in LgfL 1 land.

 

What you can do is run your local firewall in one-to-one nat mode rather than many-to-one this means that every workstation and device gets it's own 10.x.x.x address as it goes past your firewall. This way you can make use of the WebScreenII filtering in full. Tricky to set up but does the trick.

 

There is no specific need for an ISA in the corner of the network and I've got rid of that in a couple of primaries but the real way to do it is to re-ip the network which makes full use of all the features.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...