Back-to-back perimeter network configuration

In a back-to-back perimeter network configuration, two Microsoft Internet Security and Acceleration (ISA) Server computers are located on either side of the perimeter network (also known as a DMZ, demilitarized zone, and screened subnet). The figure illustrates a back-to-back perimeter network configuration.

In this configuration, two ISA Server computers are hooked up to each other, with one connected to the Internet and the other to the local network. The perimeter network resides between the two servers. Both ISA Server computers are set up in integrated or firewall mode, which reduces the risk of compromise, since an attacker would need to break into both systems in order to get to the internal network.

Perform the following steps to make the servers on the perimeter network available to external (Internet) clients:

1.

Configure the local address table (LAT) on the ISA Server computer that is connected to the corporate network (ISA Server computer 2) to include the Internet Protocol (IP) addresses of the computers in the corporate network. For more information, see Configuring the local address table.

2.

Configure the LAT on the ISA Server computer connected to the Internet to include the IP address of the ISA Server connected to the corporate network and the IP addresses of all the publishing servers in the perimeter network.

3.

Create a server publishing rule for each of the publishing servers on the perimeter network. To publish Web servers, create a Web publishing rule. For example, the figure illustrates a Telnet server and an Internet Information Services (IIS) server. To publish the Telnet server, create a server publishing rule with the following parameters:

Set the IP address of the internal server to the IP address of the IIS server. This address should be in the LAT.

Set the external IP address on the ISA Server computer. This is the address made available to external clients.

Set the protocol settings to Telnet Server.

Set the client to Any user, group, or client computer.

For more information, see Server publishing rules and Web publishing rules.

4.

To publish the IIS server, create a Web publishing rule with the following parameters:

Set the destination sets to a destination set that includes the external IP address of the ISA Server on the perimeter network.

Set the client type to Any user, group, or client computer.

Set the rule action to Redirect the request to a hosted site and specify the IP address or computer name of the publishing Web server.


Top of pageTop of page