Thomas Shinder Blog RSS

All Blogs  »  Thomas Shinder Blog  »  ISA Central  »  Blog article: ISA Pet Peeve #12536921

ISA Pet Peeve #12536921

“I have an ISA firewall in the DMZ”

What does this mean?

Does the ISA firewall have an external interface connected to the Internet and an internal interface connected to the DMZ?

Does the ISA firewall have an external interface connected to a DMZ and an internal interface connected to the private corporate network?

Does the ISA firewall have an external interface in an anonymous access DMZ and an internal interface in an authenticated access DMZ?

Does the ISA firewall have 9 NICs, with 5 of them in DMZs and 4 in private corporate networks?

OR, is it the most dreaded possibility:

Does the single-NIC (caponized) ISA firewall have its only, solitary interface in a DMZ segment between two "firewalls" (invariably souped up routers with a FIREWALL sticker on their bezels)

MORAL OF THE STORY:

Tell us about the relevent network topology. “In the DMZ” means as much as “open a port” (cf. http://www.tacteam.net/openport.htm)
 
HTH,

Tom

Thomas W Shinder, M.D.

Site: www.isaserver.org

Blog: http://blogs.isaserver.org/shinder/

Book: http://tinyurl.com/3xqb7

MVP — ISA Firewalls

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a

Related Posts from the Past:




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Solution Center