Thomas Shinder Blog RSS

All Blogs  »  Thomas Shinder Blog  »  News ISA Central  »  Blog article: Does the ISA Firewall Support VLAN Tagging?

Does the ISA Firewall Support VLAN Tagging?

Over the years, I’ve seen a lot of people ask if the ISA Firewall supports VLAN tagging . The answer is YES.

Want more details? Check the ISA Server Team Blog for a recent post by Jim Harrison. Jim gives you all the details you need to get it up and running.

Check it out at:

http://blogs.technet.com/isablog/archive/2006/10/0...r.aspx

HTH,

Tom

Thomas W Shinder, M.D.
Site: www.isaserver.org

Blog: http://blogs.isaserver.org/shinder/
Book: http://tinyurl.com/3xqb7

Email: tshinder@isaserver.org

MVP — Microsoft Firewalls (ISA)

3 Responses to “Does the ISA Firewall Support VLAN Tagging?”

  1. Polom Says:

    October 4th, 2006 at 9:12 am

    Hello Tom,

    I’m using an ISA Server 2004 to filter the traffic between many VLAN and IPSec tunnels (aka “remote sites”). All my VLAN are managed on a team (802.3ad) of gb adapters and everything works fine.

    The only major drawback of that technical choice (Windows Server and ISA in the heart of my network !) is that I have no way to implement fault tolerance :( I would have loved migrating to ISA Server EE but it’s impossible, even for that such a critical system !

    The reason is that, to my knowledge, there’s no way to use both ISA’s integrated NLB and 802.1Q.

    In the long run it may lead me to use a different solution for my security need, because redundancy becomes a prerequisite for my company :-|

    Any ideas are welcome !

    Best regards,
    Polom.

  2. Jim Harrison Says:

    October 4th, 2006 at 12:55 pm

    NLB; not ISA, is the limiting factor here.
    You can’t use 802.1Q or 802.1ag with NLB because of the way NLB manipulates the packets.

  3. MV Says:

    October 18th, 2006 at 2:51 pm

    What about SP2 and the VB script in KB 912943?

    At the end of the KB it says:

    You cannot enable 802.1Q VLAN tagging and integrated NLB on the same interface of a network adapter. This limitation is imposed by NLB. (What Jim says above)

    But then the KB also mentions:

    You cannot enable both 802.1Q VLAN tagging and integrated NLB on different interfaces of a network adapter on ISA Server 2004, Enterprise Edition computers. To enable this functionality, you must install ISA Server 2004 SP2 and run the VBScript file that is described in the “Resolution” section.”

    So there is some support for it but not on the same interface….

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Solution Center