PC Review


Reply
Thread Tools Rate Thread

Configuring Exchange 2000, ISA 2000 on W2K Advanced Server

 
 
Wil Biscardi
Guest
Posts: n/a
 
      31st Jan 2004
We are currently running W2K Advanced Server. We have two
(2) W2K ISA 2000 servers with the external ISA acting as
the PDC and running IIS. We also have a W2K Exchange 2000
cluster running on 2 servers. Things have not been
working very well and we are working with consultants to
help us reconfigure this arrangement to a more "industry-
standard", "best-practices" setup....

One consultant suggests moving the PDC functionality from
the ISA server to the Exchange Cluster. One of the ISA
servers would then act as our external firewall while the
second ISA server would act as an internal firewall
creating a DMZ in the process. There are other details,
but this is the basic concept.

Another vendor is recommending a similar arrangement, but
they suggest obtaining a NEW server to act as the PDC.
The ISA servers and the Exchange servers would act as
member servers on the network.

Any comments, recommendations, advice would be
appreciated. We are sure that there are probably many
acceptable ways to set up a network that is secure,
redundant, etc., so there is more than likely not ONE
answer that says "this is THE way to do it." But we are
looking for suggestions from experts and those of you with
the technical experience to help shed some light on the
matter for us. Please advise. Thank you!

 
Reply With Quote
 
 
 
 
Rob Elder, MVP
Guest
Posts: n/a
 
      31st Jan 2004
I would side with the second vendor. I would never recommend running ISA on
domain controller. That's just plain foolish.

"Wil Biscardi" <(E-Mail Removed)> wrote in message
news:7d9b01c3e847$4bdb4850$(E-Mail Removed)...
> We are currently running W2K Advanced Server. We have two
> (2) W2K ISA 2000 servers with the external ISA acting as
> the PDC and running IIS. We also have a W2K Exchange 2000
> cluster running on 2 servers. Things have not been
> working very well and we are working with consultants to
> help us reconfigure this arrangement to a more "industry-
> standard", "best-practices" setup....
>
> One consultant suggests moving the PDC functionality from
> the ISA server to the Exchange Cluster. One of the ISA
> servers would then act as our external firewall while the
> second ISA server would act as an internal firewall
> creating a DMZ in the process. There are other details,
> but this is the basic concept.
>
> Another vendor is recommending a similar arrangement, but
> they suggest obtaining a NEW server to act as the PDC.
> The ISA servers and the Exchange servers would act as
> member servers on the network.
>
> Any comments, recommendations, advice would be
> appreciated. We are sure that there are probably many
> acceptable ways to set up a network that is secure,
> redundant, etc., so there is more than likely not ONE
> answer that says "this is THE way to do it." But we are
> looking for suggestions from experts and those of you with
> the technical experience to help shed some light on the
> matter for us. Please advise. Thank you!
>



 
Reply With Quote
 
Wil Biscardi
Guest
Posts: n/a
 
      1st Feb 2004
Hi, Rob!

Thanks for your quick reply! I don't think I was clear in
my explanation....
We CURRENTLY have the Domain Controller running on the ISA
server, and we realize, as you noted, that this is a poor
design. Both consultants agree with your assessment. The
difference is that the FIRST consultant would move the PDC
functionality to the Exchange cluster servers. The SECOND
consultant recommends a SEPARATE server to act as the PDC,
and the Exchange and ISA boxes would be member servers.
Are you still leaning towards the second consultant's
recommendation? Thanks again for your time!

Regards,
Wil

>-----Original Message-----
>I would side with the second vendor. I would never

recommend running ISA on
>domain controller. That's just plain foolish.
>
>"Wil Biscardi" <(E-Mail Removed)>

wrote in message
>news:7d9b01c3e847$4bdb4850$(E-Mail Removed)...
>> We are currently running W2K Advanced Server. We have

two
>> (2) W2K ISA 2000 servers with the external ISA acting as
>> the PDC and running IIS. We also have a W2K Exchange

2000
>> cluster running on 2 servers. Things have not been
>> working very well and we are working with consultants to
>> help us reconfigure this arrangement to a

more "industry-
>> standard", "best-practices" setup....
>>
>> One consultant suggests moving the PDC functionality

from
>> the ISA server to the Exchange Cluster. One of the ISA
>> servers would then act as our external firewall while

the
>> second ISA server would act as an internal firewall
>> creating a DMZ in the process. There are other details,
>> but this is the basic concept.
>>
>> Another vendor is recommending a similar arrangement,

but
>> they suggest obtaining a NEW server to act as the PDC.
>> The ISA servers and the Exchange servers would act as
>> member servers on the network.
>>
>> Any comments, recommendations, advice would be
>> appreciated. We are sure that there are probably many
>> acceptable ways to set up a network that is secure,
>> redundant, etc., so there is more than likely not ONE
>> answer that says "this is THE way to do it." But we are
>> looking for suggestions from experts and those of you

with
>> the technical experience to help shed some light on the
>> matter for us. Please advise. Thank you!


 
Reply With Quote
 
Rob Elder, MVP
Guest
Posts: n/a
 
      1st Feb 2004
Also agree with a seperate dc.

"Wil Biscardi" <(E-Mail Removed)> wrote in message
news:7e0301c3e857$fbb46c10$(E-Mail Removed)...
> Hi, Rob!
>
> Thanks for your quick reply! I don't think I was clear in
> my explanation....
> We CURRENTLY have the Domain Controller running on the ISA
> server, and we realize, as you noted, that this is a poor
> design. Both consultants agree with your assessment. The
> difference is that the FIRST consultant would move the PDC
> functionality to the Exchange cluster servers. The SECOND
> consultant recommends a SEPARATE server to act as the PDC,
> and the Exchange and ISA boxes would be member servers.
> Are you still leaning towards the second consultant's
> recommendation? Thanks again for your time!
>
> Regards,
> Wil
>
> >-----Original Message-----
> >I would side with the second vendor. I would never

> recommend running ISA on
> >domain controller. That's just plain foolish.
> >
> >"Wil Biscardi" <(E-Mail Removed)>

> wrote in message
> >news:7d9b01c3e847$4bdb4850$(E-Mail Removed)...
> >> We are currently running W2K Advanced Server. We have

> two
> >> (2) W2K ISA 2000 servers with the external ISA acting as
> >> the PDC and running IIS. We also have a W2K Exchange

> 2000
> >> cluster running on 2 servers. Things have not been
> >> working very well and we are working with consultants to
> >> help us reconfigure this arrangement to a

> more "industry-
> >> standard", "best-practices" setup....
> >>
> >> One consultant suggests moving the PDC functionality

> from
> >> the ISA server to the Exchange Cluster. One of the ISA
> >> servers would then act as our external firewall while

> the
> >> second ISA server would act as an internal firewall
> >> creating a DMZ in the process. There are other details,
> >> but this is the basic concept.
> >>
> >> Another vendor is recommending a similar arrangement,

> but
> >> they suggest obtaining a NEW server to act as the PDC.
> >> The ISA servers and the Exchange servers would act as
> >> member servers on the network.
> >>
> >> Any comments, recommendations, advice would be
> >> appreciated. We are sure that there are probably many
> >> acceptable ways to set up a network that is secure,
> >> redundant, etc., so there is more than likely not ONE
> >> answer that says "this is THE way to do it." But we are
> >> looking for suggestions from experts and those of you

> with
> >> the technical experience to help shed some light on the
> >> matter for us. Please advise. Thank you!

>



 
Reply With Quote
 
Wil Biscardi
Guest
Posts: n/a
 
      1st Feb 2004
Thanks for the follow-up, Rob!
Regards,
Wil

>-----Original Message-----
>Also agree with a seperate dc.
>
>"Wil Biscardi" <(E-Mail Removed)>

wrote in message
>news:7e0301c3e857$fbb46c10$(E-Mail Removed)...
>> Hi, Rob!
>>
>> Thanks for your quick reply! I don't think I was clear

in
>> my explanation....
>> We CURRENTLY have the Domain Controller running on the

ISA
>> server, and we realize, as you noted, that this is a

poor
>> design. Both consultants agree with your assessment.

The
>> difference is that the FIRST consultant would move the

PDC
>> functionality to the Exchange cluster servers. The

SECOND
>> consultant recommends a SEPARATE server to act as the

PDC,
>> and the Exchange and ISA boxes would be member servers.
>> Are you still leaning towards the second consultant's
>> recommendation? Thanks again for your time!
>>
>> Regards,
>> Wil
>>
>> >-----Original Message-----
>> >I would side with the second vendor. I would never

>> recommend running ISA on
>> >domain controller. That's just plain foolish.
>> >
>> >"Wil Biscardi" <(E-Mail Removed)>

>> wrote in message
>> >news:7d9b01c3e847$4bdb4850$(E-Mail Removed)...
>> >> We are currently running W2K Advanced Server. We

have
>> two
>> >> (2) W2K ISA 2000 servers with the external ISA

acting as
>> >> the PDC and running IIS. We also have a W2K Exchange

>> 2000
>> >> cluster running on 2 servers. Things have not been
>> >> working very well and we are working with

consultants to
>> >> help us reconfigure this arrangement to a

>> more "industry-
>> >> standard", "best-practices" setup....
>> >>
>> >> One consultant suggests moving the PDC functionality

>> from
>> >> the ISA server to the Exchange Cluster. One of the

ISA
>> >> servers would then act as our external firewall while

>> the
>> >> second ISA server would act as an internal firewall
>> >> creating a DMZ in the process. There are other

details,
>> >> but this is the basic concept.
>> >>
>> >> Another vendor is recommending a similar arrangement,

>> but
>> >> they suggest obtaining a NEW server to act as the

PDC.
>> >> The ISA servers and the Exchange servers would act as
>> >> member servers on the network.
>> >>
>> >> Any comments, recommendations, advice would be
>> >> appreciated. We are sure that there are probably

many
>> >> acceptable ways to set up a network that is secure,
>> >> redundant, etc., so there is more than likely not ONE
>> >> answer that says "this is THE way to do it." But we

are
>> >> looking for suggestions from experts and those of you

>> with
>> >> the technical experience to help shed some light on

the
>> >> matter for us. Please advise. Thank you!

>>

>
>
>.
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
2000 advanced server sp4 memory max with sql 2000 enterprise SPiderman Microsoft Windows 2000 1 21st Dec 2007 04:29 AM
Configuring Outlook 2000 for Exchange. =?Utf-8?B?Sm9zZXBoIFBhbG1lcg==?= Microsoft Outlook Installation 2 17th Sep 2005 11:43 PM
Re: Installing Advanced Server 2000/Configuring Active Directory Microsoft Windows 2000 Advanced Server 0 3rd Sep 2004 06:34 PM
Downgrade Windows 2000 Advanced Server to 2000 Server Enrico Mantovani Microsoft Windows 2000 Advanced Server 3 5th Feb 2004 04:41 PM
HELP configuring Windows 2000 Workstation to Join a Server 2000 DNS messed up!!! doug Microsoft Windows 2000 DNS 1 2nd Aug 2003 09:10 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 06:49 AM.