configuring ISA server as part of domain

A

Akhlaq Khan

following is the configuration in my office LAN:

1. A Win2k Server domain controller.
2. A Win2k Proxy + Firewall Server (ISA).

the proxy server is directly connected to the internet (DSL) and the DNS
entries point to the DNS servers of my ISP. Also the gateway defined in my
proxy server TCP/IP properties is pointing to the DSL modem.

Previously, the proxy server was running fine as a stand-alone server. after
introducing the domain controller in the network for centralized
authentication i wanted to configure the proxy server as part of the domain.
in order to make it part of the domain i had to change the DNS entries of
proxy server to point to the local DNS server (domain). so i did that and
made the proxy server part of the domain and added the domain users to the
local groups of the proxy server having rights to browse the internet. then
i changed the DNS settings back to the original ones (pointing to my ISP DNS
servers) but also added the local DNS server entry as a third DNS server (i
kept its order lowest) so that the proxy server won't have any problem in
authenticating domain users or applying any group policies that i would need
to do in future.

The only problem that i have so far expereinced with this configuration is
that some of the users are unable to browse some websites while others seem
to be working fine. also, sometimes the smtp server of my ISP is not found.
if i bypass the proxy server (connecting directly to the DSL modem)
everything works fine. Also, when i remove the local DNS entry from the
proxy server TCP/IP settings (leaving only the two original entries of my
ISP DNS servers) everything again works fine.

My questions are:

1. Did i adopt correct method for configuring my ISA server ? if not, what
would be a more appropriate method for making an ISA proxy server a part
of the domain ?
2. How do i make sure that my domain users still have access to all the
internet resources as they had previously, and at the same time i
can apply any group policies that i need to in future ?

thanks ...
akhlaq.
 
M

Marina Roos

DNS on all nics should point to your server-IP. You put the ISP-DNS-numbers
in the forwarders of your DNS-server.

Marina
 
P

Pavan \(MS\)

Akhlaq,

Vist www.isaserver.org on how to configure your ISA server.

--
Pavan
This posting is provided "AS IS" with no warranties, and confers no
rights
Please note I cannot respond to e-mailed questions.
Please use these newsgroups to let me know if the suggestions resolved the
issue.
 
A

Akhlaq Khan

Pavan,
Thanks for letting know about isaserver.org, its a great resource for ISA
server administartors like me :)

Though i couldn't find answer to my questions on this site. maybe i am
giving an incorrect search string ( i tried searching for "configuring ISA
server as part of domain" and "joining ISA server to domain"). Could you
please let me know how can i find answer to my questions on this site ?

thanks ...

akhlaq
 
A

Akhlaq Khan

Hello Marina,
Your solution seems logical, thanks for your help.

Can you please tell me how to add my ISP DNS numbers in the local DNS server
? I am new to DNS thing ....

thanks ..

akhlaq.
 
M

Marina Roos

DNS-server, rightclick your servername, tab forwarders, add those
ISP-DNS-numbers. After that Restart DNS.

Marina
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top