"Scott" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>> ...the ISP has to Reverse-NAT or Reverse-proxy anything that you ever
>> expect to do *inbound*.
>
> I dont fully understand this, are you saying the ISP has to Reverse-NAT or
> Reverse-proxy any traffic from my nodes on the ISP network to my network ?
> not exactly sure what this means.
No, I mean from the Public Internet to your LAN.
Picture your LAN as being just another subnet "behind" another subnet within
the same building. You are in charge of your LAN but someone else is in
charge of the other one and they are the one with the Firewall and the
Public Internet on the outside of their firewall. You can't do anything
outside your own subnet that the other guy on the other subnet doesn't do
for you.
Then you put a VPN capable Firewall between the subnets, which means it is
effectively in the "middle" of the overall LAN and you want to create a
site-to-site tunnel somewhere. You are totally at the mercy of the other
guy on the other subnet. This is a very bad situation to be in.
In this illustration you are you and the other guy is the ISP and your LAN
is "effectively" just simply nothing more than a subnet "inside" the ISP's
LAN. To me that is horrible. But anyway, the point is that the ISP is the
only one who can help you and if they don't have the smarts to just
*automatically & already know* what to do without you having to ask people
in public news groups then you are just really really screwed and should get
out of that situation. Because in the end, in this situation, they are
really the ones who run your LAN,...not you.
I don't think I can do anything more with this beyond what little I have
already suggested in the earlier posts.
--
Phillip Windell
www.wandtv.com
The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Technet Library
ISA2004
http://technet.microsoft.com/en-us/l...chNet.10).aspx
ISA2006
http://technet.microsoft.com/en-us/l...chNet.10).aspx
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/IS...cessRules.html
Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/downlo...7/ts_rules.doc
Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/p...s/default.mspx
Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/e...epartners.mspx
-----------------------------------------------------