
Configuring ISA Server with a Single Network Adapter
When you install ISA Server on a computer with a single network adapter, ISA Server is only aware of two networks: the Local Host network that represents the ISA Server computer itself, and the Internal network, which includes all unicast Internet Protocol (IP) addresses that are not part of the Local Host network. In this configuration, when an internal client browses the Internet, ISA Server sees the source and destination addresses of the Web request as belonging to the Internal network.
Configure the Internal Network During Setup
During Setup of ISA Server 2004 on a computer with a single network adapter, specify all IP address ranges for the Internal network, excluding the following:
-
0.0.0.0
-
255.255.255.255
-
224.0.0.0-254.255.255.255 (multicast)
-
127.0.0.0-127.255.255.255
Apply a Network Template
ISA Server includes a number of predefined network templates that respond to common network topologies. When you install ISA Server on a computer with one network adapter, we recommend that you configure the ISA Server Single Network Adapter network template. To do this, use the Network Template Wizard, as follows.
To apply the Single Network Adapter template
-
In ISA Server Management, expand the Configuration node, and then click Networks.
-
On the Templates tab, click the Single Network Adapter template.
-
On the Welcome page of the Network Template Wizard, click Next.
-
On the Export the ISA Server Configuration page, click Export to export your current configuration before applying the Single Network Adapter template. Then click Next.
Caution: |
|---|
|
When you apply a network template, the new template overwrites all current rules (except system policy rules) and network configuration settings.
|
-
On the Internal Network IP Addresses page, specify settings for the Internal network. Then click Next.
Note: |
|---|
|
The default configuration proposed for the Internal network IP address range is:
|
-
0.0.0.1 to 126.255.255.255 and 128.0.0.0 to 255.255.255.254.
-
This includes all IP addresses except 0.0.0.0, 255.255.255.255, and the address ranges 127.0.0.0–127.255.255.255 (localhost).
-
We recommend that you also exclude 224.0.0.0-254.255.255.255 (multicast).
-
On the Select a Firewall Policy page, click Apply default Web proxying and caching configuration, and then click Next.
Note: |
|---|
|
This creates a default access rule denying traffic to all networks. After setting up the template, create the policy rules required to allow Internet access to Web clients, configure caching as required, and create Web publishing rules to control access to servers protected by ISA Server.
|
-
Check the settings for the new template, and click Finish to complete the wizard.
-
In ISA Server Management, click Apply to save the new settings.
After applying the Single Network Adapter network template, the following network and access rule settings are configured:
-
Local Host network: 127.0.0.0–127.255.255.255.
-
Internal network: equals everything else, where everything else is:
-
0.0.0.1–126.255.255.255
-
128.0.0.0–255.255.255.254
-
Default access rule: denies access to all locations.
This is the set of addresses defined by RFC 791 and related RFC updates. Addresses outside this scope are not generally allocated for the Internet or for intranets.
Note: |
|---|
|
If you excluded the multicast addresses in addition to 0.0.0.0, 255.255.255.255 and 127.0.0.0.-127.255.255.255.255, the Internal network range will be as follows:
|
0.0.0.1 - 126.255.255.255, 128.0.0.0 - 223.255.255.255.255, 255.0.0.0 - 255.255.255.254.