Reviewing and Modifying Network Rules


After the wizard has completed, the networks, network rules, and firewall rules will have been created and can be customized as necessary. In certain cases, it may be necessary to modify some of the settings that the wizard created, particularly if changes have been made or new networks need to be added to an environment after it has been placed into production.

Modifying Network Rules

Network rules, after they are put into place, are not changed often because the relationship between networks is often quite static. In certain cases, however, modifications may be necessary. If those circumstances arise, the task of modifying the rules is relatively straightforward. To modify an existing network rule, perform the following tasks:

1.

From the ISA Console, click on the Networks node in the console tree.

2.

Click on the Network Rules tab in the Central Details pane.

3.

Double-click on the particular network rule to be modified.

4.

From the dialog box shown in Figure 5.7, reconfigure the network rules as necessary, making changes to Source Networks, Destination Networks, or the Network Relationship.

Figure 5.7. Modifying network rules.


5.

Click OK when the changes are complete.

6.

Click Apply to apply the changes and then click OK.

Creating New Network Rules

Creating a new network rule is primarily done only when a major change to the ISA firewall configuration has taken place, such as when a new network has been added to the server. In addition, this procedure can be used if the network template wizard is not run on a new server and manual methods of configuring the network rules are required. To create a new Network rule, perform the following tasks:

1.

From the ISA Console, click on the Networks node in the console tree.

2.

Click on the Network Rules tab in the Central Details pane.

3.

Click on the Tasks tab in the Tasks pane.

4.

Click the link titled Create a New Network Rule.

5.

Enter a descriptive name for the network rule and click Next to continue.

6.

On the Network Traffic Sources dialog box, click Add.

7.

Select the network or network set that will be added as a source of the rule and then click Add, Close, and Next to continue.

8.

For destination, click Add and perform the same process, this time selecting the network or network set that will be the destination set. Click Next when complete.

9.

Select the type of relationship to configure, NAT or Route, as shown in Figure 5.8. Click Next to continue.

Figure 5.8. Creating new network rules.


10.

Review the settings and click Finish.

11.

Click Apply and then click OK to enable the new rule.



    Microsoft Internet Security and Acceleration ISA Server 2004 Unleashed
    Microsoft Internet Security and Acceleration (ISA) Server 2004 Unleashed
    ISBN: 067232718X
    EAN: 2147483647
    Year: 2005
    Pages: 216
    Authors: Michael Noel

    flylib.com © 2008-2017.
    If you may any questions please contact us: flylib@qtcs.net