Òë×ÔThomas Shinder ¡°Using ISA Server 2004 Network Templates to Automatically Create Access Policy: The Edge Firewall Template¡±£¬¼ÓÒÔÕûÀíÐÞ¸Ä

ǰÑÔ£ºISA Server 2004ÔÚ·À»ðǽÅäÖúÍÌṩµ½InternetµÄ°²È«·ÃÎÊÉϱȹýÈ¥ÓÐÁ˺ܴóµÄÌá¸ß£¬Ò²±È¹ýÈ¥¸üÈÝÒ×ʹÓá£Èç¹ûÄã¹ýÈ¥Ôø¾Ê¹ÓùýISA Server 2000£¬ÄÇôÄãÔÚÅäÖÃISA Server 2004ÉÏ»áºÜÇáËÉ£¬ÁíÍ⣬ISA Server 2004ÌṩÁËÍøÂçÄ£°å£¬¿ÉÒÔÈÃÄãÇáËɵÄÉèÖ÷À»ðǽ²ßÂÔ£¬ÕâÆªÎÄÕ½«ÒÔ×î³£¼ûµÄ±ßÔµ·À»ðǽģ°å½øÐÐÅäÖõĽéÉÜ¡£
¡¡
ISA Server 2004·À»ðǽ¾ßÓÐ5¸öÔ¤¶¨ÒåµÄÍøÂçÄ£°å£º
±ßÔµ·À»ðǽ£»
3Öܳ¤µÄÍøÂ磨°üº¬DMZ£¨Í£»ðÇø£©£©
ǰ¶Ë·À»ðǽ£»
±³²¿·À»ðǽ£»
µ¥ÍøÂçÊÊÅäÆ÷£»
ISA Server 2004¹ÜÀí¿ØÖÆÌ¨ÌṩÁËһЩͼƬ£¬ÈÃÄã¿ÉÒÔ¸üÄÜÇåÎúµÄÁ˽âÕâЩÃû×ÖËù´ú±íµÄÒâ˼¡£ÔÚÕâÆªÎÄÕÂÖУ¬ÎÒÃǽ«Ïêϸ½éÉÜ×î³£ÓõıßÔµ·À»ðǽģ°å¡£Õâ¸öÄ£°åÊÇÖ¸ISA Server 2004´¦ÓÚInternet±ßÔµ£¬ÓµÓÐÒ»¸ö½ÓÈëµ½InternetµÄÍⲿ½Ó¿ÚºÍÒ»¸ö½ÓÈëµ½LanµÄÄÚ²¿½Ó¿Ú¡£ÀýÈçÎÒÃÇ×ʹÓÃµÄ¿í´ø²¦ºÅ£¬È»ºó°ÑISA Server 2004×÷ÎªÍø¹Ø£¬¾ÍÊôÓÚÕâÖÖÄ£°å¡£
ÔÚÄãÕýÈ·µÄÅäÖÃÍøÂç½Ó¿Úºó£¬¿ÉÒÔʹÓÃÕâ¸öÄ£°å£¨Çë×¢Ò⣺һ¶¨ÒªÕýÈ·µÄÅäÖÃÍøÂç½Ó¿Ú£©¡£ÖÁÓÚÈçºÎÅäÖÃÍøÂç½Ó¿Ú£¬Çë²ÎÔÄISA Server 2004¿ìËÙÅäÖÃÖ¸ÄÏ¡£
ÏÂͼÊÇISA Server 2004¶Ô±ßÔµ·À»ðǽģ°åµÄ˵Ã÷ͼ¡£Internal Network ÔÚISA Server 2004ºóÃæ£¬²¢ÇÒÊܵ½ISA Server 2004µÄ±£»¤¡£Local HostÖ¸µÄÊÇISA Server 2004·À»ðǽ±¾Éí¡£External Network (Internet)Ö¸µÄÊÇûÓбíÏÖÔÚInternet networkºÍVPN¿Í»§ÍøÂçµÄÆäËûÍøÂç¡£VPN¿Í»§ÍøÂçÊÇÓÉISA Server 2004·À»ðǽ¶¯Ì¬½¨Á¢µÄÍøÂ磬ÀïÃæ°üº¬ÁËVPN¿Í»§µÄµØÖ·¡£
¡¡

¡¡
±ßÔµ·À»ðǽģ°åΪÁË×öÁËÁ½¼þÖ÷ÒªµÄÊÂÇ飺
¶¨ÒåÁËÄÚ²¿ÍøÂçµÄIPµØÖ·£»
½¨Á¢ÁËÁ½¸ö°üº¬·À»ðǽ²ßÂÔÔÚÄڵķÃÎʲßÂÔ¡£
ÄÚ²¿ÍøÂçÊÇÔÚÄãÔËÐбßÔµ·À»ðǽÏòµ¼Ê±»áÅäÖõÄIPµØÖ·¼¯¡£Õâ¸öÏòµ¼Ò²»áÔÊÐíÄãÑ¡Ôñ¿ØÖÆÄÚ²¿ÍøÂç¡¢VPN¿Í»§ÍøÂçºÍÍâ²¿ÍøÂçÖ®¼äͨÐÅÁ÷Á¿µÄ·À»ðǽ²ßÂÔ¡£
Ïòµ¼ÔÊÐíÄã´ÓһЩ²»Í¬µÄ·À»ðǽ²ßÂÔÖнøÐÐÑ¡Ôñ£¬Ô¤¶¨ÒåµÄ·À»ðǽ²ßÂÔ°üÀ¨£º
½ûÖ¹·ÃÎÊ£ºÕâ¸ö·À»ðǽ²ßÂÔ½ûֹͨ¹ý·À»ðǽµÄËùÓзÃÎÊ£¬Ö»ÓÐÔÚÄãÏëÊÖ¶¯¶¨ÒåÈ«²¿µÄ·À»ðǽ²ßÂÔʱʹÓá£
²»ÄÜ·ÃÎÊISPÍøÂçµÄ·þÎñ£ºÕâ¸ö·À»ðǽ²ßÂÔ×èÖ¹³ýÁË·ÃÎÊÍøÂç»ù´¡·þÎñ£¨ÈçDNS£©ÍâµÄËùÓÐͨ¹ý·À»ðǽµÄ·ÃÎÊ£¬Ö»ÓÐÔÚÄãÏëÊÖ¶¯¶¨Òå¿Í»§·ÃÎʲßÂÔµÄʱºò²ÅʹÓÃÕâ¸öÑ¡ÏʹÓÃÕâ¸ö²ßÂÔ£¬½«»á½¨Á¢ÏÂÁвßÂÔ£º
DNS£ºÔÊÐíÄÚ²¿ÍøÂç¡¢VPN¿Í»§µ½InternetµÄDNSÇëÇó£»
ÊÜÏÞµÄWeb·ÃÎÊ£ºÕâ¸ö·À»ðǽ²ßÂÔÔÊÐí·ÃÎÊWebÕ¾µã£¬µ«ÊDz»ÄÜ·ÃÎÊÆäËû·þÎñ¡£Ö»ÓÐÔÚÄãÏëÖ»ÔÊÐíWeb·ÃÎÊʱʹÓã¬Äã¿ÉÒÔÐÞ¸ÄËüÒÔÔÊÐíÆäËû·þÎñµÄ·ÃÎÊ¡£Õâ¸ö²ßÂÔÐèÒªÄÚ²¿ÍøÂçÖÐÓÐDNS·þÎñÒÔ±ã½âÎöWeb·þÎñÆ÷µØÖ·¡£Èç¹ûÐèÒª·ÃÎÊInternetµÄDNS·þÎñ£¬ÄãÒ²ÐèÒªÐÞ¸ÄÕâÌõ²ßÂÔ¡£Èç¹ûÄãʹÓÃÕâ¸öÄ£°å£¬½«»á½¨Á¢ÒÔϲßÂÔ£º
1¡¢Web access £ºÔÊÐí´ÓÄÚ²¿ÍøÂç¡¢VPNÍøÂçµ½InternetµÄHTTP¡¢HTTPS¡¢FTP·ÃÎÊ£»
2¡¢VPN£ºÔÊÐí´ÓVPN¿Í»§¶Ëµ½ÄÚ²¿ÍøÂçµÄËùÓÐÐÒéµÄ·ÃÎÊ¡£
ÊÜÏÞµÄWebºÍISPÍøÂç·þÎñµÄ·ÃÎÊ£ºÕâ¸öÄ£°åºÍÉÏÃæµÄÏà±È£¬Ö»ÊǶàÁ˸öÔÊÐíÏòInternet·¢ËÍDNSÇëÇó¡£Ê¹ÓÃÕâ¸öÄ£°å£¬ÒÔϹæÔò½«»á½¨Á¢£º
1¡¢Web access £ºÔÊÐí´ÓÄÚ²¿ÍøÂç¡¢VPNÍøÂçµ½InternetµÄHTTP¡¢HTTPS¡¢FTP·ÃÎÊ£»
2¡¢DNS £º ÔÊÐí´ÓÄÚ²¿ÍøÂç¡¢VPN¿Í»§µ½InternetµÄDNSÇëÇó£»
3¡¢VPN£ºÔÊÐí´ÓVPN¿Í»§¶Ëµ½ÄÚ²¿ÍøÂçµÄËùÓÐÐÒéµÄ·ÃÎÊ¡£
ÎÞÏÞÖÆµÄInternet·ÃÎÊ£ºÔÊÐíͨ¹ý·À»ðǽµÄËùÓÐInternet·ÃÎÊ£¬·À»ðǽ½«×èÖ¹Internetµ½±»±£»¤ÍøÂçµÄ·ÃÎÊ¡£Äã¿ÉÒÔÐÞ¸ÄËüÒÔ×èÖ¹Ä³Ð©ÍøÂç·ÃÎÊ¡£Ê¹ÓÃÕâ¸öÄ£°å£¬½«½¨Á¢ÒÔϲßÂÔ£º
1¡¢Internet access £ºÔÊÐí´ÓÄÚ²¿ÍøÂç¡¢VPN¿Í»§µ½InternetµÄËùÓÐÐÒ飻
2¡¢VPN£ºÔÊÐí´ÓVPN¿Í»§µ½ÄÚ²¿ÍøÂçµÄËùÓÐÐÒ飻
¡¡
Õâ¸öµØ·½ÐèÒª³ÎÇåµÄÊÇDNS²ßÂÔ°üº¬ÔÚËüÃÇÖ®¼äµÄһЩ²ßÂÔÖС£ÄÚ²¿µÄDNS·þÎñÆ÷ÐèÒªÄÜ·ÃÎʵ½InternetµÄDNS·þÎñÆ÷»òÕßISPµÄת·¢Æ÷²ÅÄÜÕý³£¹¤×÷£¬²¢²»ÊÇ˵ÄÚ²¿ÓÐÁËDNS·þÎñÆ÷¾Í²»ÐèÒª¿ª·ÅÏòÍⲿDNS·þÎñµÄ·ÃÎÊ¡£
Èç¹ûÄãÊdzõѧÕߣ¬½¨ÒéÄãʹÓÃÎÞÏÞÖÆµÄInternet·ÃÎÊÄ£°å£»µ±Äã±È½ÏÊìÏ¤ÍøÂçºÍISA Server 2004ºó£¬ÔÙʹÓÃÆäËû¸üÓÐÏÞÖÆµÄÍøÂç·ÃÎÊ¿ØÖÆ¡£
Ö´ÐÐÒÔϲ½ÖèÒÔʹÓñßÔµ·À»ðǽģ°åÀ´½¨Òé·À»ðǽ·ÃÎʲßÂÔ£º






ÍøÂçÄ£°åÏòµ¼ÔÚ·À»ðǽ²ßÂÔÖн¨Á¢ÁËÁ½¸ö²ßÂÔ£¬Äã¿ÉÒÔͨ¹ýMicrosoft Internet Security and Acceleration Server 2004¹ÜÀí¿ØÖÆÌ¨À´»Ø¹ËËûÃÇ¡£

Action: Allow
Protocols: All Protocols
From: Internal and VPN Clients networks
To: External
Condition: All Users
ÕâÌõ²ßÂÔÔÊÐíÄÚ²¿ÍøÂçºÍVPN¿Í»§ÍøÂç·ÃÎÊInternet£¬×¢ÒâºÍISA Server 2000Ïà¶Ô±ÈµÄÊÇ£¬VPN¿Í»§Ò²¿ÉÒÔͨ¹ýISA Server 2004·À»ðǽÀ´·ÃÎÊInternet¡£ÔÚISA Server 2000ÖУ¬Äã²»Äܽ«VPN¿Í»§ÉèÖÃΪSecureNAT¿Í»§¶Ë£¬ËùÒÔ£¬Äã±ØÐ뽫VPN¿Í»§ÉèÖÃΪFirewall¿Í»§¶Ë£¬²ÅÄÜÈÃËü·ÃÎÊInternet¡£ÔÚISA Server 2004ÖУ¬ÒѾ½â¾öÁËÕâ¸öÎÊÌ⣬VPN¿ÉÒÔ¶Ë¿ÉÒÔ×÷ΪSecureNAT¿Í»§¶ËÀ´·ÃÎÊInternet¡£
Action: Allow
Protocols: All Protocols
From: VPN Clients network
To: Internal
Condition: All Users
ÕâÌõ²ßÂÔÔÊÐíVPN¿Í»§·ÃÎÊÄÚ²¿ÍøÂçµÄËùÓÐ×ÊÔ´¡£
Äã¿ÉÒÔÔÚһ̨ÄÚ²¿¿Í»§¼ÆËã»úÉϲâÊÔеķÀ»ðǽ²ßÂÔ¡£ÔÚһ̨ÄÚ²¿¿Í»§¼ÆËã»úÉÏÖ´ÐÐÒÔϲ½Ö裺

| ×ÔÓÉ¹ã¸æÇø |
| ¡¡ |