Microsoft KB Archive/837833

= How to publish a DNS server in Internet Security and Acceleration (ISA) Server 2006 or in ISA Server 2004 =

Article ID: 837833

Article Last Modified on 12/4/2007

-

APPLIES TO


 * Microsoft Internet Security and Acceleration Server 2004 Standard Edition
 * Microsoft Internet Security and Acceleration Server 2006 Enterprise Edition
 * Microsoft Internet Security and Acceleration Server 2006 Standard Edition
 * Microsoft Internet Security and Acceleration Server 2004 Enterprise Edition

-





For a Microsoft Internet Security and Acceleration Server 2000 version of this article, see 291662.

IN THIS TASK

 * INTRODUCTION
 * Create a server publishing rule
 * REFERENCES



INTRODUCTION
This article describes how to publish a DNS server by using Microsoft Internet Security and Acceleration (ISA) Server 2006 or by using ISA Server 2004.

Create a server publishing rule
To publish a DNS server that is hosted on the ISA Server computer or that is hosted on the internal or the perimeter network, create a new server publishing rule. To do this, follow these steps:
 * 1) Start the ISA Server Management tool.
 * 2) Expand  , where   is the name of your ISA Server computer, and then click Firewall Policy.
 * 3) Click the Tasks tab, and then click Create a New Server Publishing Rule.

Note In ISA Server 2006, click Publish Non-Web Server Protocols.
 * 1) In the Server publishing rule name box, type a descriptive name for this rule, and then click Next.
 * 2) In the Server IP address box, type the IP address of the DNS server that you want to publish, and then click Next.

Note If the DNS server is hosted on the ISA Server computer, type the IP address of the ISA Server computer's internal interface.
 * 1) In the Selected protocol list, click DNS Server, and then click Next.
 * 2) In the Listen for requests from these networks list, click to select the check box of the network that you want ISA Server to listen on for DNS queries. For example, to enable external users to submit queries to your DNS server, click to select the External check box.

Note If you want to specify a particular IP address that ISA Server listens on, click Address, click Specified IP addresses on the ISA Server computer in the selected network, click the IP address that you want ISA Server to listen on, click Add>, and then click OK.
 * 1) Click Next, and then click Finish.
 * 2) Click Apply to save your changes and to update the firewall policy, and then click OK.

To help prevent DNS zone transfers to unauthorized DNS servers, configure the DNS server properties to allow zone transfers only to specific DNS servers. You can also modify the server publishing rule to restrict traffic to a specific computer. To do this, follow these steps:
 * 1) Click the Firewall Policy tab, right-click the new server publishing rule that you created, and then click Properties.
 * 2) Click the From tab, click Anywhere, click Remove, and then click Add.
 * 3) In the Network entities dialog box, click New, and then click Computer.
 * 4) In the Name box, type a descriptive name for the new computer rule element, type the computer's IP address in the Computer IP Address box, and then click OK.
 * 5) Expand Computers, click the new computer element that you created, click Add, and then click Close.
 * 6) Click OK.
 * 7) Click Apply to save your changes and to update the firewall policy, and then click OK.

In some scenarios, you may have to modify your firewall rule hierarchy if an earlier firewall rule blocks the DNS traffic before this firewall rule is processed. To move a firewall rule up in the hierarchy, right-click that rule, and then click Move Up. When you have finished modifying your firewall rule hierarchy, click Apply to save your changes and to update the firewall policy. Click OK.

back to the top

