Petri IT Knowledgebase Forums
 

Petri.co.il forums Home Forums Start Page Forums Frequently Asked Questions FAQ Member List Members List
Go Back   Petri IT Knowledgebase Forums > Server Operating Systems > SBS 2000 / 2003
Petri.co.il is happy to award auglan the title of Most Valuable Member !!!
Register Calendar Calendar Search Petri IT Knowledgebase Forums Search Todays Posts Today's Posts Mark Forums Read

Notices

How to remove the double-NAT on SBS2000

How to remove the double-NAT on SBS2000

this thread has 3 replies and has been viewed 4718 times

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 14th June 2005, 15:56
-string- -string- is offline
Casual
Casual
 
 Join Date: Mar 2005
  6 month star 12 month star
 Location: Pom now living in Sydney, Aus
 Posts: 18
 Reputation: -string- is on a distinguished road (10)
Default How to remove the double-NAT on SBS2000

Currently my clients SBS2000 server is setup in the standard configuaration with 2 x NICs (1xLAN & 1xExternal). The SBS2000 Server is Routing between the 2 networks, thus creating a double-NAT. Clients on the internal LAN use the SBS internal NIC as their DG and Proxy Server. + are Windows Firewall Clients.

I need to remove the 2nd NIC on the SBS2000 to create a single NAT'ed internal network. Central office are planning Site to Site VPN tunnels in near future between Cyberguard firewalls and want to be able to ping all hosts across the tunnels. I still want the SBS server to handle DHCP, DNS, Web Proxy. Just not to Route!.

Heres my list so far, but I guess Im missing some ISA, SBS, Windows Firewall specific stuff.

Firewall
Repatch Cyberguard onto main switch
Readdress Cyberguard Firewall so in internal network range
Edit PAT rules on Cyberguard to direct 25 & 443 to the LAN interface on the SBS2000

SBS2000 Server -
Backup ISA config and System State!
Disable SBS2000 External NIC
Change the Default Gateway of the LAN side nic to the new firewall
Change and the DG of clients in the DHCP scope to point to the newly addressed Firewall

Any help muchly appreciated!!
Cheers
String
Sydney Aus
  #2  
Old 17th June 2005, 19:45
teiger teiger is offline
Moderator
 
 Join Date: Mar 2005
  6 month star 12 month star
 Location: Tzurit, Israel
 Posts: 2,687
  Send a message via MSN to teiger
 Reputation: teiger is a splendid one to beholdteiger is a splendid one to beholdteiger is a splendid one to beholdteiger is a splendid one to beholdteiger is a splendid one to beholdteiger is a splendid one to beholdteiger is a splendid one to behold (757)
Default RE: How to remove the double-NAT on SBS2000

You may have a major problem here as your DNS/AD/DHCP are all linked to your internal NIC (default 192.168.16.2).
Here is my list:
Make sure you have a good backup
Make sure you have another good backup
Disabale one NIC
Set the desired fixed IP on the NIC that is still enabled
Delete and reinstall DNS as an AD linked zone
Rerun the ICW wizard
__________________
TIA

Steven Teiger [SBS-MVP(2003-2009)]
http://www.wintra.co.il/
  #3  
Old 18th June 2005, 15:41
-string- -string- is offline
Casual
Casual
 
 Join Date: Mar 2005
  6 month star 12 month star
 Location: Pom now living in Sydney, Aus
 Posts: 18
 Reputation: -string- is on a distinguished road (10)
Default RE: How to remove the double-NAT on SBS2000

Thanks teiger..
Actually it went just like clockwork.. Running thru the ICW after disabling the external nic worked a treat. All I had to do is manually change the DG in the DHCP scope to point to the router not the SBS Server. I also checked thru DNS carefully however no changes needed as all SRV records point to hostnames and not IP addresses.

Thanks for your reply.
Best
String

  #4  
Old 18th June 2005, 16:00
teiger teiger is offline
Moderator
 
 Join Date: Mar 2005
  6 month star 12 month star
 Location: Tzurit, Israel
 Posts: 2,687
  Send a message via MSN to teiger
 Reputation: teiger is a splendid one to beholdteiger is a splendid one to beholdteiger is a splendid one to beholdteiger is a splendid one to beholdteiger is a splendid one to beholdteiger is a splendid one to beholdteiger is a splendid one to behold (757)
Default RE: How to remove the double-NAT on SBS2000

Please make sure your DHCP points all stations' DNS setting to the SBS server IP and that you are now in a less secure setup as you no longer have the SBS server firewall offering your LAN any protection. Check out
http://www.smallbizserver.net/Default.aspx?tabid=156
for further details.
__________________
TIA

Steven Teiger [SBS-MVP(2003-2009)]
http://www.wintra.co.il/
Closed Thread


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Moving E2K from SBS2000 to E2K Enterprise fhubbard SBS 2000 / 2003 1 13th October 2005 09:42
remove subdomain from AD domain marcop Active Directory 3 17th December 2004 17:38
DNS,DHCP,Active directory and NAT in same machine prashanth Windows Server 2000 / 2003 6 29th October 2004 22:31
ST510 Router without NAT yanivi20 DSL, Cable, and other Broadband Issues 1 20th June 2004 18:22
Second CPU Problem on the SBS2000 Help Please ! messenger Windows Server 2000 / 2003 13 31st March 2004 07:58


All times are GMT +3. The time now is 09:33.

Steel Blue 3.5.4 vBulletin Style ©2006 vBEnhanced
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
 

Valid XHTML 1.0!   Valid CSS!

Copyright 2005 Daniel Petri