الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

ما هو الفرق بين كلا من ICS/NAT/ISA

مغلق
بدأه Saatchi في 20 نوفمبر 2004 · 1 رد · 5,846 مشاهدة · في منتدى الشبكات العام
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

بسم الله الرحمن الرحيم

سوف نتكلم اليوم عن موضوع مهم في عالم الشبكات والانترنت وهو مشاركة الاتصال بالانترنت عن طريق السيرفر .

- ماهو ICS:

هي اختصار لي INTERNET CONNECTION SHARING وهي خدمة جديد في ويندوز 2000وهذه السمه تسهل من استخدام المشاركه في الاتصال الانترنت بين الاجهزه الداخليه ويفضل استخدام هذه الخدمه في المكتب المنزلي او المكتب الصغير في العمل .

كيفية تشغيل ICS في ويندوز 2000 سيرفر:

1- Start >> Settings Network and Dial-up Connections, right click the public

connection, and click on Properties.

2-Select the Sharing tab. To enable ICS, all that you have to do is to place a check mark

in the box next to Enable Internet Connection Sharing for this connection, and

click OK.

3- The message in the picture below should appear. In the lab setup, your private network

interface was configured with the static IP address of 192.168.1.201. ICS will now

automatically change your private IP address to 192.168.0.1 if you select Yes. Also, the

DHCP allocator service will be enabled and begin to lease out IP address, subnet mask,

and default gateway information to the internal clients on the 192.168.0.0/24 subnet.

The DHCP allocator service allows ICS to lease IP addresses from its default address

pool, between 192.168.0.2 and 192.168.0.254. Click Yes to enable ICS.

4-To verify this new IP Address, go to Start Run, type in cmd and click OK to open the

command prompt. From within the command prompt, type in ipconfig and press

Enter. The IPCONFIG utility will give you some basic output about the IP

configurations of the interfaces on SRV-1. As you see, there are 2 network interfaces on

SRV-1, private and public. Your private IP address has been changed to use 192.168.0.1

since you enabled ICS on SRV-1. Just type in Exit and press Enter to close the

command prompt after you have verified this configuration.

5- Client computers will now need to be configured to obtain an IP address automatically

from the DHCP allocator service.

Client-1, go

to Start Settings Network and Dial-up Connections, right click the Local Area

Connection and click on Properties. On the General tab, highlight Internet Protocol

(TCP/IP) and click Properties.

6- On the General tab select Obtain an IP address automatically and click OK. Client-1

will now start broadcasting for an IP address on your network. Since the DHCP

allocator service was automatically enabled, Client-1 should be able to obtain an IP

address

7- To check Client-1’s IP address go to Start Run from the desktop, type in cmd and

click OK to open the command prompt. From within the command prompt type in

ipconfig and press Enter.

===========

-ما هو NAT:

NAT is a new feature in Windows 2000. It is an internet standard that is offered in

Windows 2000 Server to provide small to medium sized networks access to the Internet,

while maintaining their private class IP structure on the internal network. It is scalable and

offers many configuration options that Internet Connection Sharing (ICS) does not, such as

multiple public IP addresses and custom configurations within DHCP. You can have as

many private IP addresses as you want that will all “map” through the same public IP

address, providing access to the Internet. As mentioned above, NAT is an Internet

standard, not just a Windows 2000 feature, and is therefore found in many different firewall

and Internet connection products. Within Windows 2000, NAT is only offered in Windows

2000 Server, NOT Professional. NAT is very similar to ICS, but is a step-up for companies

that need a little more flexibility in their Internet solution.

==========

-ما هو ISA:

Internet Security and Acceleration Server (ISA Server) is Microsoft’s first “true” firewall

product replacing its predecessor Proxy Server 2.0. ISA Server is a substantial upgrade to

the Proxy Server 2.0 product and has received great reviews, including the much-coveted

ICSA Certification, which puts firewalls through a difficult battery of tests before endorsing

a product.

ISA Server not only acts as a firewall preventing unauthorized access but also as an

“acceleration” server, delivering content from the Internet to network users much faster

than is normally delivered. When deploying ISA Server, you have the flexibility to install it

in Firewall mode (security only), Cache Mode (Internet acceleration only) or Integrated

Mode, where you can utilize all of the features of ISA Server.

-فوائد وسمات خادم ISA:

-Multi-layer Firewall functionality – filtering by user or data (application layer),

circuits (Session layer) and packets (Network layer). NAT, ICS and many other

firewall products ONLY filter packets at the network and transport layers.

-Intrusion Detection – this feature, which was created by the security company

Internet Security Systems, Inc. (ISS), allows the ISA Server to proactively monitor

incoming traffic and stop network attacks in their tracks.

-SecureNAT – allows non-Microsoft operating systems, such as UNIX and

Macintosh clients, to securely connect through the ISA Server by just configuring a

default gateway.

-Integrated Virtual Private Network (VPN) – ISA Server makes setting up a VPN

(between two sites or for a remote user) very simple and very secure. A wizard walks

you through the process, making setup a snap.

-Server Publishing – this feature is the same concept that is offered in NAT & ICS,

but is behind a more secure firewall product and with much greater flexibility.

-Active Directory Integration – ISA Server can fit right into the Active Directory

(but doesn’t have to) allowing you to specifically control exactly which users can

access what type of content. For example, you might want to allow the Marketing

department (or an individual user in Marketing) access to the Internet while blocking

members of the sales group from accessing the Internet. All access to the Internet

can be determined by the same user account that the user logs on to the network

with.

-Web Page Caching – ISA Server sets aside part of your server’s hard drive to be

used as a web cache. Any time a user accesses a web page, that web page will be

cached locally on the ISA Server. If another user in the company then attempts to

access the same web page, the ISA Server will deliver the page from its cache

contents rather than going out to the Internet. You can even set the ISA Server to

actively cache popular sites at night when users are not accessing the network.

-Reporting & Monitoring – the reports that can be generated by ISA Server are

fabulous. You can look at the most accessed sites, the most active users, what

protocols they used, and even how long they were connected. The best part is that

traditionally information like this has to be “translated” from cryptic text files that

the firewall product produced, while ISA provides nice easy to read web based

reports that can be printed out for further examination.

وبنهاية الدرس ارجوا اني قد وفقت بتوصيل المعلومه وشكرا

إذا كنت قد استطعت رؤية ما هو أبعد من أن يراه الاخرون ، فذلك لأنني وقفت على أكتاف عمالقة سبقوني .

#2

معلومات اضافيه حوله الموضوع :

ISA:

Microsoft Internet Security and Acceleration ISA

مع زيادة إستخدام شبكة الانترنت في الشبكات المحلية سواء لربط الشبكات الفرعية أو وصول الزبائن أو نشر التطبيقات ، كان لابد من وجود برنامج حماية متكامل يمنع كل الاخطار المحتملة من الانترنت ،

وبرنامج Microsoft Internet Security and Acceleration ISA هو من البرامج المثالية لذالك ، فهو يقدم ادوات وقدرة كبيرة لحل كثير من المشاكل الامنية على الشبكة وتحكم شبه كامل بكل منافذ الدخول والخروج من الشبكة ، وبلإضافة لذالك فهو يعمل كبروكسي للشبكة لوصلها بالانترنت بطريقة سريعة حيث يمثل مصدر للطلبات لكل زبائن الشبكة حيث يعرض الطلبات بطريقة دينميكية من ذاكرة الخادم بدل الانترنت ، ويكون بذاك اسرع من الوصول للانترنت بصورة مباشرة

خادم Microsoft Internet Security and Acceleration ISA يعطي قيمة كبيرة للشبكة وقدرة على التحكم لمن يطمعون في الوصول إلى نتائج أمن مرضية ، فهو برنامج يعمل على كل الحجوم من الشبكات ، شبكة مكتب صغير ، فرع شركة ، مواقع تجارة الاكترونية ، مزوّدو خدمات الإنترنتِ (مزوّدو خدمة الإنترنت) وشركات إستضافة مواقع ويبِ .

خادم ISA يمكن أن ينشر كبرنامج حماية يقوم مقام بوابة بين الانترنت والشبكة الداخلية مع سياسات وصول متكاملة تجعل المدراء يتبعون منهج دقيق في تدقيق وإعطاء ومنع الوصول غير المخول وكشف كل محتوى خبيث .

تثبيت البرنامج ISA

تثبيت البرنامج هو في غاية السهولة لمن له خبرة بسيطة في التعامل مع برامج وتطبيقات مايكروسوفت ، فبعد أن تكون قد اشتريت النسخة الخاصة بك عليك بتفحص المتطلبات الرئيسية لتركيب الخادم على شبكتك ، ومن أهم ذالك مايلي :-

جهاز بنتيوم 2 - 300 megahertz حد أدنى

نظام التشغيل يجب أن يكون أحد النظم التالية Microsoft Windows 2000 Server مع Service Pack 1 أو أعلى , Microsoft Windows 2000 Advanced Server مع Service Pack 1 أو اعلى, أو Microsoft Windows 2000 Datacenter Server

256 MB من الـ memory

20 MB من المساحة الحرة على القرص الصلب

كرت شبكة يكون متوافق مع الويندوز 2000 للوصول للشبكة الداخلية

مقطع يكون بنظام NTFS

إذا كنت ستركب البرنامج كـ array وتريد تطبيق سياسة الأمن المتقدم يجب أن تكون الشبكة وخادم الشبكة عليه الدليل النشط Active Directory

نوعية التثبيت

لنوعية التثبيت أهمية كبيرة في تثبيت البرنامج وذالك بإختيار صفة خادم ISA هل سيكون خادم مستقل ام سيكون array ، والفرق بين الخادم المستقل والـ array هو الـ array يتم التعامل مع نظام الشبكة كـ ميدان في دليل نشط ويأخذ كل بيانات المستخدمين من قاعدة بيانات ذالك الدليل ، وفي الخادم المستقل stand-alone server لا يتطلب وجود ميدان ولا دليل نشط ، وإذا كانت هذه اول مرة تثبت فيها خادم ISA على الجهاز وكنت تريد التثبيت يكون كـ array فيجب عليك أولاً ان تثبت ISA Server schema وهو برنامج صغير يثبت في الدليل النشط مرة واحدة فقط وليس عليك تثبيته مرة أخرى حتى لو حذفت خادم ISA من الشبكة واردت تثبيته مرة ثانية .

فإذا كان لديك ميدان مع دليل نشط Active Directory لا تركب البرنامج ( خادم ISA ) إلا كـ array ، وإن كان بإمكانك تثبيته كـ stand-alone server

خصائص التثبيت

يمكن التثبيت على ثلاث أشكال وهي على التوالي كما يلي :-

firewall

cache

integrated

إذا كنت قد استطعت رؤية ما هو أبعد من أن يراه الاخرون ، فذلك لأنني وقفت على أكتاف عمالقة سبقوني .

هذا الموضوع مغلق.

مواضيع مشابهة