jason sigurdur said:
Hi, currently I have 13 Dc's using integrated AD. I just setup a ISA2004
on a 2k member server.
The ISA2004 server has a internet connection.
Could I install DNS on the ISA2004 member server,
Yes.
and have it's dns point to itself,
Not unless it can resolve "internal resource records" which
is a bad idea for such machines.
As a MEMBER machine it must be able to find the DCs to
authenticate itself -- soe that all of the features of ISA will
work, such as access security control using groups.
and have forwarder entries that would be the ISP dns?
Yes.
I have systems set up this way in fact (with my one correction):
DNS on the Gateway/Firewall/Proxy/ISA for resolving the Internet
CLIENT DNS settings for that "server" set to an INTERNAL DNS
server though (and if you are forced to use a DHCP address on
the external NIC you must override the DNS setting to avoid
multiple incompatible settings.)
Internal DNS servers forward to the "firewall DNS" server.
Firewall DNS service either recurses physically OR forwards to
the ISP
--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]