The remainder of this post will give step-by-step instructions for setting up the ISA configuration.
When you have decided on the address range you want to use for the Macs, follow the instructions in the Configuring DHCP Reservations in SBS 2003 post to create the reservations for the Macs. This does two things. First, it guarantees that the Macs will fall into this address range. Second, it guarantees that no other systems will fall into the address range.
Now, to configure ISA:
- Open the ISA Server Management Console.
- Expand you server name and click Firewall Policy.
- In the right-hand pane, click the Toolbox tab.
- Expand Network Objects, and then click
Computer Sets.
- Right-click on Computer Sets and select New
Computer Set.
- Enter a name for the set in the Name field (something
like "Mac Group").
- Click Add, then select Address Range.
- Enter a name for the range in the Name field (something
like "Mac Range").
- Enter the starting and ending addresses for the range to
match the DHCP reservations you created in DHCP.
- Click OK when the range is correct.
- Click OK to save the Computer Group.
- In the right-hand pane, click the Tasks tab.
- Click Create a New Access Rule.
- Enter a name for the Access Rule (i.e. "Mac Internet
Access Rule") and click Next.
- In the Rule Action page, click Allow
and then click Next.
- In the Protocols page, select All outbound
traffic if you don't want to restrict Internet access
for the group, or select Selected Protocols or
All outbound traffic except selected if you want to
restrict the types of traffic for the group. If you choose
either of the latter options, you will need to click Add
and select the protocols you wish to allow or deny and add
them to the list.
- Click Next to continue.
- In the Access Rule Sources page, click Add.
- Expand Computer Sets, and select the group you
just created.
- Click Add, then click Close.
- When you see that the correct computer group is listed,
click Next.
- In the Access Rule Destinations page, click
Add.
- Expand Networks, and select External.
- Click Add, then click Close.
- When you see External listed, click Next.
- Click Next to accept the All Users
group.
- Click Finish to create the rule.
- Click Apply above the Firewall Policy tab.
- Click OK when the changes have completed.
Now you will need to reboot the Mac and make sure it receives the correct address from the DHCP server. If for some reason the Mac does not receive the correct address, you can manually set the IP address to match the number it should have received from the DHCP server.
At this point, the Mac should have access to the Internet based on the restrictions you placed in the rule, if any. Note that you will not need to configure the Mac web browsers to use the proxy server with this configuration.