Quote Originally Posted by cheyenne1212
As SirDice said using your DNS/AD machine as a ISA server is a very very bad idea. You want your AD/Internal DNS server behind the firewall, you don't want it to be the firewall lol.


As they said its no problem to have 2 firewalls like that, just set up your IP's and routing appropriately, and your good to go.
yea but the first firewall will make a good protection from any outside threat and my dns will be behind this firewall and the second is just made as a prison gate to deny access to certain sites and messengers from inside and its not a problem if its installed on the DNS server, the gateway of the users and the DNS will be the same and they cant pass to the first firewall without passing by the internal firewall.