Welcome to TechNet Blogs Sign in | Join | Help

802.1Q and ISA Server

Many folks have asked the question: "Does ISA Server support VLANs?".  The quick and dirty answer to this question is "nope - don't gotta."  The longer, more useful answer is "ISA isn't aware of 802.1Q."

The core of the answer to this question lies in the fact that ISA Server is a layer-3 (IP) firewall, and that for IPv4 only (we'll discuss that in another blog).  802.1Q VLANs are a layer-2 network management mechanism.  Thus, ISA is blissfully unaware of this protocol. 

The good news is that if your NIC manufacturer has designed the NIC and provided drivers to support 802.1Q, Windows can use 802.1Q to build more logical interfaces, and thus ISA can actually see and use many more interfaces than you have PCI slots in the machine.  I personally have produced 11 separate interfaces in my lab ISA to separate the various test scenarios.  This machine only had two physical NICs, though.  802.1Q is kewl fer shur!

Various restrictions prevent me from recommending specific NIC manufacturers, but there is one thing that remains true; you won't get this capability from the $5 adapter you find at your local CompAmWe stores.  You'll have to buy a server class NIC and you'll have to make sure the NIC manufacturer provides drivers capable of *properly* supporting 802.1Q.

You'll greatly improve your chances of succeeding here if you start with devices listed in the Windows Catalog (formerly the Hardware Compatability Lab): http://www.windowsservercatalog.com/.  Make sure you have the latest drivers; check the manufacturer's website as soon as you get the adapter.

Jim Harrison (ISA SE)

Published Wednesday, October 04, 2006 12:08 AM by isablog

Comments

# Thomas Shinder Blog » Blog Archive » Does the ISA Firewall Support VLAN Tagging?

# re: 802.1Q and ISA Server

Thanx for the pingback, Tom...

Use http://isatools.org/stuff/isasefw.scrn.png if you want to see a screenshot of my lab ISA with 11 (count 'em) interfaces, of which only two are physical...

Sunday, October 08, 2006 11:21 PM by isablog

# re: 802.1Q and ISA Server

Stupid question. How did you get 11 interfaces with only 2 NICs?

Tuesday, October 10, 2006 1:40 PM by Patrick

# re: 802.1Q and ISA Server

Does Isa support NLB and Vlan Tagging on the same NIC?

Monday, November 27, 2006 5:43 AM by Iñaki Baranda

# re: 802.1Q and ISA Server

I get 11 NICs because the NICs we bought include support for 802.1Q-tagged frames and the software the NIC manufacturer provides creates a logical interface for each VLAN in which the physical NIC participates.

Obviously, I can't get into manufacturer specifics, but the question to ask is:

"does this NIC manyufacturer provide software that allows the driver to create logical NICs from 802.1q VLAN associations?"

If they're confused by this question, the answer is likely to be "no".

Friday, March 16, 2007 2:33 PM by Jim Harrison (ISA SE)

# re: 802.1Q and ISA Server

"Does Isa support NLB and Vlan Tagging on the same NIC?"

As I stated in the original blog, ISA has (and needs) no support for VLANs.

This is strictly the purview of the NIC drivers and software.

Friday, March 16, 2007 2:34 PM by Jim Harrison (ISA SE)

# re: 802.1Q and ISA Server

Hi,

Maybe Inaki asked the wrong question: Will VLAN tagging and NLB work on the same interface?

My understanding is that due to NLB limitations/design, these 2 features cannot be configured on the same NIC. Or am I mistaking?

Monday, April 23, 2007 10:52 AM by Enrico Klein

# re: 802.1Q and ISA Server

No; ISA has no support for VLANs and therefore has no support statement regarding the combination for NLB + 802.1Q VLANS.  This is strictly the NLB team's support area.

The answer from them is "NLB does not support Q-tagged frames on the same interface where NLB is operating."

Tuesday, May 08, 2007 12:49 PM by isablog

# re: 802.1Q and ISA Server

Please just tell us which lan card you are using in your example. Why would I spend the next 2 weeks researching which lan card will do this, when you could just tell me?

Wednesday, August 15, 2007 4:31 PM by which lan card?

# Windows 2008 y las Vlan...

Hace un par de semanas conocí ( vía MSN) a Elias , por un post que hice y desaparecí al mismo tiempo

Saturday, July 26, 2008 11:30 PM by El Ddaz

# Windows 2008 y las Vlan...

Hace un par de semanas conocí ( vía MSN) a Elias , por un post que hice y desaparecí al mismo tiempo

Saturday, July 26, 2008 11:36 PM by David Daniel Arroyo Zari - Ddaz -

# re: 802.1Q and ISA Server

therefore has no support statement regarding the combination for NLB + 802.1Q VLANS.

Tuesday, May 26, 2009 2:00 AM by HD Video Converter
Anonymous comments are disabled
 
Page view tracker