Re: Secondary Protocols

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: J.C. Hornbeck [MSFT] (jchornbe_at_online.microsoft.com)
Date: 03/23/04

  • Next message: J.C. Hornbeck [MSFT]: "Re: web browsing"
    Date: Tue, 23 Mar 2004 08:36:56 -0600
    
    

    Hi Zaidi,
    Are you by chance referring to Secondary Connections? If so one example
    would be active mode FTP. When a client makes an active mode FTP connection
    to an FTP server, the client makes the initial control channel connection,
    then the FTP server initiates a new session to the client for the data
    channel. That secondary connection initiated by the FTP server is treated by
    the ISA Server as any other outbound client connection and would require
    both a site and content rule and a protocol rule. Passive mode FTP would not
    require a site and content rule since the secondary connection (the data
    channel) is initiated by the client.

    There's a general article on FTP and ISA that discusses this at
    http://www.isaserver.org/articles/How_the_FTP_protocol_Challenges_Firewall_Security.html.

    -- 
    J.C. Hornbeck, MCSE
    Microsoft Product Support
    NOTE: Please reply to the newsgroup and not directly to me. This allows
    others to add to and benefit from these threads and also helps to ensure a
    more timely response. Thank you!
    This posting is provided "AS IS" without warranty either expressed or
    implied, including, but not limited to, the implied warranties of
    merchantability or fitness for a particular purpose.
    "admin" <anonymous@discussions.microsoft.com> wrote in message
    news:11feb01c4109e$e82c48b0$a101280a@phx.gbl...
    > Hi all,
    >
    > What is "secondary Protocols"? I encounter this term many
    > times in documents related to Firewall Client. Can
    > someone guide me to a link talking about this?
    >
    > Thanks in advanced
    > zaidi
    

  • Next message: J.C. Hornbeck [MSFT]: "Re: web browsing"

    Relevant Pages

    • RE: SBS 2003 Premium: how to allow FTP .EXE downloads
      ... Disable the problematic client XP firewall, ... click to check the "Hide All Microsoft Services" ... Is the FTP server on SBS? ... Download the file from the following URL: ...
      (microsoft.public.windows.server.sbs)
    • Re: Telnet/ftp problems SBS2000
      ... | through the server to get internet access everything works. ... | client uses an internet backup company to backup his really vital data, ... I understand that you cannot use ftp service to ... the connection can be established ...
      (microsoft.public.windows.server.sbs)
    • Directory Traversal Vulnerabilities in FTP Clients
      ... Vendors informed individually and through CERT/CC ... FTP clients, including those that may be embedded in web clients, can ... filename that the client requests. ... or the associated CERT vulnerability ...
      (Bugtraq)
    • [VulnWatch] Directory Traversal Vulnerabilities in FTP Clients
      ... Vendors informed individually and through CERT/CC ... FTP clients, including those that may be embedded in web clients, can ... filename that the client requests. ... or the associated CERT vulnerability ...
      (VulnWatch)
    • [NEWS] Directory Traversal Vulnerabilities in FTP Clients
      ... vulnerable to certain directory traversal attacks by modified FTP servers. ... file/directory permissions and the privilege level of the client. ... A malicious server could potentially overwrite key files to cause a denial ... your vendor, or the associated CERT vulnerability note, if your product is ...
      (Securiteam)