Re: Firewall client behavior with a modem



"UnderCoverGuy" <UnderCoverGuy@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:BB551755-D275-4787-A9CD-628018C7F20D@xxxxxxxxxxxxxxxx
I have to wonder - why would or how does the firewall client impact a
local
workstation modem connection? Is there a way to exclude the modem from
the
local workstation firewall client configuration?

The Firewall Client works as a Winsock Layer Service Provider (LSP) so it
operates at a much higher level than the modem connection. Therefore the
Firewall Client will "see" the traffic long before it ever gets down to the
level where it gets passed accross the modem. Since the Destination is not
"on the LAN" the Firewall Client interprets it to be "out on the internet"
and sends it out the ISA,...where it obviously and subsequently fails.

You have a couple options:

1. If the Dialup is using TCP/IP and you know what the IP Range that is
being used by the connection,...you can add the IP Range to the Addresses
Tab of the Internal Network Definition.

2. Or you can teach the user to right-click on the Firewall Client Icon by
the Clock,...set it to disabled,...use the Dialup connection,...when
finished with the Dialup Connection go back and re-enable the Firewall
Client.
We have always used this one in similar situations.

3. Find another way to use the product that currently uses the Dialup. A
Dialup is a "cave-man" technology from back when we used pull-ropes and a
choke to start computers. The company the product comes from needs to come
out of the dark ages and come up with a new method of making their services
available to you.

Also,..before anyone asks,...VPN will not solve the problem,...it will be
the *same* problem because VPN is also a Dialup based technology. It
doesn't matter if it is a real dialup adapter (modem) or a virtual dialup
adapter (VPN),...it is still a Dialup Adapter,...the Virtual one just uses
an IP# in place of the phone number but in the end it is operated by the
same principles.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.mspx

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------


.



Relevant Pages

  • Firewall Client installed - cannot use Dialup via modem?
    ... Desktop computer uses LAN to access the internet, but uses a dialup ... the dialup to the bank will not ... DUN/RAS says that the modem is in use. ... Disabling the Firewall Client also results in same message. ...
    (microsoft.public.isa)
  • Firewall Client installed - cannot use dialup via modem?
    ... Desktop computer uses LAN to access the internet, but uses a dialup ... the dialup to the bank will nto ... DUN/RAS says that the modem is in use. ... Disabling Firewall Client also results in same message. ...
    (microsoft.public.isaserver)
  • Re: Networking
    ... Internet in the future, cable, DSL, or wireless, etc., all may soon be ... My general recommendation is to keep the modem, the router, and the WiFi ... will support dialup, ...
    (microsoft.public.windowsxp.network_web)
  • Re: Dialup PPPD with Network Manager in F12
    ... My internet access is provided by 56kbit/s dialup modem on /dev/ttyS0 ... I currently have dialup pppd working in Fedora 9. ... Network Manager Applet 0.7.996. ...
    (Fedora)
  • Re: 56K modem up vs. pppoe adsl dialup
    ... > and pppoe adsl dialup in ppp.conf file. ... Currently I m using adsl modem ... set filter dial 0 permit tcp dst eq domain ...
    (comp.unix.bsd.freebsd.misc)

Loading