Packet filter just won't work.

From: Kurt Drefs (meklaar777_at_yahoo.com)
Date: 04/23/04


Date: Fri, 23 Apr 2004 10:15:35 -0600

My config is this. Internet>PIX>2 ISA Loadbalanced with Rainwall>internal. I
am trying to have the PIX use an internal Syslog server. I have created a
filter to allow bidirectional UDP 514 for Syslog

Allow PIX Syslog Inbound\outbound
 Description : Allows UDP 514 in for PIX syslog logging
 Enabled : True
 Filter Mode : Allow
 Filter Type : Custom
 Protocol : UDP
 Direction : Inbound and Outbound
 Local Port : 514
 Remote Port : 514
 Local Computer Filter Applies to : Default External IP
 Remote Computer Filter Applies to : All Remote Computers

The messages are not getting through. I have tried trying a rule for each
individual ISA server applying it to a static external IP,
stopping/restarting services, rebooting the servers, and it just won't work.

IPPEXTD log
2004-04-23 15:54:38 172.16.1.1(PIX) 192.168.27.35(Syslog address)Udp 514 514
BLOCKED 172.16.1.12 (an external isa address)
When I shut one ISA server down the other just takes over blocking the
messages.
Any input would be appreciated.
Thanks
Kurt



Relevant Pages

  • Re: POP virtual server problem
    ... Glad its working and yes the ISA "built in filters" have been an issue ... I also want to re-iterate that allowing your Exchange Server to act as a ... Please do not respond to me directly by email but only in the newsgroups so ... > but I created a new filter identical to the one ISA on SBS2k had and now ...
    (microsoft.public.backoffice.smallbiz)
  • Re: Connector for POP3 Mailboxes will not receive mail
    ... Your going to need a packet filter in ISA to allow outbound traffic on port ... Since you haven't run ICW, ... You may want to reboot the server after you create the filter. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: ISA 2004 Error 14060
    ... If that script solves your problem, you'll want to reinstall ISA via Add/Remove Programs and choose "repair" when prompted. ... That seems like a problem with your DNS filter. ... After disabling the DNS filter this way, reboot your server and see if you ... > stop and restart the Firewall service. ...
    (microsoft.public.isaserver)
  • Re: Mails auf Linux auf Spam untersuchen
    ... Filter ... Einstellung funktioniert der IMF in Kombination mit den anderen Boardmitteln ... bietet sich entweder ein Relay Server an, ... Arbeitszeit / Kosten wie der Isa kostet. ...
    (microsoft.public.de.german.exchange2000.general)
  • Re: How to allow port 514?
    ... a packet filter allows traffic into the server itself. ... If you want to run your syslog on the server you would use a packet filter. ... In ISA Policy Elements, right click Protocol Definitions, ... in Publishing, right click Server ...
    (microsoft.public.windows.server.sbs)