Re: Packet filter just won't work.

From: Tristan Kington [MSFT] (tristank_at_online.microsoft.com)
Date: 04/24/04


Date: Sat, 24 Apr 2004 15:17:28 +1000

You use packet filters to provide access to the ISA Server itself, and the
DMZ (perimeter) network.

Looking at your requirements, I think you're trying to route through the ISA
Server to the internal network from the external network; that won't work,
any external net to internal net traffic must be published.

Instead, delete the packet filter and try creating a Server Publishing rule
with a Receive Send protocol definition for the protocol you want published.

-- 
This posting is provided "AS IS" with no warranties, and confers no rights.
"Kurt Drefs" <meklaar777@yahoo.com> wrote in message 
news:eDx524UKEHA.2024@TK2MSFTNGP11.phx.gbl...
My config is this. Internet>PIX>2 ISA Loadbalanced with Rainwall>internal. I
am trying to have the PIX use an internal Syslog server. I have created a
filter to allow bidirectional UDP 514 for Syslog
Allow PIX Syslog Inbound\outbound
 Description : Allows UDP 514 in for PIX syslog logging
 Enabled : True
 Filter Mode : Allow
 Filter Type : Custom
 Protocol : UDP
 Direction : Inbound and Outbound
 Local Port : 514
 Remote Port : 514
 Local Computer Filter Applies to : Default External IP
 Remote Computer Filter Applies to : All Remote Computers
The messages are not getting through. I have tried trying a rule for each
individual ISA server applying it to a static external IP,
stopping/restarting services, rebooting the servers, and it just won't work.
IPPEXTD log
2004-04-23 15:54:38 172.16.1.1(PIX) 192.168.27.35(Syslog address)Udp 514 514
BLOCKED 172.16.1.12 (an external isa address)
When I shut one ISA server down the other just takes over blocking the
messages.
Any input would be appreciated.
Thanks
Kurt


Relevant Pages

  • Re: ISA 2006 Basic Configuration
    ... Troubleshooting Client Authentication on Access Rules in ISA Server 2004 ... Microsoft Internet Security & Acceleration Server: ... Microsoft ISA Server Partners: Partner Hardware Solutions ... The routing table for the network adapter Internal ...
    (microsoft.public.isa.configuration)
  • Re: ISA 2006 Basic Configuration
    ... Does the AD/DNS Server have the ISP's DNS properly configured as a Forwarder? ... Microsoft Internet Security & Acceleration Server: ... Microsoft ISA Server Partners: Partner Hardware Solutions ... The routing table for the network adapter Internal includes IP address ranges that are not defined in the array-level network Internal, ...
    (microsoft.public.isa.configuration)
  • Re: March 29, 2006 total eclipse - IT admins WORST NIGHTMARE
    ... and NewsProxy is the answer for that. ... > Comcast news server. ... simply filters out what I dont want on the network. ... NewsProxy - Network level killfile and content filter for Usenet. ...
    (comp.security.firewalls)
  • Re: I dont uderstand ISA Logs
    ... This really has not much todo with the ISA server, ... Generally user requests are to pages like: ... When you are programming an ISAPI filter, you should try to catch the ...
    (microsoft.public.isa)
  • Re: SMTP Filter, blocking inbound spoof addresses
    ... But this is missing the point of wanting the ISA’s SMTP ... Filter to check the inbound traffic for only valid traffic. ... My current config on the server is not allowing relaying of spam as ... the inside firewall (the ISA server) and not reach the network, after all, is ...
    (microsoft.public.isa.configuration)