Re: Blocking SMT Connections by clients

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I prefer dark or semi-sweet chocolate... :-)

You have two options, depending on your current policies:

1 - you're operating with an "allow all" policy. If this is the case, then anyone that happens to be in your LAN has access to
anything on the Internet. This is bad. Your ISA policies should "deny by default" and "allow only those things I want to allow".
This means a restructuring of the policy set to provide this. If you can't drop the "allow all" rule, then you'll have to create a
"deny all except" protocol rule. Use the CAS operation from option 2 and apply it in the exception portion of the deny rule. This
will have the effect of denying SMTP traffic for all except approved hosts.

2 - you're not using an "allow all policy", but your ISA SMTP access rule allows "all users" "all computers". What you should do is
create a Client Address Set for "approved mail servers" and enter only those IPs that you want to allow to send mail. Then you'll
associate this CAS with the SMTP protocol rule.

--
--
Jim Harrison [ISA SE]
Read the help, books and articles!

This posting is provided "AS IS" with no warranties, and confers no rights.

"krakan" <ctfisher@xxxxxxxxx> wrote in message news:b880c327.0504190113.60e00b5f@xxxxxxxxxxxxxxxxxxxxx
Hi guys,

Right, what we've got is a problem. Our SBS2000 server is currently
getting blacklisted at cbl.abuseat.org - it seems to us that the
problem is a compromised machine within the network sending emails
worthy of a blacklisting.

The problem is that we are the contracted IT support for this company
and this isn't out mess we have inherited. The network is regularly
used by visiting dignitaries and we hae been unable as yet to lock
this down. The number of laptops which come and go each day without
our knowledge is worrying, since none of them have AV, none of them
are firewalled most of the time and ALL of them are operated
exclusively. We cannot stop this situation right now so we must do
something to lessen the danger of it. What we want to do now is
prevent any machines on the network from connecting to remote hosts on
port 25 (with the obvious exception of the SBS server which runs
exchange) and this will have the added advantage of showing us who is
causing the problems because ISA's logs will point to it!

Problem is, I'm new to ISA server and can't for the life of me see how
to construct a packet filter to do this - block any machines INSIDE
the network from making TCP connections to REMOTE hosts on port 25..

If anyone can help I'll send them a chocolate bar.


.



Relevant Pages

  • Licensing server issue
    ... have a 2003 AD with DNS operational on another server operating in Interim ... mode (since I still have a couple of BDC NT 4.0 computers on the network). ... Pre-2000 and Post-2000 operating systems? ... When I go into terminal services licensing on the TS server (named ...
    (microsoft.public.windows.terminal_services)
  • Cant use Remote Desktop Connection
    ... My network is Win Server 2003.I'm working on Win server 2003(my operating ... I previously then used remote desktop connection to ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: Administrator handling users.
    ... group if you need them to manage network connections, ... folders/registry keys in the operating system but still not do things like ... below explains how to configure Software Restriction Policies using mostly ... and then try to prevent them from installing software with Software ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Lab OS Choices
    ... You also want to have a variety of operating ... somewhere...then you lab can grow. ... I think I'd start with an unpatched Windows 2000 server. ... wipe the drives before you mess with 'em. ...
    (Pen-Test)
  • Re: Problem with tcsh?
    ... > I downloaded Openssh today. ... > I have a problem with a special server in our college. ... > I don't have cygwin on my computer. ... My operating system is windows xp ...
    (comp.security.ssh)