IP Options filtering



Hi,

This seems to be the last "black area" for me in the ISA 2004 configuration.
Actually I have several questions concerning the options configured in
“<Server>/Configuration/General/Define IP Preferences” dialog.

Let me qualify a situation. I have “IP Options filtering” enabled. “Deny
packets with the selected IP options” mode is chosen. Several options like
option 68 (Time Stamp) are selected as it is done by default.

Did I get it right that ISA server does block any inbound or outbound IP
packets that have mentioned options filled?

I tried to find some information on the purpose for these IP Options and I
did find some. For example on
http://www.networksorcery.com/enp/protocol/ip.htm

Could anybody comment?
1. Why do I see only a very limited list of IP options in IP Options
filtering?
2. Why are other options listed as undefined and untitled when I ask to list
them anyway?
3. What is a possible reason to prohibit IP options? Are there any standard
situations in which I should change the default settings?
4. I have found only a single criterion for the default setting. Those
options that have variable length by definition are banned by default. Is
this the reason?
5. Is there a way to see the effect of the IP Options filtering? Is it
logged in the firewall log? How do I distinguish these records?


Thanks in advance.
--
Eugene U. Zverev,
System Administrator
.



Relevant Pages

  • IP Options filtering
    ... This seems to be the last "black area" for me in the ISA 2004 configuration. ... packets with the selected IP options” ... What is a possible reason to prohibit IP options? ... situations in which I should change the default settings? ...
    (microsoft.public.isa)
  • Re: Unable to view usual/php websites in IE help!
    ... I don't want to fiddle with the settings too much. ... Enable Service Name Action LAN Server IP address WAN Users Log ... packets transmitted, 0 packets received, 100% packet loss ... >> I've not been able to view websites from certain domains just lately - ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • RE: Problems with ISA2004 during SP1 upgrade
    ... Microsoft CSS Online Newsgroup Support ... | well until I got to the ISA 2004 portion. ... | "The wizard could not export your settings for the ISA 2000 Server. ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA 2000 Problem - SBS2003
    ... identification" option after you gather the ISA info? ... please click the Settings button ... Stop the Web Proxy service. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Integrated authentication and IE proxy settings
    ... ISA server for all requests. ... Check your Netowrks/Internal/Properites/Web Browser settings. ... IE Options/Advanced/Enable Integrated Windows Authentication is ...
    (microsoft.public.isa.clients)