Re: SFTP & ISA 2004...



Hello Paul,

Neither ISA 2000 nor ISA 2004 can support FTPS because:

1: ISA needs to "follow the conversation" between an FTP client and
server so
that it can adjust the traffic policies to accommodate new connections as
defined
by the protocol commands between the client and server.
2: The FTP Application filter is the one responsible for accomplishing
#1
3: Outbound SSL connections (regardless of application protocol) are
invisible to ISA (as they should be; there's an implicit trust between SSL
client /
server communications)
4: Server published SSL connections are also invisible to ISA

Since #1, #3 and #4 are in direct conflict, you can't use FTPS across ISA.

(The above clarification has been provided by Jim Harrisson)


But there is some documentation on the isaserver.org website that suggests
that it
can be done, but our official stance is the above.

http://www.isaserver.org/articles/How_the_FTP_protocol_Challenges_Firewall_Security.
html

Regards,

Henk Steunenberg
"Paul S." <Paul S.@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:762CA094-2DEE-4629-AD9A-6C7B58DA1EAF@xxxxxxxxxxxxxxxx
> What is the best way to secure FTP on my ISA server for my Internet
> clients?
> Can I use SFTP or SCP? If so how can I implement this?
>
> Thanks in advance!


.



Relevant Pages

  • Re: securenat and firewall clients no internet access
    ... Why are you messing with HTTP and the HTTP Filter in an attempt to get FTP ... You need the Firewall Client running on the box that the Application ... Understanding the ISA 2004 Access Rule Processing ... Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa.clients)
  • Re: Ftp via command line
    ... In SBS2003 Server where also is the ISA 2000, ... are the client pc's that don't connect via command line. ... > longer able to connect to any external FTP Server with IE. ... Do I have to create a special rule in ISA ...
    (microsoft.public.isa)
  • Re: FTP Server setup... Im so close!
    ... > I have installed the Internet Information Services, etc, and have the FTP ... Your external client is trying to use Passive Mode. ... Since your server is behind NAT, ...
    (microsoft.public.windowsxp.network_web)
  • Re: Is this a 3-Leg Perimeter scenario?
    ... Disabled the ISA firewall client on the LAN client by opening the configure ... server, and leave LAN clients as 'normal'? ... From the network diagram, to access the FTP server from the LAN client, ...
    (microsoft.public.windows.server.sbs)
  • Re: Is this a 3-Leg Perimeter scenario?
    ... Disabled the ISA firewall client on the LAN client by opening the configure ... server, and leave LAN clients as 'normal'? ... From the network diagram, to access the FTP server from the LAN client, ...
    (microsoft.public.windows.server.sbs)