Re: Acces to HTTP over non standard ports



For outbound traffic tunneled to external HTTPS sites, ISA Server limits the
port ranges by default to the standard ports. There is a script available to
extend this range to allow access to SSL sites on alternate ports. See
Managing Tunnel Port Ranges at http://go.microsoft.com/fwlink/?linkid=58801
for more information. Remember that after such a link is established,
traffic is not inspected.

--
Rayne Wiselman [MSFT]
This posting is provided "AS IS" with no warranties, and confers no rights

"Luis Arellano" <LuisArellano@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:777FF711-49DC-4A08-A8F4-3F6CB06B75E7@xxxxxxxxxxxxxxxx
Hello

I have an ISA Server 2004 where all clients are using Secure NAT to access
the internet, I've defined an access rule to allow HTTP and HTTPS to the
external connection and everything works fine.
The problem comes in when some sites that use non standard ports can't be
accessed (i.e. http://www.company.com:5467).
I've been adding this ports to the User-Defined protocols and adding this
protocol definition to the access rule, but I'm not happy with this
solution
because there are plenty of sites on the Internet that use so many
different
ports that I'll end up adding thousands of User-Defined protocols.
Is there a way to allow HTTP trafic to any port, but prevent the use of
such
ports by any other protocol?
I'll appreciate your help.

Best Regards
Luis Arellano


.



Relevant Pages

  • Re: RWW with no https
    ... SBS's ports. ... two are unrelated systems, i.e., SBS for one domain, Kerio for another. ... Or dump Kerio Mail Server since you have the same capabilities in Exchange ... I can not use https. ...
    (microsoft.public.windows.server.sbs)
  • Re: RWW with no https
    ... SBS's ports. ... two are unrelated systems, i.e., SBS for one domain, Kerio for another. ... Or dump Kerio Mail Server since you have the same capabilities in Exchange ... I can not use https. ...
    (microsoft.public.windows.server.sbs)
  • Re: warum PnP Dienst =?ISO-8859-1?Q?=FCber_Netzwerk=3F?=
    ... Bei VPNs hast Du immer das Problem, dass Du nicht sicherstellen kannst, dass nur der Client in das Netz kommt. ... Da sind einzeln absicherbare Protokolle wie RPC over HTTPS, ... Auf Anwendungsseite wurde reagiert und die Applikationen benutzten nur noch bestimmte, fest definierbare Ports. ...
    (microsoft.public.de.german.win2000.networking)
  • Re: countermeasure against attacks through HTML shared files
    ... looks at attacks through HTML shared files in Web ... acmemail on https URLs, and that meant either using wildcard ... flaws in acmemail) or different ports. ...
    (Bugtraq)
  • more SSL ports
    ... non-default ports. ... I have not heard that is required for Web Publishing ... Internal web server will work on ... http (not https). ...
    (microsoft.public.isa)