CSS can't talk to array members in workgroup config



We have a single NIC ISA 2006 SP1 server sitting on a DMZ network of our PIX.
The CSS is on the internal network. I have verified the PIX is not the
problem, or at least is most likely not the problem. I used the FWEngMon.exe
tool and allowed access between the CSS and Array member, then the CSS was
able to see the Array memeber, no problem. What's strange is Array member
has no problem seeing the CSS and is able to make changes to the
configuration. This is usally the other way around (harder to get from DMZ
to inside that vise versa), but futher proves the PIX isn't the problem since
it allows traffic from the inside to the less trusted network by default, but
blocks everything from the less trusted to the internal side.

The array member seemed to be blocking some sort of RPC traffic (stuff on
port 1035), but I couldn't come up with a rule to allow incoming tcp 1035
traffic (am I retarded?), but could make only an Outgoing rule (wtf?).

I'm assuming 1035 is being used for authentication, I've opened these ports
on webservers on the DMZ to the DCs before.
.



Relevant Pages

  • RE: Configuration for SMTP in DMZ-PIX
    ... check the PIX access rule and the network relationship from internal to DMZ. ... I am able to test the SMTP server from the internet thru the PIX and also ...
    (microsoft.public.isa.configuration)
  • RE: [fw-wiz] pix nat question
    ... You just have to think like a PIX. ... If you want it to appear this way on the inside network, you need to create a global for the DMZ network, and then a static, like so: ... > statics with acl's ...
    (Firewall-Wizards)
  • PIX firewall config question
    ... I'm not sure if this is even possible with a PIX, ... is a private 192.168.1/24 network and the outside is a public network ... Is it possible for outside and DMZ to be on the same IP ... everything is done through translations (port translation, ...
    (comp.security.firewalls)
  • Re: Design Help
    ... The second PIX can just be put on the network and the new DMZ ... connections we need can be hooked up that way. ...
    (comp.dcom.sys.cisco)
  • RE: Problems configuring Integrated NLB on 2004 Ent Array
    ... each and what is the type of network they each represent (external, ... teeming to work you need to enable NLB on all interfaces on all array servers ... (excluding the intra array communication network) ... the CSS should be able to ...
    (microsoft.public.isa.enterprise)

Loading