RE: NAT publishing works, but command netstat doesnt show all the listning ports

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Kenny Wood (Kenwood_at_online.microsoft.com)
Date: 08/23/04


Date: Mon, 23 Aug 2004 01:17:18 GMT

Hello Ivan,

When you say perimeter, what do you mean? Typically a perimeter network, means a third leg
in a DMZ. If this is the case, then the request is simply routed.

If it is published, then you may see that the system is listening on 0.0.0.0, which is all IP
addresses.

Thank you for your post.

Kenny Wood
CISSP, MCSE (+S, +M)
PSS Security
Microsoft Corporation

-- 
This posting is provided "AS IS" with no warranties, and confers no rights. Use of included 
script samples are subject to the terms specified at http://www.microsoft.com/info/cpyright.htm 
Note:  For the benefit of the community-at-large, all responses to this message are best 
directed to the newsgroup/thread from which they originated.  
--------------------
| From: "Ivan Mckenzie Rodriguez" <imck@inerza.com>
| Subject: NAT publishing works, but command netstat doesnt show all the listning ports
| Date: Tue, 17 Aug 2004 22:56:11 +0100
| Lines: 21
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Outlook Express 6.00.2800.1437
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1441
| Message-ID: <OmZNYRKhEHA.2916@TK2MSFTNGP12.phx.gbl>
| Newsgroups: microsoft.public.isa.publishing
| NNTP-Posting-Host: 10.red-81-33-218.pooles.rima-tde.net 81.33.218.10
| Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP12.phx.gbl
| Xref: cpmsftngxa06.phx.gbl microsoft.public.isa.publishing:2613
| X-Tomcat-NG: microsoft.public.isa.publishing
| 
| Hi everyone,
| 
| I have a NAT relation from my perimeter interface to my external interface.
| I have published telnet, ftp and https from a server on the perimeter
| network with the Create New Server Publishing Rule Wizard.
| 
| I can connect from a computer on the external network to all 3 published
| ports.
| 
| What I dont understand is that if I run command netstat -ano on the ISA2004
| server I cant see the perimeter interface listening for ports telnet or
| https. I can only see the perimeter interface listening on port ftp.
| 
| How does it work then?
| 
| Thanks a lot,
| 
| Ivan
| 
| 
| 
| 


Relevant Pages

  • Re: Publish webserver in perimeter
    ... Web publishing is supported for NAT relationships. ... ISA Server Product Team ... My perimeter network is set up with a range of public Ip ...
    (microsoft.public.isaserver)
  • Re: NAT publishing works, but command netstat doesnt show all the listning ports
    ... Kenny Wood wrote: ... Typically a perimeter ... | network, means a third leg in a DMZ. ... || network with the Create New Server Publishing Rule Wizard. ...
    (microsoft.public.isa.publishing)
  • Re: How can I open port 99?
    ... - The destination network in the Perimeter ... >> I have installed a source code tracking system called Test Track Pro. ... >> ISA server? ... >> I'm using a ISA system with 3 network cards. ...
    (microsoft.public.isa.configuration)
  • Defining a Protocol
    ... I just installed ISA2004 and SP1 and started to setup a rule to allow port ... 9200 from an external source to talk to computer on my perimeter network. ... to a computer in my perimeter, selected the new protocol that I created ...
    (microsoft.public.isa)
  • Defining Protocols
    ... I just installed ISA2004 and SP1 and started to setup a rule to allow port ... 9200 from an external source to talk to computer on my perimeter network. ... to a computer in my perimeter, selected the new protocol that I created ...
    (microsoft.public.isa.configuration)