ISA 2004 Publishing Rules

From: NIC Student (nospam_at_nospam.land)
Date: 12/30/04


Date: Thu, 30 Dec 2004 09:19:43 -0800

Hi,

I have a mystery that is driving me crazy. Hopefully someone can give me a
hand.

Situation:

ISA2004 isolates several secure domain servers from the rest of our network.
192.168.1.62=ISA external address on our main subnet.
10.150.0.1=ISA internal address on protected subnet
10.150.0.4=Protected server

We use two ports for our application: TCP 1240 and TCP 1188.
I created two server publishing rules, one for each. An example:
Listener-external ip 192.168.1.62, protocol tcp 1240 inbound, from anywhere,
to 10.150.0.4, schedule always.

I run the FWENGMON.EXE and it shows creation objects: Source 0.0.0.0 Dest
10.150.0.4:1240. From that, I assume that ISA is listening.

I turn on monitoring>logging and begin logging:

clientip 192.168.1.12, dest ip 192.168.1.62, tcp 1240, unidentified ip
traffic, denied connection, default rule, source net external, dest net
localhost.

My network rule says to route external network to internal network (no nat).

I have no other rules that deny tcp 1240.

Any help is appreciated!!

-- 
Scott Baldridge


Relevant Pages

  • Re: SCO 5.0.7 MP5 network hung up
    ... instead of the server I was reloading. ... The system was still inaccessible via the network. ... It is probably the case, with some minor exceptions, that whatever `tcp ... is still seeing the streams memory leakage with its NIC on IRQ11. ...
    (comp.unix.sco.misc)
  • RE: [Full-Disclosure] TCP port 25 traffic?
    ... I'm not running a mail server anywhere on my network. ... TCP port 25 traffic? ...
    (Full-Disclosure)
  • Re: Diskless client problems
    ... I have fixed the problems with all the error messages, The server was ... network is now flying. ... I still know why it is not using tcp, but this is not so important now. ... >> When running NFS over a wireless link for example, ...
    (Debian-User)
  • Re: Short guide to secure network
    ... UPD is required and what needs to be opened on the server and what needs to ... be opened on the client. ... > I am going to secure my network with tcp/ip and ICF on all my computers. ... > Is there a short guide to the basic ports, both TCP and UDP to keep open. ...
    (microsoft.public.windows.server.security)
  • Re: Fully parallel Scheme-based language w/ evaluator
    ... Windows Server 2003 and networks in simple - and irreverent - terms. ... If networking really is a big deal, ... Concepts and Terminology in Part I, and The Design and Deployment of Network ...
    (comp.lang.misc)