Re: trying to publish a video conferencing system

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



No. Absolutely not.
ISA is not an "open a port" appliance. You do not open ports.

You define Protocols, add them to Access Rule and then grant permissions to
users to use the Rules.

The VC system probably has to be out on the Public Internet
directly,...possibly on its own Internet connection.

I've seen all the TV commercials about all the wonderful Star-Trek-like
experiences with VC Systems with $15,000 LCD TVs mounted on the wall in the
conference room in HDTV where you can see every pimple on the CEO.

That's called Marketing (I call it Fantasy).
The unsaid motto is always "Over market -- Under Deliver"

I only deal with the real world which usually bears no resemblence.

Anyway, there is no exact standard for the design of a VC system and how it
communicates. Everyone does it "their own way" and how it works over a
firewall or a proxy, or whether it can even can work at all,...is totally
dependent on the design choices of the Developers and how well they
understand how proxys or firewalls function. I dare say that way too many
don't have a clue how proxys or firewalls function and what is required.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


"Thomas T" <ThomasT@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:5A731E3E-0784-4B49-ACF3-E49352756142@xxxxxxxxxxxxxxxx
Hi @ all,

actually I would like to try the so-called solution "open firewall".
Sounds
bad and might even be so. Please feel free to comment this attempt.
But what I really want to know now is if or how it can be accomplished to
create a publishing rule that publishes the port range from 1024 to 65535.
Of
course there exists already another rule that permits the traffic to only
come from some certain computer objects and is only for my VC system. But
when I hit the ...button my ISA 2004 immediately eats up all its paging
file
and the event log gets filled wirh entries like this:

Event type: Error
Event source: Microsoft-Firewall
categorie: Keine
Event id: 14092
Date: 15.01.2009
Time: 14:15:17
User:
Computer: ISA
Description:
Server publishing rule [VIKO Publish incoming TCP 1024-65535] has failed.
The angegebene protocol can not be uses for publishing. Standort
325.2219.4.0.2167.887.

I tried to translated the event log entry as good as possible. Sorry if it
does not match the exact message in an english system.

So any ideas concerning my server going down (only reboot with firewall
service start type "manual" helps it to come up again) when attemting to
activate this rule will be appreciated.

Best regards,
Thomas


.



Relevant Pages

  • Re: [fw-wiz] Instance Messengers and Firewalls
    ... > This has the distinct advantage that port management in the firewall is ... These protocols are proprietary and ever changing and it ... firewalls can't be trusted to have support for new IMs ...
    (Firewall-Wizards)
  • Re: Firewall madness?
    ... go via the Internet is much better served via a VPN. ... those protocols can be easily sniffed for useful information - not least ... these days to the point where only port 80 can be guaranteed to work. ... Opening up firewall ports adds an extra layer of complexity that people can do without, especially if they don't know what you're talking about. ...
    (microsoft.public.windows.server.networking)
  • RE: Detailed Port Filtering
    ... protocols, including ports used, proxying characteristics, NAT'ing ... > I'm looking at building my first IP port firewall for my Windows ... > take the server ...
    (Focus-Microsoft)
  • Re: Help! ipsec not talking IKE
    ... >> machines are listening on port 500. ... > Protocols involved in IPSec tunnel setup and connection are three. ... > the second and third may be elusive for the less robust firewall and/or ...
    (comp.os.linux.security)
  • Re: Event ID 1089 & 1090 Userenv
    ... Make sure port 123 is open on your firewall. ... net stop w32time & net start w32time ... Look in the event log and see if the error is gone. ...
    (microsoft.public.windows.group_policy)