Re: VPN to ISA server, can't FTP through it



"jogdial" <jogdial@xxxxxxxxx> wrote in message
news:492cb425-7f3e-4b52-b58e-dd9e76d41ad2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi, thanks for the reply. I've been trying to watch the monitoring,
but so far haven't seen anything coming through. This is a VERY busy
firewall, I've tried not putting any filters on the monitoring at all
thought and I don't see any rule being applied to the FTP upload, or
FTP connection for that matter.

Set the Log filter to show traffic where the Destination IP# is the FTP
Server.

Repeat the monitoring with the filter set to Client IP# as the FTP Server.

As the requests are coming and going
through a VPN, will they not be encrypted anyway?

No. The Tunnel terminates "at" the ISA,...it doesn't go "through it". It is
normal traffic going through the ISA.

publishing new web applications mostly. So, if there isn't a specific
rule for FTP to this specific server, and it's coming from a VPN, is
there still an application filter for all traffic?

The VPN would use a "routed" relationship instead of NAT,...but the Access
Rules still control the traffic flow. If the VPN is a Remote Access VPN
then the Source Network is "VPN Clients",....if the VPN is a Site-2-Site VPN
then the Source Network would be the "created" Network that ws created when
the Site-2-Site VPN was setup. I believe yours is a Site-2-Site from what
you earlier post says. Protocols are all treated as "outbound" no matter
what.

You should already have an Access Rule in place or nothing would be working
over the VPN at all,...so just make sure that Rule allows FTP, has the FTP
Application Filter applied and has the Filter's "read-only" box *unchecked*.

Typically the Rule would look something like this:

Source Network: Internal, <VPN Network Name>
Destination Network: Internal, <VPN Network Name>
Protocol: <whatever>
Configure FTP, "Read-only" Unchecked
Users: <whatever>


--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.mspx

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------


.



Relevant Pages

  • Re: VPN to ISA server, cant FTP through it
    ... filter on the FTP server first. ... what the client IP address might be, but I do know what the server IP ... through a VPN, will they not be encrypted anyway? ... then the Source Network would be the "created" Network that ws created when ...
    (microsoft.public.isa.vpn)
  • Re: VPN and access rights
    ... What about FTP over SSL? ... that is not secure at all. ... Give him the 'dial in' right that is needed for VPN. ... >> computers within the network! ...
    (microsoft.public.windows.server.sbs)
  • Re: Whats Best Way to Get Data from Web Server to Private Network?
    ... >> possibilities come to mind ftp, or setup a VPN to the server. ... >something like vpn, ssl, or sftp to encrypt the traffic between the two. ... >you could put the web server inside the private network. ...
    (comp.security.misc)
  • Re: Whats Best Way to Get Data from Web Server to Private Network?
    ... >> possibilities come to mind ftp, or setup a VPN to the server. ... >something like vpn, ssl, or sftp to encrypt the traffic between the two. ... >you could put the web server inside the private network. ...
    (comp.security.misc)
  • Re: Binding FTP Server Service to Internal Network Card
    ... used to establish the VPN tunnel should be present in the AD. ... you can use some 3rd-party FTP applications such as WS_FTP. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)

Quantcast