Re: VPN to ISA server, can't FTP through it



Thanks! this looks like the info I need to track it down now, still
having my Tee at home but as soon as I get to the office, (5 minute
walk to next room ;-) I'll have a look.

Thanks again for going through the filters etc. Not sure why I didn't
filter on the FTP server first. I was trying client and I'm unsure
what the client IP address might be, but I do know what the server IP
is an once I concentrate on that server and FTP I should see the
client IP as well and can go from there.

Cheers
Bill


On 10 Mar, 17:31, "Phillip Windell" <philwind...@xxxxxxxxxxx> wrote:
"jogdial" <jogd...@xxxxxxxxx> wrote in message

news:492cb425-7f3e-4b52-b58e-dd9e76d41ad2@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Hi, thanks for the reply.  I've been trying to watch the monitoring,
but so far haven't seen anything coming through.  This is a VERY busy
firewall, I've tried not putting any filters on the monitoring at all
thought and I don't see any rule being applied to the FTP upload, or
FTP connection for that matter.

Set the Log filter to show traffic where the Destination IP# is the FTP
Server.

Repeat the monitoring with the filter set to Client IP# as the FTP Server.

 As the requests are coming and going
through a VPN, will they not be encrypted anyway?

No. The Tunnel terminates "at" the ISA,...it doesn't go "through it".  It is
normal traffic going through the ISA.

publishing new web applications mostly.  So, if there isn't a specific
rule for FTP to this specific server, and it's coming from a VPN, is
there still an application filter for all traffic?

The VPN would use a "routed" relationship instead of NAT,...but the Access
Rules still control the traffic flow.  If the VPN is a Remote Access VPN
then the Source Network is "VPN Clients",....if the VPN is a Site-2-Site VPN
then the Source Network would be the "created" Network that ws created when
the Site-2-Site VPN was setup.  I believe yours is a Site-2-Site from what
you earlier post says.  Protocols are all treated as "outbound" no matter
what.

You should already have an Access Rule in place or nothing would be working
over the VPN at all,...so just make sure that Rule allows FTP, has the FTP
Application Filter applied and has the Filter's "read-only" box *unchecked*.

Typically the Rule would look something like this:

Source Network: Internal, <VPN Network Name>
Destination Network: Internal, <VPN Network Name>
Protocol: <whatever>
        Configure FTP, "Read-only" Unchecked
Users: <whatever>

--
Phillip Windellwww.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processinghttp://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-...

Microsoft Internet Security & Acceleration Server: Partnershttp://www.microsoft.com/isaserver/partners/default.mspx

Microsoft ISA Server Partners: Partner Hardware Solutionshttp://www.microsoft.com/forefront/edgesecurity/partners/hardwarepart...
-----------------------------------------------------  

.



Relevant Pages

  • Re: [Full-disclosure] Remote Desktop Command Fixation Attacks
    ... This set of steps is redundant in many places, and it's also enormously expensive, since you're using no less than three different expensive bits of networking hardware (AP, PIX, VPN Concentrator), in addition to a bunch of x86 server hardware, windows server licenses, and at least one ISA license. ... Your computers necessarily don't have full access to your network infrastructure when they aren't logged on, so GPOs, software updates, etc can't be applied at the times you want them to be applied. ... Turning on, enabling, and implementing every possible security setting and device you think of is not defence in depth, and will probably only have two effects - your users won't use your wireless network, and you'll burn so much cash you won't have any left to spend on *useful* security measures. ...
    (Full-Disclosure)
  • Re: VPN with SBS 2003 (not R2) and DSL.
    ... Reading property value for VPN returned OK ... Reading VPN Server Name returned OK ... identical network cards. ... it seems doubtful that SBS will work properly with two NICs ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN Connection Problems
    ... Note that we are able to successfully VPN into the office. ... to browse the network, RDP to the server or even ping the server. ... > This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN clients unable to connect to other resources.
    ... on the SBS 2003 server just not sure where to go for help on it. ... Next time I'm at my home PC, I'll VPN in and see what IP info I'm getting ... client PC on your LAN, you should be able to do so from a remote VPN client, ... get the network path was not found. ...
    (microsoft.public.windows.server.sbs)
  • Re: RRAS as VPN Server Configuration Questions...
    ... Ethernet adapter VPN: ... Name resulotion on VPN Connection issues on DC, ISA, DNS and WINS server as ... Issue in a VPN client ... ... How to Setup Windows, Network, VPN & Remote Access on ...
    (microsoft.public.win2000.ras_routing)