Open ports in ISA after PIX...

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Gary (myemail_at_mybusiness.com)
Date: 04/08/04


Date: Thu, 08 Apr 2004 00:01:52 GMT

Hi,
Well, I banged my head long enough. We recently had a PIX installed outside
the ISA server perimeter. It's still in Integrated mode, though it was
logging constant 14120 (I think that's it) errors, so I realized that the
PIX guy had disabled one of the NIC's so essentially packet filtering was
null and void! So, I turned off packet filtering.

Anyway, we needed to open access up to port 8051 on a website, and when we
create the protocol definition and protocol rule (in any number of
combinations; 8051 with secondary connections; one inbound and one outbound
definition, etc.) and we cannot get this site to work! In the past, opening
ports on ISA worked just fine. Now does anyone know if disabling packet
filtering would affect the ability to open ports? The PIX guy has checked
and insists that it's not being restricted through the PIX.
The site is https://massrevs.eds.com:8051/
We get a blank page. Outside the network, it loads fine.

I have tried this on machines with and without the firewall client, but
it's just a TCP port. I didn't try SecureNAT client, but I figure that
won't work, because it's no longer multihomed.

Thanks for any advice you can offer.
Gary



Relevant Pages

  • Re: Open port PIX 501
    ... :i can't open the port in my PIX. ... :I need open the port 1000 to point to the IP 10.254.254.222. ... in practice only DNS servers doing zone transfers need tcp. ... of UDP, it would be a highly unusual client which did not stick ...
    (comp.dcom.sys.cisco)
  • Re: Testing A Cisco PIX 501
    ... and it uses let's say 53 DNS port or HTTP 80 port ... Optionally write a test bench. ... I would like to, for example, be safer from trojans. ... my PIX, my PC is also cabled to the PIX and my wireless router is also ...
    (comp.security.firewalls)
  • RE: [fw-wiz] ? re: PIX port translation config
    ... however inorder to perform the port mapping you need to use the following ... Also make sure you do not have 'sysopt noproxyarp dmz' defined or the pix ... wont proxy arp on that interface. ... > and need assistence with the config. ...
    (Firewall-Wizards)
  • Re: Allowing icomming connections?
    ... >I am suspecting that one of my users is allowing an Internet IP Addy ... I see many of the below lines (PIX log) where the UDP ... Port on C.C.C.C remains constant as well, ... ports on A.A.A.A increment and that that tells you "that NAT remains active". ...
    (comp.dcom.sys.cisco)
  • Re: SBS Prem on dual homed system HELP
    ... I opened the 443 port and was not able to connect. ... PIX and I heard that it can be stopping the traffic. ... > "chris landman" wrote in message ... You could of course increase the protection by adding ISA. ...
    (microsoft.public.windows.server.sbs)