Re: packet filters just dont apply?

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: A Klimkin (aklimkin)
Date: 05/27/04

  • Next message: Jim Harrison [MSFT]: "Re: Publishing A web Server"
    Date: Thu, 27 May 2004 10:17:49 +0400
    
    

    Just to be "totally" accurate ;)
    In fact packet filters are able to affect clients traffic, but only if they
    are the deny packet filters. If you create packet filter that drops any
    tcp/25 packet in both directions, your internal clients (and the server, of
    course) will not be able to send or get SMTP traffic at all.
    In contrast with static IP packet filters that are the only way to allow the
    ISA server itself access the internet, clients internet access is allowed
    via dynamically created packet filters that are based on protocol and
    site&content rules.

    Regards,
    Andrew

    "Phillip Windell" <@.> wrote in message
    news:usW3BT0QEHA.3660@TK2MSFTNGP10.phx.gbl...
    > "Enyalius" <anonymous@discussions.microsoft.com> wrote in message
    > news:12c6201c44342$dda5ce30$a301280a@phx.gbl...
    > > From what I have read packet
    > > filters should apply to all computers behind the ISA
    > > firewall, but apparently they dont.
    >
    > No they don't. Machines behind ISA are controlled by the other "services"
    > of ISA which are 100 times more secure than just simple packet filters.
    > Packet filters are the lowest & weakest level of security in an ISA
    > environment, hence are only used in the much smaller "realm" of
    Applications
    > on the ISA box itself or on the DMZ interface of a Tri-Homed DMZ.
    >
    > --
    >
    > Phillip Windell [MCP, MVP, CCNA]
    > www.wandtv.com
    >
    >
    >


  • Next message: Jim Harrison [MSFT]: "Re: Publishing A web Server"

    Relevant Pages

    • Re: AV Update on Server
      ... how're your clients configured to successfully download AV ... > If your client computers are web proxy clients AND protocol is HTTP or FTP ... > connectivity for the ISA server itself. ... > I'd like to add here that creating static packet filters weakening your ISA ...
      (microsoft.public.isa)
    • SMTP stopped working!
      ... I was fiddling around with my ISA Protocol Rules and Packet Filters and I ... SecureNAT clients). ...
      (microsoft.public.isa.configuration)
    • Re: Lost with ISA...
      ... > I thought the protocol rules were applied on top of> the Packet Filters. ... the clients would only have acces to a subset of what's> available on the server itself... ... >> The server doesn't have the Firewall Client>> installed, that is the reason why it needs packet filters. ...
      (microsoft.public.backoffice.smallbiz2000)
    • RE: ISA Clients
      ... >I am having trouble with ISA. ... My server can take ... >advantage of the packet filters in ISA, but the clients ... Packet filters normally only apply to the server itself. ...
      (microsoft.public.windows.server.sbs)
    • Re: Lost with ISA...
      ... >> the Packet Filters. ... the clients would only have acces to a subset of what's ... >>> The server doesn't have the Firewall Client ... I don't really need to ftp from the server but I don't ...
      (microsoft.public.backoffice.smallbiz2000)