Re: Why is ISA letting outside clients into DHCP and WINS?

From: Phillip Windell (_at_.)
Date: 07/30/04


Date: Fri, 30 Jul 2004 08:08:22 -0500


"Arch Willingham" <arch@tuparks.com> wrote in message
news:ONXUA4cdEHA.3616@TK2MSFTNGP10.phx.gbl...
> 1. VPN log does not show anyone coming in.
> 2. There is no wireless access point inside the building (however the
actual
> site is serviced via a wireless device off the side of a mountain).
> 3. The building has been locked for ten days with no people in the
building.
>
> I am confused to say the least!

Well those are still the general areas you will have to look. It can't come
through ISA because:

1. ISA is not a router and would not route from the outside to the inside.

2. ISA will not pass such requests from the outside to the inside unless the
WINS and DHCP were somehow "published" to the outside. That could never
happen by accident and would even be very difficult to do on purpose.

3. The Internet routing system is incapable of routing to your private
addresses.

4. DHCP requests are done by broadcasting and broadcasts do not cross
routers and certainly don't cross proxy servers. Such requests can only
cross a router if the router is specifically configured to pass those
requests to a particular destination, and as in #1, ISA is not a router.

-- 
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com


Relevant Pages

  • RE: Help me
    ... you could enable logging on your router to determine what / ... Further (although I'm not that familiar with ISA) doesn't ISA have the ... allowed),their server logged all requests to my router and firewall from the ... except (attack, scan ping ...) in a month. ...
    (Security-Basics)
  • Re: Web Chaining - Ausgehender Port für SSL
    ... den isa, weil du ihre browserkonfigurationen angepasst hast. ... somit schickt dein isa die requests an den squid und bittet jenen ... auseinandernimmt und je nach Aufbau an den entsprechenden Port ... Also bekommt der upstream-Proxy das nur auf die entsprechenden Ports ...
    (microsoft.public.de.german.isaserver)
  • Re: Web Chaining - Ausgehender Port für SSL
    ... isa, weil du ihre browserkonfigurationen angepasst hast. ... somit schickt dein isa die requests an den squid und bittet jenen wiederum ... dass der ISA auf Port 80 ein HTTP-Connect an den Squid stellt.. ... Also bekommt der upstream-Proxy das nur auf die entsprechenden Ports ...
    (microsoft.public.de.german.isaserver)
  • Re: [Full-disclosure] Netgear DG632 Router Remote DoS Vulnerability
    ... think that only GET requests are CSRFable! ... Netgear DG632 Router Remote DoS Vulnerability ... TN> on that LAN and the "remote management" interface is ...
    (Full-Disclosure)
  • Re: ISA configuration question
    ... - create a certificate that uses either the name or IP of the ISA web proxy listener (depends on how you want the clients to ... - configure the web proxy listener to listen for SSL connections and choose the port you want ... For clients that support secure communication directly with ISA Server, ... > I'm referring to web proxy requests. ...
    (microsoft.public.isa.configuration)