Re: SBS 2003 ISA proxy for FTP fails

From: Steve Foster [SBS MVP] (steve.foster_at_picamar.co.uk)
Date: 08/16/04


Date: Mon, 16 Aug 2004 05:58:52 -0700

David Barnes wrote:

> Steve,
> Many thanks for looking into this..
> Bearing in mind that this is SBS 2003 and things come 'pre
> configured' and you need to use wizards to enable anything. Is there
> some wizard or setup bit that I've missed?
> Will re-running the CEICW wizard undo any settings I set?

Rerunning the CEICW will disable any Access Policy elements you
manually create (ie S&C Rules, Protocol Rules, Packet Filters). It
won't do anything to any of the components within Policy Elements
(Protocol Defn's, Client Sets, etc.).

>
> not being an ISA wiz I do need some pointers on what you suggest.
> 3. I assume this is done in IE.. what setting needs to be tweaked?
> can I set this as a domain policy, rather than visit 35 workstations.

Yes, you can set this in IE. It's under Tools > Internet Options >
Advanced "Use Passive FTP (for firewall and DSL modem compatibility)".

You _should_ be able to set this via GPO, but I don't have any
specifics. Manipulating IE through GPO always seems to work out harder
than it ought to.

> 4. I never have really got my head round ISA, Read the book, done the
> course,
> still don't understand it..
>
> My understanding was that IE was port mode unless you set the PASV
> setting in advanced.
> This would give you
> Client Server
> >1023 --------control------> 21
> > 1023 <-------data--------- 20
> Note: I'm only representing the 'initial connect' here, and hence
> what goes in the 'filter'
>
> For PASV mode:
> Port 20 is not used and the local client has to be able to connect a
> local dynamic port to a remote dynamic port.(well the proxy has to do
> this) Client Server
> >1023 --------control------> 21
> >1023 -------data---------> >1023
> Note: I'm only representing the 'initial connect' here, and hence
> what goes in the 'filter'
>
> I thought I had enabled the filters for active mode and setup one to
> cover the PASV secondary connection.
> SBS comes with some ftp filters pre-defined but disabled. Are these
> the correct ones to use?
> Have I set these up correctly? what should the filters be set like?
> Is there a 'pre configured' rule set that I need to turn on? where do
> I set these and what should be in them?
> What else do I need to do?

The default FTP protocol definitions don't deal with the active element
on port 20. So you need to create your own, that has the primary
connection on TCP/21 (like the predefined protocols), and a Secondary
Connection of TCP/20/Inbound. Then add a Protocol Rule to Allow your
new Protocol for Any Request.

The packet filters that are defined are for the server itself, and also
apply to clients where the firewall client is installed.

> I suppose a better question would be.
>
> What do I need to do to 'out of the tin' SBS 2003 Premium to enable
> FTP(Read) proxy access for non windows clients (EG Apple MAC, Unix)
> and windows clients without the firewall client installed?

See above.

-- 
Steve Foster [SBS MVP]
---------------------------------------
MVPs do not work for Microsoft. Please reply only to the newsgroups.


Relevant Pages

  • Re: SBS 2003 ISA proxy for FTP fails
    ... > Will re-running the CEICW wizard undo any settings I set? ... manually create (ie S&C Rules, Protocol Rules, Packet Filters). ... (Protocol Defn's, Client Sets, etc.). ...
    (microsoft.public.windows.server.sbs)
  • Re: MSN Messenger question
    ... I can't find the file mspclnt.ini on the client pc as mentioned in step 2. ... > 1) Add the following protocol rule and protocol definition for File ... > MSN MESSENGER SETTINGS FOR ISA2000 ...
    (microsoft.public.isaserver)
  • Re: client -server interaction over XML supporting multiple protocols
    ... > NETBEUI to access the server to access the functionalities exposed. ... > server doesnot know in advance which client is using what protocol. ... size of the XML and Xfunctionality will determine the demands ...
    (comp.lang.cpp)
  • Re: Access Rule for OutLook mail from Exernal ISP
    ... Client IP =123.56.78.910 ... Destination IP = 21.217.9.25 ... Make sure it is enabled and the ISA Server name shows. ... > will tell you which Rule is doing the deny and which Protocol is being ...
    (microsoft.public.isa)
  • Re: ISA 2004 and Standalone CA on the same Server
    ... Sometimes the app-level filters perform ... internal access rule that allows HTTP to ISA LocalHost from Internal. ... HTTP" entry in the right-click menu then it means the app level filter is ... > authentication but still the client pc uses the anonymous account. ...
    (microsoft.public.isa)