Re: HELP with inbound Ports 25, 80

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Phillip Windell (_at_.)
Date: 10/11/04


Date: Mon, 11 Oct 2004 11:09:11 -0500


"Adam" <anonymous@discussions.microsoft.com> wrote in message
news:255301c4af2f$99f28cb0$a301280a@phx.gbl...
> I'm running Small Business Server 2003 Premium which comes
> with ISA 2000. To make a long story short, ISA configures
> ports 25 and 80 to be OPEN

Actually it is not doing that. There is a difference between a port that
"exists" and a port that can actually be used. I think the hardware NAT
Firewall world has over simplified people's understanding to this stuff.
IIS and SMTP are listening on the external interface, but ISA has its finger
stuck in their ears so they don't hear anything.

Those ports will exist on each interface because the services bind to all
interfaces by default, but they will only function on the internal interface
unless a Packet Filter is created to allow them to function on the external
side. So,...in the end you simply use the ISA's Packet Filters to allow
access to what you want available the the outside, but for the rest,...no
Packet Filter = no access.

-- 
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com


Relevant Pages

  • RE: Windows Update
    ... create an outbound TCP packet filter on ... 443 (Local Port Dynamic, Remote Port Fixed on 443) using the following ... From within the ISA Management MMC console, ... accessing the Windows Update Site from the same box. ...
    (microsoft.public.isaserver)
  • Re: Telnet to Router from Server
    ... Open the ISA Administration tool, and then expand the Server ... click Create Packet Filter. ... Local Port: All Ports ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA Server 2000 mit BackupExec sichern
    ... Interface abgeschaltet. ... > Name: Veritas ... > Remote Port: Alle ... > [MVP ISA Server] ...
    (microsoft.public.de.german.isaserver)
  • Re: Protocol Rule
    ... First, what version of ISA. ... So you're asking you have email server in USA and you want your internal ... > as i understood Packet filter is used to make a control on the Incomeing ... > the Port for HTTP only and this Port is open dynamic through Policy, ...
    (microsoft.public.isa.clients)
  • Packet Filter & Protocol Rule -Disable
    ... as i understood Packet filter is used to make a control on the Incomeing ... is used to make a control on the outgoing traffic from the ISA ... Block the Traffic which is outgoing and incomeing from enter the ISA and get ... the Port for HTTP only and this Port is open dynamic through Policy, ...
    (microsoft.public.isa.clients)