Is ISA2004 filtering on IP or an IPs MAC?

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Bill C (C_at_discussions.microsoft.com)
Date: 02/06/05


Date: Sun, 6 Feb 2005 13:07:01 -0800

Under the hood, does an ISA2004 server filter on IP or an IPs MAC?

Problem:
An ISA 2004 server’s default gateway IP is a Cisco HSRP (hot standby routing
protocol) IP address.

When packets for an upstream BGP session are sent back through the standby
router’s IP/MAC (which can happen for normal BGP reasons), the ISA firewall
won't accept standby’s packets (the TCP_SYN packet is dropped by ISA), and
ISA will only accept those that were sourced on the HSRP virtual IP/MAC.

There is no way to get the standby router to source its own packets on the
virtual MAC, as specified by RFC 2281.

Question:
Is the ISA firewall is able to accept packets sourced on many different
IP/MAC addresses, not only those from a particular device? The PIX doesn't
support MAC address filtering. I'm pretty sure that there are other firewalls
from other vendors that don't filter based on MAC address.

How do I get the ISA server to accept a respone form the HSRP standby
router's IP/MAC?

Thanks,
Bill Chaffin, MCSE



Relevant Pages

  • Re: wierdness in my security report
    ... > and there for will change the MAC address again. ... Routers running HSRP communicate HSRP information between each other, ... These packets are sent to the destination IP multicast ...
    (FreeBSD-Security)
  • Re: Is ISA2004 filtering on IP or an IPs MAC?
    ... ISA's policy is based on IP addresses and not on MAC addresses. ... Ori YosefiISA Server Team ... "Bill C" wrote in message ... > won't accept standby's packets, and> ISA will only accept those that were sourced on the HSRP virtual IP/MAC. ...
    (microsoft.public.isa)
  • Re: Please dont shoot me but......
    ... IE for the Mac never really worked right with ISA anyway, ... "Jim Harrison " wrote: ... This posting implies no warranty and confers no rights. ... IOW, if you configure the MAC browser to "use a proxy", then the FWC ...
    (microsoft.public.isa.clients)
  • RE: Mac OSX Client through ISA 2004
    ... Thank you for posting in SBS newsgroup. ... ISA2004 to enable the Mac to access the internet and Exchange. ... clients to connect to the Internet through ISA: ...
    (microsoft.public.windows.server.sbs)
  • FWX_E_TCP_NOT_SYN_PACKET_DROPPED on SMTP Connections
    ... BGP session are sent back through the standby router's ... IP/MAC, the ISA ... firewall won't accept standby's packets (the TCP_SYN ... >SMTP and HTTP packets. ...
    (microsoft.public.isa.enterprise)