Protocol Rules vs IP Packet Filters

From: Bernie Hunt (bhunt_at_optonline.net)
Date: 03/19/05


Date: Sat, 19 Mar 2005 09:32:40 -0500

I'm slowly getting my arms around ISA, but there a still a few issues that
aren't yet clear. One of them is when to use Protocol Rules and when to use
IP Packet Filters.

I'm running mainly SBS environments so most everything is in the same box.

I found a very helpful post from Zachary Gutt that defined this

Protocol rules = for allowing outbound communication...from internal
networks (things in the LAT) to external networks like the Internet (things
not in the LAT).

IP Packet filters = for allowing communication to and from the ISA Server
computer itself

>From this I understand that if the user needs to run say Quicken on the
server, then I need to configure the IP Packet Filters to allow the traffic
to the quicken update server.

If they are running quicken on a workstations, then I need to set up a
Protocal Rules to pass the traffic through the server and on out to the
internel. My confusion is, if the Protocal Rules defines traffice that is
allowed through the server, do I also have to make equivalent IP Packet
Filters for the server to let the traffic in and out?

Thanks for any help or references to sources of learning. This stuff is
think to learn but powerful knowledge to have!

Bernie



Relevant Pages

  • Re: Lost with ISA...
    ... > I thought the protocol rules were applied on top of> the Packet Filters. ... the clients would only have acces to a subset of what's> available on the server itself... ... >> The server doesn't have the Firewall Client>> installed, that is the reason why it needs packet filters. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: packetfilters vs protocol rules
    ... Packet Filters are used to provide access to and from the ISA ... Server machine itself, and to/from a perimeter network, if one exists. ... ISA isn't a SecureNAT or Firewall client to itself, so Protocol Rules and ...
    (microsoft.public.isaserver)
  • Re: Lost with ISA...
    ... I don't really need to ftp from the server but I don't understand then ... > how come the Clients can ftp if all the server can't... ... Packet filters control access to/from the SBS ... >>> while Protocol Rules add one more level of filtering for ISA ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Lost with ISA...
    ... I thought the protocol rules (for the clients) were applied on top of the ... available on the server itself... ... Should I understand that the clients are ONLY affected by the protocol rules ... and NOT by the packet filters? ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Outlook Express is blocked on client
    ... I get the same on port 25. ... And when I do it from the server. ... I have three Protocol Rules defined: ... 1: Small Business Internet Access Protocol Rule: Enabled, Allow, All IP ...
    (microsoft.public.windows.server.sbs)