Re: Witch rule to allow firewal client to connect to isa server ?



> recipient ip : 172.18.0.1 (network gateway .. my isa server)
> sender ip : 172.18.100.100 (the client ip)
> Destination port : 1745
> Protocol : unindentified
> connection : close
It does not make much sense in this situation. At least for me ;-)
I'd say that there is nothing uncommon. Protocol is 'unidentified' just
because there is no protocol description for firewall client control
channel.
You should look for any 'Denied' connections to see what protocol is really
blocked by which policy.

> -) i have a tri-home network : perimeter, internal, external
OK.
Have you configured the ISA server using ISA configuration wizard?

> -) i have 3 internal subnet (172.16, 172.17. , 172.18) .. where i could
> see
> which subnet does isa server belong to ?
What are IP addresses of each of your ISA interfaces?
What are subnet masks?
What are (if any) default gateways?
Which networks those interfaces are physically connected?

And what do you mean by "I have 3 internal subnets"? How do they connected
with each other? By hardware router? What are subnet masks on each client?

I believe your problem is slightly misunderstanded IP subnetting concept.
Just as I can see from your explanations and questions...

Regards,
Andrew

>
> "A. Klimkin" <aklimkin at mail dot ru> a écrit dans le message de news:
> eidzTrS5FHA.1464@xxxxxxxxxxxxxxxxxxxxxxx
>> What does that log records look like?
>> What is your networks configuration?
>> Which subnets does your ISA server interfaces belongs to?
>>
>> Regards,
>> Andrew
>>
>> "moi" <me@xxxxxxx> wrote in message
>> news:%23i1J0iS5FHA.1248@xxxxxxxxxxxxxxxxxxxxxxx
>>>I have enable it ...
>>> In the Log, i see that fireclient try the port 1745 with the isa server
>>> withtout success ...
>>>
>>> In the rules base, i just create a rule that allow all port from this
>>> computer to all networks but with user authentification (my isa server
>>> is
>>> a domain member) .
>>>
>>> Help...
>>>
>>> "A. Klimkin" <aklimkin at mail dot ru> a écrit dans le message de news:
>>> udkXR9R5FHA.2628@xxxxxxxxxxxxxxxxxxxxxxx
>>>> There is no special rule in policies list that allow firewall client to
>>>> communicate with ISA server.
>>>> But you have to put a flag at 'Enable Firewall client support for this
>>>> network' checkbox at particular network properties.
>>>> Without this option enabled ISA will not handle firewall client
>>>> requests
>>>> from this subnet.
>>>>
>>>> Regards,
>>>> Andrew
>>>>
>>>> "Ouba" <ouba974@xxxxxx> wrote in message
>>>> news:OYZF$LQ5FHA.2552@xxxxxxxxxxxxxxxxxxxxxxx
>>>>> Hello,
>>>>> Is there a special rule to allow firewall client to connect to isa
>>>>> server ? rule with port 1745 open ?
>>>>>
>>>>> thanks a lot ...
>>>>>
>>>>
>>>>
>>>
>>>
>>
>>
>
>
>


.



Relevant Pages

  • Re: How do I configure ISA server to allow access to computer game server
    ... How to Allow Third-Party Internet Application Connections Through ISA Server ... > Protocol Definitions and define a protocol (port to open). ... > first port the primary connection and then specify the remaining posts as ...
    (microsoft.public.isa)
  • Re: Internal Clients cant VPN to External VPN Server(s)
    ... The Router NAT's to the ISA server which NAT's to the client. ... subnet as the VPN server we connect to, whereas the odd one out assigns ... I've changed the connection details so that we connect by IP address ...
    (microsoft.public.isa.vpn)
  • Re: CEICW fails - several errors
    ... On the WAN NIC of your server the DNS has to point to the LAN IP. ... Ethernet adapter Internet Connection: ... I immediately checked and ISA Server ... Management said that Web Proxy, Firewall and ...
    (microsoft.public.windows.server.sbs)
  • Re: SSL vs. SSL over tcp/ip
    ... that were at different places in the internet backbone ... hierarchical routing (part of the problem was anarchy routing was ... that was only true once the connection was made. ... kernels and tcp/ip protocol stack ... ...
    (comp.security.misc)
  • Re: Help with ISA 2000 / Load balancing router requested - Thanks.
    ... I have a load balancing router that will load balance two connections quite ... happily but then I have two different proxy servers that I ... connection that the load balancing router is using. ... My understanding is that ISA server 2000 Standard Edition won't load balance ...
    (microsoft.public.isa)

Loading