Re: ISA 2004 - FTP allowed, then denied on "unidentified IP traffic"



Please find my inline comments.

"InfoVision" <infovision1@xxxxxxxxx> ???????/???????? ? ???????? ?????????:
news:1138213490.241685.99950@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
> My customer has a nicely organized ISA 2004 Firewall Policy.
>
> FTP Access is allowed from Localhost and All Protected Networks to
> External.
>
> FTP is not set to read-only.
>
> FTP Access Filter is enabled, though I have tried it with and without
> this selection.
>
> My troubleshooting has been from the ISA server itself, with IE proxy
> settings tested with fields configured and blank, passive FTP on and
> off, Folder View FTP on and off.
>
> Browser shows a connection to FTP site, can view the FTP SERVER WELCOME
> MESSAGE, but it hangs, eventually timing out. ISA log shows initial
> connection on port 21, then subsequent denial on "unidentified IP
> traffic" - the ports are all over the map, sometimes in the 6000 range,
> sometimes 9000.
This behavior is most likely because of disabled FTP access filter.

>
> ISA help says "The FTP access filter dynamically opens specific ports
> for the secondary connection, but the protocol definition opens a range
> of secondary ports"; I assume that is what these are, and they should
> not require additional rules...anyway, they vary,so I'd be chasing a
> ghost.
>
> Same behavior in TELNET FTP...can connect, not list or PUT or GET.
What is "telnet ftp"? Have you meant ftp.exe command line utility? If so, it
requires FTP access filter up and running just like as IE of any other ftp
client.

> ISA is behind a managed telecom router, could it be affecting the port
> traffic coming back in ?
Yes, it is. I've faced some cases where upstream router blocks PORT mode ftp
connections. Never seen the situation when PASV ftp connections being
blocked.

A couple of thoughts:
- Never perform any connectivity testing from the ISA server itself. Always
check the connectivity from within the same network as the rest of clients
belongs to. There is several reasonts of that. First, access policy for
local host and internal networks could be (or even should be - for security
considerations) much different. Second, you have no way to configure ISA
server as firewall client to itself; it dramatically reduces the ISA server
capability to follow the majority of authenticating access policy.
- Never use IE as an FTP client. It's just a mess. ftp.exe also limited to
PORT mode ftp connections only. Take one of plenty FTP clients either
commercial or freeware available out there. Personally I'm using a FAR
Manager utility FTP plugin.
- Is your FTP access allow rule anonymous? If so, if any access policies
before this (in order of processing) require authentication? Any anonymous
assecc rules should precede all the rules requiring authentication. If your
FTP access rule requires users authentication either, you should install and
configure firewall client software on the client host.

> Thanks
> Jon Epstein, MSCA / MSCE
> InfoVision, Inc.
> Charlotte, NC
>

Regards,
Andrew


.



Relevant Pages

  • FTP server publishing
    ... perimeter network on the back firewall. ... FTP on the same server as the web sites are published. ... fine before the introduction of ISA. ... connection ...
    (microsoft.public.isa.enterprise)
  • ISA 2004 drops ftp connection
    ... I am running ISA 2004 Server on Windows Server 2003 SP2 Standard Edition. ... I have a ftp service running on internal interface ... Connection to host lost. ...
    (microsoft.public.isa.configuration)
  • FileZilla FTPS through ISA
    ... XPsp2 with Filezilla ftp program through ISA2000. ... this is where through ISA it ... negotiating SSL connection... ...
    (microsoft.public.isa)
  • FTP Client through ISA
    ... XPsp2 with Filezilla ftp program through ISA. ... I opened up the ftp outbound ports and also created a ... negotiating SSL connection... ...
    (microsoft.public.windows.server.sbs)
  • FileZilla FTPS through ISA
    ... Have you installed the firewall client? ... >XPsp2 with Filezilla ftp program through ISA2000. ... this is where through ISA it ... >negotiating SSL connection... ...
    (microsoft.public.isa)

Loading