UDP Rule Ignored



I have an ISA Server 2004 rule that seems to be not taking, and what is
stranger is how the monitor is showing the packets.

One of our "internal" segments is a dedicated NTP server on Windows that is
pretty much isolated on its segment and can only get out and in by NTP and a
proprietary superset of NTP that the vendor supports for the product. The
box had to be put behind ISA Server 2004 since it is our clock for all the
internal domain controllers. I have several boxes in front of the ISA
Server 2004, in a no man's land that is behind yet another firewall, that I
want the same NTP server to service. I could have published the UDP
protocol on the NTP server on the ISA, but I decided to flex ISA's
capabilities and just route the dedicated internal NTP network out to the no
man's land, and then I have a route on the no man's land to point back to
the NTP server on the dedicated internal NTP network using ISA Server 2004
as the "router".

What I see on the monitor of ISA Server 2004 baffles me. The route on the
no man's land is working fine. The proprietary NTP UDP variant packets
come in with a target IP pointing to the NTP server, presented on the
correct interface of the ISA Server 2004. But in the monitor ISA Server
2004 rejects the packets, and the baffling part is that it SHOWS NO RULE AS
MATCHING. I would expect if I had the rule wrong that the default rule
would catch this packet and it would be rejected using that rule. Instead,
the packet is denied, and NO rule shows as matching on the Denied line of
monitor. What the heck would cause that behavior?!

--
Will


.



Relevant Pages

  • Re: UDP Rule Ignored
    ... rule back into the one segment with the NTP server. ... having introduced an ISA Server 2004 Network rule ... the firewall, the traffic flies in and out of the firewall, but the monitor ... the NTP server on the dedicated internal NTP network using ISA Server 2004 ...
    (microsoft.public.isa)
  • Re: ISA Server 2004 and External Time Source
    ... In ISA Server 2004 there is an SBS Localhost Access Rule which lists NTP ... Protocol is using port 123 to send and receive. ... I found an NTP Server, and have it's IP address and FQDN name. ...
    (microsoft.public.isa)
  • Re: NAT vs Route checking
    ... capturing the packets on the ISA server on the external NIC, ... In both cases I see the ISA server external ... Understanding the ISA 2004 Access Rule Processing ...
    (microsoft.public.isa.configuration)
  • Re: Detection of outbound spam on an SBS network?
    ... You can absolutely monitor for this traffic using ISA server, ... Les Connor [SBS MVP] ...
    (microsoft.public.windows.server.sbs)
  • ISA as a One-legged Route
    ... By one-legged route I mean that the routing device forwards the packet to be ... I'm currently on ISA Server 2K4 SP1. ... We thus have two holes by which packets leave the building, ... ISA Server has a route for the remote site that ...
    (microsoft.public.isa.configuration)