Re: "Opening ports"



Well, that's what I thought it should look like. But even with things set as
From=Internal & Local Host, To=External Protocol allow TCP port 5656
outbound, it's denied access. When filtering log on port 5656, I noticed
that the Client IP of entries is our external IP, so I filtered on that
instead. The only things that show up involve the PartsExpress5656 rule:
Destination IP=(partsexpress247.com), port=5656, Client IP=(our public IP),
Action=Denied connection.

--
Gary S. Terhune
MS MVP Shell/User

"Phillip Windell" <@.> wrote in message
news:OBq9N6p3GHA.696@xxxxxxxxxxxxxxxxxxxxxxx
Assuming there isn't anything "weird" with it that I don't know
about,..the
rule would be like this:

Create Protocol:
Name: PartsExpress5656
Port Range: 5656 - 5656 (start/end number same = single number)
Direction: Outbound

Create Domain Name Set (unless you wish to use "External")
Name: PartsExpress247
Domain name: "partsexpress247.com"

Create Access Rule
Name: Parts Express 247
Source: Internal (if App runs from the SBS, use "LocalHost")
Destination: External or use "PartsExpress" (the Domain Name Set)
Protocol: "PartsExpress5656"
Users: "All Users" (= "anonymous", and may be required here)

If it fails, go the the Live Log in the Monitoring section and set the
filter to only show traffic from the specific Client then try again and
see
what it shows. The may be other hidden Domain Names and ports that haven't
been disclosed to you.

--
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004

http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Guidance
http://www.microsoft.com/isaserver/techinfo/Guidance/2004.asp
http://www.microsoft.com/isaserver/techinfo/Guidance/2000.asp

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.asp

Deployment Guidelines for ISA Server 2004 Enterprise Edition

http://www.microsoft.com/technet/prodtechnol/isa/2004/deploy/dgisaserver.mspx
-----------------------------------------------------

"Gary S. Terhune" <grystnews@xxxxxxxx> wrote in message
news:e3WyIup3GHA.836@xxxxxxxxxxxxxxxxxxxxxxx
Yeah, yeah, I know that's not exactly how it's done in ISA, but what do
I
do
with the following?

ISA 2004 Standard on SBS 2003 machine. Primary application for this
small
aircraft shop is a specialized shop management app, .Net something or
other
using a SQL database. App needs to update on a fairly regular basis, but
the
update is manual.

The update fails from behind ISA 2004. If I disable the firewall, the
update
goes through. Best the tech has given me suggests that port 5656
outbound
should be opened, that it's seeking "partsexpress247.com,5656, using
ADO.NET
(.Net 1.1) to connect to our SQL server to check version."

Any assistance would be greatly appreciated. I can't quite connect the
dots.

--
Gary S. Terhune
MS MVP Shell/User







.



Relevant Pages

  • RE: ISA access rules, help
    ... please let me know whether you're using ISA 2000 or ISA 2004 ... (SBS SP0 or SBS SP1). ... the ISA server will not be used as a proxy server. ... Since SBS already used port 80, ...
    (microsoft.public.windows.server.sbs)
  • RE: Remote Web Workplace not completely working.
    ... In order to allow a remote desktop connection to a client computer through ... TS requests through a firewall on TCP port 4125, ... To open the port 4125 on ISA, we can re-run CEICW to confirm it. ... server certificate) and then click Next. ...
    (microsoft.public.windows.server.sbs)
  • RE: How to add a Citrix Server
    ... ISA about the second address (how do I attach a second IP address to the NIC ... the ISA server to handle the incoming traffic that needs to go to the Citrix ... How would I forward the traffic coming in on the new port to port ... that the newsgroups are staffed weekdays by Microsoft Support professionals ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA access rules, help
    ... please let me know whether you're using ISA 2000 or ISA 2004 ... >(SBS SP0 or SBS SP1). ... the ISA server will not be used as a proxy server. ... Since SBS already used port 80, ...
    (microsoft.public.windows.server.sbs)
  • Re: How to Configure ISA 2004 for remote access like vnc, pcanywhere
    ... ISA has several protocols pre-defined, but it isn't uncommon for us to need to define custom protocols to allow certain traffic. ... ISA will route this traffic to a specific IP address, so your target server always needs to have the same IP address. ... Then in ISA we need to create our PCAnywhere Server protocol if it doesn't exist, then create a new Server Publishing Rule to forward PCAnywhere traffic to the target machine. ...
    (microsoft.public.windows.server.sbs)