Re: Firewall Client Extremely Chatty
- From: "Jim Harrison \(ISA SE\)" <jmharr@xxxxxxxxxxxxxxxxxxxx>
- Date: Wed, 17 Jan 2007 14:04:44 -0800
As I said, you'll see FW log entries that include the application name and a
version number in the "client-agent" field.
These are FWC-sourced requests.
What the logs show depends on the field options you've selected.
ISA doesn't log every SYN/SYN_ACK, etc.
--
Jim Harrison (ISA SE)
This posting implies no warranty and confers no rights.
"Will" <westes-usc@xxxxxxxxxxxxxx> wrote in message
news:BaSdnZg8EN7gBDDYnZ2dnUVZ_rOqnZ2d@xxxxxxxxxxxxxxx
"Jim Harrison (ISA SE)" <jmharr@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:0F1225CF-75CC-4A75-92AF-DBDAF5BDB5B9@xxxxxxxxxxxxxxxx
ISA does show you where FWC traffic is going - ISA has this in thefirewall
log.field,
All FWC traffic will include an appliation name in the "Client-Agent"
along with a number that indicates the OS version.located
You can see the client IP and the final destination of the request.
The FWC is as hinted at by Phil (hi Phil), a "Winsock remoter" that allows
non-proxyable traffic such as POP3, SMTP, etc. to act as if it were
on the ISA itself (ISA policies permitting, of course). If you deploy anISA.
"allow all" policy set, then yes; you can use anything you want thorugh
If you use a "deny all except" policy, then you can control who uses what.
Thank you for that information. If things are working as designed, what
should see in addition to the connections to the ISA Server on 1745/UDP from
the computers running firewall client? How will we see the endpoints in
the firewall log? Will it simulate an end to end connection and show the
source IP of the machine running firewall client together with the
destination IP of the computer on the Internet? Or will only only show
the connection from the client to the firewall, and then a separate
connection from the firewall to the actual destination?
--
Will
.
- References:
- Firewall Client Extremely Chatty
- From: Will
- Re: Firewall Client Extremely Chatty
- From: Will
- Re: Firewall Client Extremely Chatty
- From: Will
- Re: Firewall Client Extremely Chatty
- From: Will
- Re: Firewall Client Extremely Chatty
- From: Jim Harrison \(ISA SE\)
- Re: Firewall Client Extremely Chatty
- From: Will
- Firewall Client Extremely Chatty
- Prev by Date: Re: ISA 2004 and I.E 7 Authentication intermittent issue
- Next by Date: Re: Firewall Client Extremely Chatty
- Previous by thread: Re: Firewall Client Extremely Chatty
- Next by thread: Re: Firewall Client Extremely Chatty
- Index(es):
Relevant Pages
|