Connection denied
From: Mykhaylo Khodorev (ralfeus_at_chicagocentre.com.ua)
Date: 11/03/04
- Next message: Tristan Kington [MSFT]: "Re: Connection denied"
- Previous message: Mykhaylo Khodorev: "Re: ISA 2004 doesn't work at all"
- Next in thread: Tristan Kington [MSFT]: "Re: Connection denied"
- Reply: Tristan Kington [MSFT]: "Re: Connection denied"
- Messages sorted by: [ date ] [ thread ]
Date: Wed, 3 Nov 2004 09:41:25 +0200
I've found a strange behavior of ISA 2004 (Windows 2003 Server
Standard). At the beginning the network rule was:
Source networks: Internal
Dest networks: All networks (and Local Host)
Relation: NAT
and firewall rule was:
From: Internal
To: All networks (and Local Host)
Condition: All users
Protocols: pings
Action: Allow
I could ping any external destination.
But when I've changed Relation of network rule from NAT to Route, I've got
such records in the log:
Client IP: 192.168.0.200
Destination IP: 216.109.112.135
Destination Port: 0
Protocol: Ping
Action: Initiated Connection
Rule: Allow Pings
Source network: Internal
Dest network: External
Client IP: 192.168.0.200
Destination IP: 216.109.112.135
Destination Port: 0
Protocol: Ping
Action: Denied Connection
Rule:
Source network: Internal
Dest network: External
Client IP: 192.168.0.200
Destination IP: 216.109.112.135
Destination Port: 0
Protocol: Ping
Action: Denied Connection
Rule:
Source network: Internal
Dest network: External
Client IP: 192.168.0.200
Destination IP: 216.109.112.135
Destination Port: 0
Protocol: Ping
Action: Closed Connection
Rule: Allow pings
Source network: Internal
Dest network: External
I read on microsoft.com that when packet is dropped before getting rules
engine the rule name won't appear. But why packet can be dropped before
getting rules engine? Why NAT is working fine, but route doesn't?
Thanks.
Mykhaylo Khodorev
- Next message: Tristan Kington [MSFT]: "Re: Connection denied"
- Previous message: Mykhaylo Khodorev: "Re: ISA 2004 doesn't work at all"
- Next in thread: Tristan Kington [MSFT]: "Re: Connection denied"
- Reply: Tristan Kington [MSFT]: "Re: Connection denied"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|