Re: Help a Noobie please with opening a port



Ok, yes, that's what I was wondering about toward the end of my post. I
assume a Computer Set would also work since it also uses the IP#?

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------

"Jim Harrison (ISA SE)" <jmharr@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:33FE2E47-F6FB-47C7-958C-D4DE60732E3B@xxxxxxxxxxxxxxxx
Unless the WARP client is making CERN proxy requests (doubtful), domain
sets
won't work.
You'll have to use an Address Set instead.
nettrans1.novainfo.net resolves to 198.203.191.104
nettrans2.novainfo.net resolves to 198.203.192.217

--
Jim Harrison (ISA SE)

This posting implies no warranty and confers no rights.
http://catb.org/~esr/faqs/smart-questions.html



"Phillip Windell" <philwindell@xxxxxxxxxxx> wrote in message
news:ePM5wJK8HHA.5164@xxxxxxxxxxxxxxxxxxxxxxx

"Kevin" <kmahoney@xxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:6a20e3pfi037clhlfc7vl2u6lr5jqsr8d2@xxxxxxxxxx
The computer that the WARP Server is running on must be able to
establish a TCP/IP client connection on a local port between 1024-5000
and talk to a remote server listening on port 8100.

I've tried setting up a new Access rule. For protocols, I chose
'Selected Protocols' and created a new protocol using Port range
1024-5000, Protocol Type - TCP, and Direction - Outbound.

No.

1024-5000 is irrelevant, those are random Client Ports,...irrelevant.

Create a Domain Name Set:
1. Name: NOVA Servers
2. Domain list: *.novainfo.net

Create the Protocol
1. Name: WARP-NOVA
2. TCP, Start #8100 - End #8100, outbound
3. Nothing else

Create the Access Rule
1. Name: WARP Service to NOVAinfo.net
2. From: LocalHost (if on SBS) or Internal (if on other server)
3. To: NOVA Servers (the Domain Name Set above)
4. Protocol: WARP-NOVA (the protocol above)
5. Users: "AllUsers"

If the Domain Name Set does not work, ping the nettrans1 and nettrans2
servers to get the IP#s and create a Computer Set with them and use the
Computer Set instead.

If the process fails, the Monitoring Log will show that if you run it with
the query filter set to show traffic to the Computer Set or Domain Name
Set,..or you could set the filter to show only traffic originating from
LocalHost but you'll have more "noise" to weed through.


--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or
Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.asp

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------




.



Relevant Pages

  • Re: Problem with updates
    ... I did setup the Auto Discovery using wpad but when I tell the client ... specific name of the ISA server it communicates with it immediatly. ... *outbound* Protocol, so don't get hung up on that idea. ...
    (microsoft.public.isa.configuration)
  • Re: Help a Noobie please with opening a port
    ... Unless the WARP client is making CERN proxy requests, ... 'Selected Protocols' and created a new protocol using Port range ... LocalHost or Internal (if on other server) ... Microsoft ISA Server Partners: Partner Hardware Solutions ...
    (microsoft.public.isaserver)
  • Re: Publishing Direct Connect (DC++)
    ... I know nothing about DC++ - if it has any protocol ... access to the server sitting behind it, so it's just inbound from elsewhere. ... to the main HUB from behind my ISA server. ... DC++ TCP Port 411 ...
    (microsoft.public.isa.publishing)
  • Re: ISA Server 2004 and External Time Source
    ... In ISA Server 2004 there is an SBS Localhost Access Rule which lists NTP ... Protocol is using port 123 to send and receive. ... I found an NTP Server, and have it's IP address and FQDN name. ...
    (microsoft.public.isa)
  • Re: How to map to Internal IP according to external IP
    ... You can probably do this by using the “from” tab in the server publishing ... rule, create a computer set, network set or whatever for each external ... His IP address is 133.128.44.77 and the ISA Server is still ...
    (microsoft.public.isaserver)