Re: Blocking Internet Access...SBS2003 and ISA

Tech-Archive recommends: Speed Up your PC by fixing your registry



Maxibo wrote:

5 workstations all 2000 professional. No ISA firewall client installed and IE settings for server proxy removed. They do not get on the internet.

Replaced with XP Professionals (did not run connect computer etc as they only run a third party app and just joined to the domain)

However these XPs went straight on the internet. Checked users are not in RWW group and not in SBS Internet users. But still went on internet.

Is this ISA2000 or ISA2004? And is the only access to the internet from the LAN through the SBS (ie it has 2 nics, one LAN, one internet), or is there a router/firewall connected directly to the LAN?

Are the workstations allocated a default gateway?


I had to setup an ISA rule for the workstation names to block external access, which worked.

The default ISA rules in SBS only allow authenticated access, so either those rules have been relaxed, or additional allow rules exist.


I am trying to understand why these went on the internet and were only blocked when I setup a rule to block workstation name.

They matched an ISA rule that allowed access, and you now have a deny rule that "beats" the allow.

--
Steve Foster [SBS MVP]
---------------------------------------
MVPs do not work for Microsoft. Please reply only to the newsgroups.
.



Relevant Pages

  • Re: Routing to remote office...
    ... > ipconfig /all from a workstation on each lan should suffice) we can come ... > the Vigor's VPN instead of just the internet? ... Because they're pointed at the external NIC addresses of each SBS box rather ... >> creating a VPN connection from the client to the Site 2 SBS box. ...
    (microsoft.public.backoffice.smallbiz2000)
  • RE: RWW not accessible over web
    ... Can you access RWW from SBS itself thru http://localhost/remote/? ... Click the "Connect to the Internet" link. ... On the ISA Server computer, stop the Microsoft Firewall service. ...
    (microsoft.public.windows.server.sbs)
  • Re: Instant Messaging not working
    ... When I attempt to log in I get the message: Signing in to Microsoft Exchange ... > We are having trouble using IM from LAN user to the SBS 2000 server. ... >> an Internet remote user to the SBServer, from a LAN User to the SBServer, ...
    (microsoft.public.backoffice.smallbiz2000)
  • RE: ISA 2004 and the internet connection
    ... would you please help me confirm if the internet ... This newsgroup only focuses on SBS technical issues. ... |> Open the ISA Server management console, ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA 2004 and the internet connection
    ... would you please help me confirm if the internet ... This newsgroup only focuses on SBS technical issues. ... |> Open the ISA Server management console, ...
    (microsoft.public.windows.server.sbs)