Re: ISA Rule for Remote Desktop?



Jeff

A couple of things happen that you may want to investigate (as I am not sure
how the traffic is passed to the "backup bandwidth" in your case.) When SBS
receives a connection on port 4125, it first compares the IP that sent the
request with the previous 443 request's source IP. (The one that opened the
session with the https://server/remote). If the 2 IPs are different, port
4125 is closed. I wonder if what your ISP rigged up is messing with that
somehow. Ok, that's probably a stretch...

More likely related to your problem though is that a device between ISA and
the remote PC (at your ISP) is blocking 4125. Did you check:
http://support.microsoft.com/kb/828053/en-us


Joe

"Jeff Teel" <jdteel@RMoveThis sugardog.com> wrote in message
news:eV%2396qOVHHA.392@xxxxxxxxxxxxxxxxxxxxxxx
Well here is the "rest of the story". My Internet provider has the
ability to provide "backup bandwidth" if one of their resources fails or
is having problems (of course depending on the source of the problem). So
when I'm on backup bandwidth I have a different IP address than the normal
address. Recently I've been switched to the backup and in turn have a
different IP address. I initially noticed that there was no access to
RWW. After we got that problem figured out (A record for the domain name
pointing to the wrong IP address) I can now access RWW and use Outlook Web
but still can't Remote Desktop into anything from within RWW (from outside
the LAN). It has worked in the past...this is not a new
configuration.....and the ISP has ports 25, 443, 444, and 4125 forwarded
to my WAN card on the server. I see the attempts being made from the
logging interface in ISA to port 4125 when I attempt to do Remote Desktop
from outside my network but I receive this message:

"The client could not connect to the remote computer. Remote connections
might not be enabled or the computer might be too busy to accept new
connections. It is also possible that network problems are preventing
your connection. Please try again later. If the problem continues to
occur, contact your administrator."

The blue information bar on this window says: VBScript: Remote Desktop
Disconnected. I'm sure that traffic is getting through to port 4125
because I can see the attempt being made to connect to that port in ISA
logging but it looks like it gets closed right after that. There are three
connection attempts in the ISA log and right after each attempt the
connection is closed.

Thanks
Jeff


"SuperGumby [SBS MVP]" <not@xxxxxxxxxxx> wrote in message
news:uYc0nOMVHHA.1208@xxxxxxxxxxxxxxxxxxxxxxx
GAWD, that, and how ISA defines inbound/outbound rules, just confuses me.

ISA rules have nothing to do with how the remote PC sees it. The
inbound/outbound is purely from (some wierd MS) ISA's perspective and the
definition of source and destination networks.

It's all pretty well irrelevent however, the rules created by the CEICW
are correct if the network has been defined correctly. Rather than asking
'did the CEICW define this rule correctly' the OP should let us know what
problem he is experiencing, what error message is occurring, and just why
the frack someone who needs assistance understanding ISA inbound/outbound
definition believes there is any benefit in questioning the result of
several hundred hours of MS' best dev team development and the experience
of several thousand users.

I think I better 'back off', something got 'under my collar' earlier
today, I think I'm starting to bite simply because it feels good.

"J. M. De Moor" <nospam@xxxxxxxxxx> wrote in message
news:etqVryLVHHA.600@xxxxxxxxxxxxxxxxxxxxxxx
Jeff

I believe the direction is "outbound" when seen from External to Local,
which is correct. Although SBS dynamically opens port 4125, it is the
remote ActiveX that initiates the connection to SBS using 4125. If you
look at the URL that RWW receives from SBS when you try to connect to a
computer on the network, you will notice a &Port=4125&, in effect
telling the remote browser to use that port. From the perspective of
the remote computer, it is outbound. ISA Server (out of the box) blocks
actual outbound traffic on port 4125, which is why connecting to a
computer on your internal network via RWW gives you problems.

...at least that is the way I understand it. Hehe.

Joe

"Jeff Teel" <jdteel@RMoveThis sugardog.com> wrote in message
news:OltwwDLVHHA.4784@xxxxxxxxxxxxxxxxxxxxxxx
I am looking at a rule in ISA 2004 named SBS RWW Inbound Access Rule.
It has an Allow action, the protocol is named
SBS_Custom_Protocol_TCP_Outbound_4125 and in the details for that
protocol it is using port 4125 Outbound. It is from the External
listener to Local Host.

My questions: Is that rule correct for allowing Remote Desktop from
outside the LAN and should there be a rule for port 4125 Inbound as
well? I'm not seeing one.

Thanks
Jeff









.



Relevant Pages

  • Re: puTTy: Coonection reset by peer
    ... I'm always getting a "connection reset by ... Your problem has nothing to do with "port 3306," or anything with your ... The difference is that the first is localhost access and the second is from ... because the code's user does not have a login via a remote host. ...
    (comp.security.ssh)
  • Re: RWW not working externally (R2)
    ... Then on your workstations and or the server, make sure that in the Remote ... I don't think this is an ISA issue or you wouldn't be getting as far as ... Ethernet adapter Server Local Area Connection: ...
    (microsoft.public.windows.server.sbs)
  • Re: Using Remote Desktop From an SBS Domain
    ... Right click My Network Places...Properties. ... computer that is on a remote network now. ... Internet connection, bypassing my SBS/ISA network all together. ... the port number you connect to from 80 to a port of your ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote Web Workplace - Cannot Connect to Server Desktop, but can use outlook web access, tim
    ... You should absolutely close PORT 80 ... I had setup the services on the router but I hadn't then inserted them into the firewall rules set. ... Download Connection Manager, ... VBSCript: Remote Desktop Disconnected ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA Rule for Remote Desktop?
    ... tips for ISA 2000 and I have ISA 2004. ... logging when I was doing the testing from a dialup connection it was the ... same IP address on both port 443 and port 4125. ... and the remote PC is blocking 4125. ...
    (microsoft.public.windows.server.sbs)