RE: Protocol question

  • From: "Thor \(Hammer of God\)" <thor@xxxxxxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Thu, 7 Apr 2005 12:30:07 -0700

It is nice to see this topology officially supported by Microsoft. Several years ago, Microsoft dropped me behind enemy lines to work on an international banking client, where I designed this exact network structure for them. At that point, they couldn't officially support it due to issues with domain controller authentication and replication issues within an infrastructure isolated via IPSec. It was really too bad, as it was a kickass design.

Official support within a Win2k3 environment is a major win.

T


----- Original Message ----- From: "Thomas W Shinder" <tshinder@xxxxxxxxxxx>
To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
Sent: Thursday, April 07, 2005 11:55 AM
Subject: [isalist] RE: Protocol question



http://www.ISAserver.org

Hi Dan,

Or use IPSec domain isolation
http://www.microsoft.com/downloads/details.aspx?FamilyId=404FB62F-7CF7-4
8B5-A820-B881F63BC005&displaylang=en

HTH,

Tom
www.isaserver.org/shinder
Tom and Deb Shinder's Configuring ISA Server 2004
http://tinyurl.com/3xqb7
MVP -- ISA Firewalls


-----Original Message----- From: Ball, Dan [mailto:DBall@xxxxxxxxxxx] Sent: Thursday, April 07, 2005 1:55 PM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Protocol question

http://www.ISAserver.org

I like the previous idea better.  Put the computer in a DMZ, and run
whatever the heck you want, forget about trying to pass through ISA.
That only requires one more NIC, and you don't have to go into the
LinkSys/double-NAT fiasco.   Only catch; you'd better reformat that
computer before putting it back on the internal side of the ISA...

If you absolutely HAVE to have it on the internal network, then take the
below listed method and lock it down even more.  Define exactly WHICH
clients are allowed to connect with WHICH servers, with WHAT protocols.
Then, in order to exploit those holes they have to impersonate those
particular servers, and can only get to that one computer if they do.

-----Original Message-----
From: Steve Moffat [mailto:steve@xxxxxxxxxx]
Sent: Thursday, April 07, 2005 14:17
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Protocol question

http://www.ISAserver.org

OK

Here we go

Create 2 new protocols

1. port 3724 TCP outbound

2. port 3724 TCP inbound

Create an allow rule using the above protocols for the pc that you are
going to use to play the game, make sure the firewall client is
installed.

Start the game, monitor the isa logs to see what other ports are needed,
inbound and outbound. Create protocols and add to the rule when needed.

Jeez.......I got it working in 20 mins.

S

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
World of Windows Networking: http://www.windowsnetworking.com
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
tshinder@xxxxxxxxxxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist
Report abuse to listadmin@xxxxxxxxxxxxx



------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
World of Windows Networking: http://www.windowsnetworking.com
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as: thor@xxxxxxxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist
Report abuse to listadmin@xxxxxxxxxxxxx





Other related posts: