It is nice to see this topology officially supported by Microsoft. Several
years ago, Microsoft dropped me behind enemy lines to work on an
international banking client, where I designed this exact network structure
for them. At that point, they couldn't officially support it due to issues
with domain controller authentication and replication issues within an
infrastructure isolated via IPSec. It was really too bad, as it was a
kickass design.
Official support within a Win2k3 environment is a major win.
T
http://www.ISAserver.org
Hi Dan,
Or use IPSec domain isolation http://www.microsoft.com/downloads/details.aspx?FamilyId=404FB62F-7CF7-4 8B5-A820-B881F63BC005&displaylang=en
HTH,
Tom www.isaserver.org/shinder Tom and Deb Shinder's Configuring ISA Server 2004 http://tinyurl.com/3xqb7 MVP -- ISA Firewalls
-----Original Message----- From: Ball, Dan [mailto:DBall@xxxxxxxxxxx] Sent: Thursday, April 07, 2005 1:55 PM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Protocol question
http://www.ISAserver.org
I like the previous idea better. Put the computer in a DMZ, and run whatever the heck you want, forget about trying to pass through ISA. That only requires one more NIC, and you don't have to go into the LinkSys/double-NAT fiasco. Only catch; you'd better reformat that computer before putting it back on the internal side of the ISA...
If you absolutely HAVE to have it on the internal network, then take the below listed method and lock it down even more. Define exactly WHICH clients are allowed to connect with WHICH servers, with WHAT protocols. Then, in order to exploit those holes they have to impersonate those particular servers, and can only get to that one computer if they do.
-----Original Message----- From: Steve Moffat [mailto:steve@xxxxxxxxxx] Sent: Thursday, April 07, 2005 14:17 To: [ISAserver.org Discussion List] Subject: [isalist] RE: Protocol question
http://www.ISAserver.org
OK
Here we go
Create 2 new protocols
1. port 3724 TCP outbound
2. port 3724 TCP inbound
Create an allow rule using the above protocols for the pc that you are going to use to play the game, make sure the firewall client is installed.
Start the game, monitor the isa logs to see what other ports are needed, inbound and outbound. Create protocols and add to the rule when needed.
Jeez.......I got it working in 20 mins.
S
------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: World of Windows Networking: http://www.windowsnetworking.com Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: tshinder@xxxxxxxxxxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx