RE: Changing Protocal access rules

  • From: "Jim Harrison" <Jim@xxxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Mon, 3 Oct 2005 08:16:32 -0700

..because you changed your "allow all" to "allow them".
SecureNAT clients can't authenticate.

-------------------------------------------------------
   Jim Harrison
   MCP(NT4, W2K), A+, Network+, PCG
   http://isaserver.org/Jim_Harrison/
   http://isatools.org
   Read the help / books / articles!
-------------------------------------------------------
 
-----Original Message-----
From: James May [mailto:Jmay@xxxxxxxxxx] 
Sent: Monday, October 03, 2005 07:14
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Changing Protocal access rules

http://www.ISAserver.org

 I want to use the http filter to stop most users from downloading
certain file extensions and limit their protocols to a selected set. My
question is why all the secureNat computers stop working when I change
the all users to a windows group or a specific set of users 

-----Original Message-----
From: Jim Harrison [mailto:Jim@xxxxxxxxxxxx] 
Sent: Monday, October 03, 2005 6:49 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Changing Protocal access rules

http://www.ISAserver.org

You might want to clarify what it is you're trying to solve.
"Im trying to use the http filter in isa 2004" is completely unrelated
to SMTP traffic.

-----Original Message-----
From: James May [mailto:Jmay@xxxxxxxxxx] 
Sent: Monday, October 03, 2005 6:42 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Changing Protocal access rules

http://www.ISAserver.org

Tom,
Ok I got the book out this morning I have no problem with the lay out
you suggested. Here's what happens I can not send mail from my exchange
server behind the isa2004. The isa2004 server is relaying the email to
the internal exchange 2000 server which is SBS2000.Only OWA is published
my thinking is I've got something wrong in the ISA2004 setup that's
causing all secureNAT clients and servers to stop working when the all
users is removed from the default protocol rule. Even if an exception is
added to the default rule the same thing happens. Jim 

-----Original Message-----
From: Thomas W Shinder [mailto:tshinder@xxxxxxxxxxx] 
Sent: Monday, October 03, 2005 6:08 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Changing Protocal access rules

http://www.ISAserver.org

Hi Jim,

1. Configure clients as Web proxy clients

2. Configure clients as Firewall clients

3. SecureNAT clients are for servers and non-Windows OS.

Laterz,

Thomas W Shinder, M.D.
Site: www.isaserver.org
Blog: http://spaces.msn.com/members/drisa/
Book: http://tinyurl.com/3xqb7
MVP -- ISA Firewalls

 

> -----Original Message-----
> From: Jim [mailto:jmay@xxxxxxxxxx] 
> Sent: Monday, October 03, 2005 1:08 AM
> To: [ISAserver.org Discussion List]
> Subject: [isalist] Changing Protocal access rules
> 
> http://www.ISAserver.org
> 
> Im trying to use the http filter in isa 2004, when I change 
> the default
> rule by changing the all users to a windows AD group all secure nat
> clients loose connectivity you have to enable the proxy 
> settings in IE to
> get to the internet. I don't have the firewall client 
> installed on any of
> the machines. Thanks Jim
> 
> ------------------------------------------------------
> List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
> ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
> ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
> ------------------------------------------------------
> Visit TechGenix.com for more information about our other sites:
> http://www.techgenix.com
> ------------------------------------------------------
> You are currently subscribed to this ISAserver.org Discussion 
> List as: tshinder@xxxxxxxxxxxxxxxxxx
> To unsubscribe visit 
> http://www.webelists.com/cgi/lyris.pl?enter=isalist
> Report abuse to listadmin@xxxxxxxxxxxxx
> 
> 

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Visit TechGenix.com for more information about our other sites:
http://www.techgenix.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
jmay@xxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist
Report abuse to listadmin@xxxxxxxxxxxxx



------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Visit TechGenix.com for more information about our other sites:
http://www.techgenix.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
jim@xxxxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist
Report abuse to listadmin@xxxxxxxxxxxxx

All mail to and from this domain is GFI-scanned.


------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Visit TechGenix.com for more information about our other sites:
http://www.techgenix.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
jmay@xxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist
Report abuse to listadmin@xxxxxxxxxxxxx



------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Visit TechGenix.com for more information about our other sites:
http://www.techgenix.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
jim@xxxxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist
Report abuse to listadmin@xxxxxxxxxxxxx

All mail to and from this domain is GFI-scanned.



Other related posts: