You can have a publishing rule with more applying to more than one protocol definition? That would greatly simplify things as I wouldn't have to maintain 100 definitions & publishing rules. -----Original Message----- From: Jim Harrison [mailto:jim@xxxxxxxxxxxx] Sent: 21 October 2003 15:00 To: [ISAserver.org Discussion List] Subject: [isalist] Re: Port Ranges http://www.ISAserver.org Rules and rule elements are separate entities. You can have a single rule that allows multiple protocol definitions quite easily (and it's scriptable). Jim Harrison MCP(NT4, W2K), A+, Network+, PCG http://isaserver.org/Jim_Harrison/ http://isatools.org Read the help / books / articles! On Tue, 21 Oct 2003 14:14:26 +0100 "Stuart Pittwood" <SPittwood@xxxxxxxxxxxxxxxxx> wrote: http://www.ISAserver.org I guess it's only fast & loose if it's not used properly. If you have an app (such as ours) which communicates to a back end database server on several different ports which are consecutive what difference does it make (apart from make things slower to configure) if you create 100 rules as opposed to one rule which encompasses the whole range. I can see it being abused by lazy admins who would rather than open ports 1000, 1005, 107, 1010 will just open a range of 1000-1010, but that is a problem with the admin not software. Anyways, no matter what, as we have ISA I have to create the definitions so I better get off my soap box and get back to work :-) -----Original Message----- From: Jim Harrison [mailto:jim@xxxxxxxxxxxx] Sent: 21 October 2003 14:10 To: [ISAserver.org Discussion List] Subject: [isalist] Re: Port Ranges http://www.ISAserver.org Sounds like PIX is being a bit fast and loose with the concept. The last thing I need is someone getting a primary connection through on a secondary port. You can also script this task using your favorite COM-capable scripting tools. Jim Harrison MCP(NT4, W2K), A+, Network+, PCG http://isaserver.org/Jim_Harrison/ http://isatools.org Read the help / books / articles! On Tue, 21 Oct 2003 13:58:00 +0100 "Stuart Pittwood" <SPittwood@xxxxxxxxxxxxxxxxx> wrote: http://www.ISAserver.org Maybe this would be something MS should add? As it means that I have to now create 100 different protocol definitions. I know you can do this on a PIX (not sure about other firewalls) Anyways off to my isa server Thanks Jim -----Original Message----- From: Jim Harrison [mailto:jim@xxxxxxxxxxxx] Sent: 21 October 2003 13:49 To: [ISAserver.org Discussion List] Subject: [isalist] Re: Port Ranges http://www.ISAserver.org Not if you're referring to a collection of primary connections. What you need to do in this caase is create each individual protocol definition. If the protocol uses a single primary port and many secondary ports, then yes; a single definition can do the job. Jim Harrison MCP(NT4, W2K), A+, Network+, PCG http://isaserver.org/Jim_Harrison/ http://isatools.org Read the help / books / articles! On Tue, 21 Oct 2003 10:33:44 +0100 "Stuart Pittwood" <SPittwood@xxxxxxxxxxxxxxxxx> wrote: http://www.ISAserver.org Is it possible to create a protocol definition that contains a range of ports? lets say I wanted to publish a server on the following TCP ports 3202 to 3302 would I need to create 100 different protocol definitions? Regards Stu A full list of partners in Amery-Parkes is available for inspection at all of our offices. Information contained in this e-mail is intended for the use of the addressee only, and is confidential and may be the subject of Legal Professional Privilege. Any dissemination, distribution, copying or use this communication without prior permission of the addressee is strictly prohibited. The contents of an attachment to this email may contain software viruses which could damage your own computer system. Whilst Amery-Parkes has taken every reasonable precaution to minimise this risk, we do not accept liability for any damage which you sustain as a result of software viruses. You should carry out your own virus checks before opening any attachment to this email. ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jim@xxxxxxxxxxxx To unsubscribe send a blank email to $subst('Email.Unsub') ^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^* All mail from this domain is virus-scanned with RAV. www.ravantivirus.com ^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^* ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: spittwood@xxxxxxxxxxxxxxxxx To unsubscribe send a blank email to $subst('Email.Unsub') ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jim@xxxxxxxxxxxx To unsubscribe send a blank email to $subst('Email.Unsub') ^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^* All mail from this domain is virus-scanned with RAV. www.ravantivirus.com ^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^* ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: spittwood@xxxxxxxxxxxxxxxxx To unsubscribe send a blank email to $subst('Email.Unsub') ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jim@xxxxxxxxxxxx To unsubscribe send a blank email to $subst('Email.Unsub') ^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^* All mail from this domain is virus-scanned with RAV. www.ravantivirus.com ^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^*^* ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: spittwood@xxxxxxxxxxxxxxxxx To unsubscribe send a blank email to $subst('Email.Unsub')