RE: Protocol question

  • From: "Thomas W Shinder" <tshinder@xxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Thu, 7 Apr 2005 13:55:33 -0500

Hi Dan,

Or use IPSec domain isolation
http://www.microsoft.com/downloads/details.aspx?FamilyId=404FB62F-7CF7-4
8B5-A820-B881F63BC005&displaylang=en 

HTH,

Tom
www.isaserver.org/shinder
Tom and Deb Shinder's Configuring ISA Server 2004
http://tinyurl.com/3xqb7
MVP -- ISA Firewalls


-----Original Message-----
From: Ball, Dan [mailto:DBall@xxxxxxxxxxx] 
Sent: Thursday, April 07, 2005 1:55 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Protocol question

http://www.ISAserver.org

I like the previous idea better.  Put the computer in a DMZ, and run
whatever the heck you want, forget about trying to pass through ISA.
That only requires one more NIC, and you don't have to go into the
LinkSys/double-NAT fiasco.   Only catch; you'd better reformat that
computer before putting it back on the internal side of the ISA...

If you absolutely HAVE to have it on the internal network, then take the
below listed method and lock it down even more.  Define exactly WHICH
clients are allowed to connect with WHICH servers, with WHAT protocols.
Then, in order to exploit those holes they have to impersonate those
particular servers, and can only get to that one computer if they do.

-----Original Message-----
From: Steve Moffat [mailto:steve@xxxxxxxxxx] 
Sent: Thursday, April 07, 2005 14:17
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Protocol question

http://www.ISAserver.org

OK

Here we go

Create 2 new protocols

1. port 3724 TCP outbound

2. port 3724 TCP inbound

Create an allow rule using the above protocols for the pc that you are
going to use to play the game, make sure the firewall client is
installed.

Start the game, monitor the isa logs to see what other ports are needed,
inbound and outbound. Create protocols and add to the rule when needed.

Jeez.......I got it working in 20 mins.

S

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
World of Windows Networking: http://www.windowsnetworking.com
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
tshinder@xxxxxxxxxxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist
Report abuse to listadmin@xxxxxxxxxxxxx




Other related posts: