Posts: 173
Joined: 29.May2002
From: Middelburg, South Africa
Status: offline
Hi there
I am currently struggling with some VPN issues and as a result I am constantly monitoring my ISA Logs.
I have an ISA server on the "internal" side of my network with a PIX firewall on the perimeter and I have just noticed the following in my Packet Filter Logs: 9/4/2002, 9:01:17, <ISA External Intf>, <PIX Internal Intf>, Udp, 1025, 137, -, BLOCKED, <ISA External Intf>
My understanding of this message is that ISA Server is denying ISA Server to send NetBIOS Name Sessions out to my PIX firewall. This prompts 2 questsions: 1) Why does ISA (on behalf of someone on the local LAN I presume) need to send an outbound NetBIOS Name Service request 2) I am currently only allowing FTP, HTTP and HTTPS protocols, should I be allowing NetBIOS Datagram, NetBIOS Name Service and NetBIOS Session as well?
I've run into the same problem. I have what I consider to be optimal DNS configurations on all my networks, but still my packet filter logs are littered with NetBIOS packets being blocked. I suspect the issue is related to inbound requests, but exactly how has escaped me so far.
If you come up with an answer, you'll be our ISA Server Hero of the month!