Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

UNREAL, NAPSTER

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 General] >> General >> UNREAL, NAPSTER Page: [1]
Login
Message << Older Topic   Newer Topic >>
UNREAL, NAPSTER - 13.Feb.2001 9:06:00 PM   
Mike5558

 

Posts: 23
Joined: 13.Feb.2001
From: Kennedale, TX USA
Status: offline
I find this very sketchy! I can not get Unreal or Napster to work unless I use the firewll Client on my workstations.

I have Unix machines on the network also that want to access these resources, and they are SOL. I have tried opening all the ports, but nothing. In fact, my main outbound rule is to allow ANY protocol!

Help me out here!

Mike

Post #: 1
RE: UNREAL, NAPSTER - 13.Feb.2001 10:35:00 PM   
jmunyan

 

Posts: 800
Joined: 3.Feb.2001
From: Seattle, WA
Status: offline
You need to define a specific protocol rule for napster used ports. There is a note about how to configure isa for napster on the site, only about 5 days old.

(in reply to Mike5558)
Post #: 2
RE: UNREAL, NAPSTER - 13.Feb.2001 6:49:00 PM   
Mike5558

 

Posts: 23
Joined: 13.Feb.2001
From: Kennedale, TX USA
Status: offline
You missed the point. I have a rule that says ANY protocol is allowed. Napster should work with that. Why not?

Unreal has the same problem. Yet I install the Client (SecureNAT Client) and it works. I should not need the client.

Mike


(in reply to Mike5558)
Post #: 3
RE: UNREAL, NAPSTER - 14.Feb.2001 12:53:00 AM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Mike,

When you configure machines as SecureNAT clients, *all protocols* means all the protocols that are included in the protocol definitions node. If the protocol does not have a protocol definition, then the SecureNAT client will not be able to use it, even though you have allowed "all protocols".

To get Napster to work, you could install the Firewall Client, and it will work without doing anything else. However, that won't help your *IX boxes. To enable Napster to work for them, you'll need to configure a protocol definition for Napster. Search this site for instructions on how to do it.

I don't know what Unreal is, but I'm sure you'll need to do the same thing for it.

HTH,

Tom

------------------
Tom Shinder
http://www.isaserver.org/shinder/


(in reply to Mike5558)
Post #: 4
RE: UNREAL, NAPSTER - 14.Feb.2001 8:40:00 PM   
Mike5558

 

Posts: 23
Joined: 13.Feb.2001
From: Kennedale, TX USA
Status: offline
Ok... Good answer.

But I have an IP filter that it set to allow ALL traffic from inside the network on ANY port to get out.

Unreal is a game that uses UDP Ports 7777,7778,7779 for communications.

My ANY IP Filter should allow this but it does not.

Thanks!

Mike


(in reply to Mike5558)
Post #: 5
RE: UNREAL, NAPSTER - 14.Feb.2001 9:36:00 PM   
Guest
hi,

first let me thank whoever is responsible for this forum. i am new to isa & can't find any more material than what's on microsoft's site.

my problem is (among others) with getting through to napster.

i read all these threads & have followed the advice to a tee:
proto defs:
primary port:8875, tcp, out
secondary:6688-6699, tcp, out/in
secondary:7777, tcp, out/in
secondary:8875, tcp, in
secondary:8888, tcp, out/in

proto rules:
enabled, allow, always, any request

stopped & started firewall service, socks4 filter enabled:1080

napster set to socks4, ip, 1080

NO DICE!

here are a few questions that i didn't answers for:
1-in napster do i choose 'download files through proxy' or 'download directly from source'?
2-i have secureNAT on the clients but no other, ie. firewall/web proxy client. don't want it unless i need it. read that i could do everything without it.
3-i have no client sets defined. the setup wizard made it sound like unless i needed to restrict internal clients, that i didn't need client sets?

thanks for your help!

ps - tom, i'm buying your book when it comes out!


(in reply to Mike5558)
  Post #: 6
RE: UNREAL, NAPSTER - 14.Feb.2001 11:39:00 PM   
jmunyan

 

Posts: 800
Joined: 3.Feb.2001
From: Seattle, WA
Status: offline
You may consider creating a protocol rule as you did for Napster for unreal. I think when all ip traffic is selected it is equivilent to all protocols. If a protocol definition does not exist for the required traffic i.e. ports then your access will fail.

John


(in reply to Mike5558)
Post #: 7
RE: UNREAL, NAPSTER - 15.Feb.2001 12:39:00 AM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi John,

You are correct. For SecureNAT clients, all protocols means all protocols that have protocol definitions. When you use the Firewall Client, it mean ALL protocols! Even those that are not included in the protocol definitions.

That's why you can use the Firewall Client, and not do anything on the ISA Server nor configure the Napster client to use a proxy, and everything just works. The Firewall Client manages the connections for you.

As for the protocol definition that I used to make Napster work with the SecureNAT client:

Primary Connection:
TCP Outbound 8875

Secondary Connections:
TCP 6688-6699 Inbound
TCP 8888 Outbound

Then configured the Napster client to use SOCKS 4, internal IP address of ISA Server, and port 1080. Also made sure the SOCKS4 Filter was enabled. Restarted the Firewall Service and Napster, and it worked.

HTH,

Tom

------------------
Tom Shinder
http://www.isaserver.org/shinder/


(in reply to Mike5558)
Post #: 8
RE: UNREAL, NAPSTER - 18.Feb.2001 3:46:00 AM   
Justen

 

Posts: 13
Joined: 18.Feb.2001
From: Manchester, NH, USA
Status: offline
Here is my solution to Unreal. I used netmon to sniff it out. This may be more that what's required, so test it. I use three protocol definitions but it may be possible with fewer.

  • 1st protocol called Unreal 28900 TCP outbound, no secondaries
  • 2nd protocol Unreal2 7778 UDP send/receive, 7770-17000 UDP receive/send secondaries.
  • 3rd protocol Unreal3 7777 UDP send/receive, no secondaries

For Napster, I just configured Napster to use SOCKS4 and port 1080. And to d/l files thru the proxy. Nothing on ISA.

------------------
Charles Ferreira
Systems Engineer, MCSE
Getronics


(in reply to Mike5558)
Post #: 9
RE: UNREAL, NAPSTER - 18.Feb.2001 5:08:00 AM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Justen,

Thanks for sniffing out the Unreal protocol definitions!

Are you using the Firewall Client? You should not be able to access Napster without it unless you create protocol definitions for it.

Thanks!

Tom

------------------
Tom Shinder
http://www.isaserver.org/shinder/


(in reply to Mike5558)
Post #: 10
RE: UNREAL, NAPSTER - 18.Feb.2001 5:35:00 AM   
jstefani

 

Posts: 8
Joined: 2.Feb.2001
From: Temecula, CA, USA
Status: offline
How about BearShare? Has anyone gotten that to work thru ISA Server

(in reply to Mike5558)
Post #: 11
RE: UNREAL, NAPSTER - 19.Feb.2001 8:29:00 AM   
joking

 

Posts: 45
Joined: 13.Feb.2001
From: Phoenix, AZ USA
Status: offline
Tom & Roger,

I have successfully connected / shared files with Napster with the configuration that Roger posted:

primary port:8875, tcp, out
secondary:6688-6699, tcp, out/in
secondary:7777, tcp, out/in
secondary:8875, tcp, in
secondary:8888, tcp, out/in

However, I can only connect from a workstation with the Firewall Client installed. Should not a SecureNAT client be able to work as well - if Napster is configured to use Socks Proxy?

From the previous posts, I think everyone's opinion is yes - but I'm wondering if there are any hidden "gotchas" that I have missed.

In Your Service,

Joseph King, MCSE


(in reply to Mike5558)
Post #: 12
RE: UNREAL, NAPSTER - 19.Feb.2001 8:46:00 AM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Joseph,

Using the configuration I've listed in this thread, I am able to connect and download files from Napster without problems on a Whistler Server running as a SecureNAT client.

I have all protocols open and all site/content open.

No tricks that I can find.

When using the Firewall Client, I don't believe you need to configure Napster to use the SOCKS Proxy, but I haven't tested that for awhile, so I'm not 100% sure on that now.

HTH,

Tom

------------------
Tom Shinder
http://www.isaserver.org/shinder/


(in reply to Mike5558)
Post #: 13
RE: UNREAL, NAPSTER - 19.Feb.2001 9:28:00 AM   
joking

 

Posts: 45
Joined: 13.Feb.2001
From: Phoenix, AZ USA
Status: offline
No, when Firewall Client is active, Napster did not have to be configured to use SOCKS. (Just like in Proxy 2.0 w/ Proxy Client).

I'm still beating it trying to get it to work in on a Secure NAT workstaion.

Perhaps I just need a bigger club...

In Your Service,

Joseph King, MCSE


(in reply to Mike5558)
Post #: 14
RE: UNREAL, NAPSTER - 19.Feb.2001 3:18:00 PM   
Ehud Tam

 

Posts: 38
Joined: 31.Jan.2001
Status: offline
Hi Joseph,
As I wrote in the other post, and as many posts mention.
You only forgot to configure Napster to use SOCKS4 Proxy, type the IP address of the ISA and use port 1080.
Choose DOWNLOAD USING PROXY/FIREWALL.
That should do it.

Tell me how it goes...

------------------
---------------
Ehud Tam
MCSE + Internet


(in reply to Mike5558)
Post #: 15
RE: UNREAL, NAPSTER - 20.Feb.2001 7:23:00 PM   
Justen

 

Posts: 13
Joined: 18.Feb.2001
From: Manchester, NH, USA
Status: offline
I uninstalled the client long ago. Just Napster running thru SOCKS4 on Secure NAT. Unless I have inadvertantly opened the correct port for another application, which is possible.

------------------
Charles Ferreira
Systems Engineer, MCSE
Getronics


(in reply to Mike5558)
Post #: 16
RE: UNREAL, NAPSTER - 22.Feb.2001 8:52:00 PM   
Poperzky

 

Posts: 10
Joined: 16.Feb.2001
From: Salt Lake City, UT USA
Status: offline
Justen, thanks for pointing me to the Unreal ports listing. It now works when I have Firewall client installed, but now as a SecureNats client. Tom, your "open any" rule should allow it to pass shouldn't it? Or do I have to create specific rules as well?

(in reply to Mike5558)
Post #: 17
RE: UNREAL, NAPSTER - 22.Feb.2001 10:35:00 PM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Poperzsky (Terry?),

If you have the right protocol definitions configured, then using the "open all" rule will allow the SNAT client to use them.

HTH,

Tom

------------------
Tom Shinder
http://www.isaserver.org/shinder/


(in reply to Mike5558)
Post #: 18

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 General] >> General >> UNREAL, NAPSTER Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts