• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

RE: Starband on ISA box

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 General] >> Installation >> RE: Starband on ISA box Page: <<   < prev  1 [2]
Login
Message << Older Topic   Newer Topic >>
RE: Starband on ISA box - 6.Aug.2001 8:35:00 PM   
bjames

 

Posts: 21
Joined: 22.Apr.2002
From: Washington, D.C.
Status: offline
Latest attempts have been driving me nuts. I spent the weekend getting real intimate with rmisa.exe <G>.
Previously, I've had great success publishing the web server with multiple sites and host headers working. Now, I can't get the listener going without crashing the isa control and the scheduled caching service. Maddening? You bet. I put off the web sites for now - all IIS services are stopped except SMTP outbound so I can send email out from some winsock apps that don't have the option of providing authentication to starband's smtp server.
Tom - I saw something about a problem with IP Pooling. Might I be another victim of this?
And on packet filtering - I have it enabled now along with ID and IP routing. However, my exernal IP is included in the LAT. I doubt it should be there, but before this point I've been seeing a firewall error that it couldn't route to the external address, so I threw it in there with the internal address range. Well, now no more error, but not reporting port scans either.

Kevin - I am meaning to nail down the ports that the RPA wants to dedicate too. Sofar, with default packet filtering set I haven't lost any functionality with chaining to as_agent, all traffic gets through. I have the secondary route set as direct to internet and there's a noticable performance drop when the rpa is bypassed. I'm not sure how crucial the nettgain2k is for good performance on the 360 yet, but the general consensus in the user groups has been to run rpa.

I'll be hammering on it some more later tonight.


(in reply to bjames)
Post #: 21
RE: Starband on ISA box - 7.Aug.2001 5:11:00 AM   
kwestby

 

Posts: 12
Joined: 22.Apr.2001
Status: offline
Bill - I think I have the RPA ports down now...at least according to the tackbar icon.

Open up a bidirectionl filter for all local ports with port 9876 on the HPA IP Address. Not sure if the HPA IP address is a single host or not. You can right click and select Setup on the RPA icon to get the correct remote IP address.

I still haven't got the Mission Control filter settings yet.

Tom - Will disabling the IP Routing result in the external interface having a more "stealth" appearance to external scans? Any downside to disabling IP Routing?

- Kevin

------------------
/*
Kevin Westby
email@kevinwestby.com
http://www.kevinwestby.com
*/


(in reply to bjames)
Post #: 22
RE: Starband on ISA box - 7.Aug.2001 6:02:00 AM   
kwestby

 

Posts: 12
Joined: 22.Apr.2001
Status: offline
Bill - Looks like required Mission Control packet filter is:

All local UDP ports, Send receive, All remote ports on host 192.168.255.252.

Not sure I understand that one.....but it's keeping my MC status icon in the green.

Do you know if it's possible to use Protocol Rules for inbound traffic? The only other alternative to the above packet filter rule might be a protocol rule that sets up the primary port and then some secondary ports.

I can't locate any files which look like NetGain2K files....do you know specifically which ones constitute NetGain (I had thought that that's what the RPA was)?

- Kevin

------------------
/*
Kevin Westby
email@kevinwestby.com
http://www.kevinwestby.com
*/


(in reply to bjames)
Post #: 23
RE: Starband on ISA box - 7.Aug.2001 5:57:00 PM   
bmonahan

 

Posts: 1
Joined: 7.Aug.2001
From: Marysville, WA USA
Status: offline
Are you guys using the RJ45 connection to your Starband modem or the USB port? The reason I ask is that every time I install ISA on me server (I am using the USB port) The Mission Control light goes black and I lose my connection to the internet. Once I uninstall ISA the Misson Control light comes back on and I have internet connection. Any advice is greatly appreciated...

(in reply to bjames)
Post #: 24
RE: Starband on ISA box - 7.Aug.2001 9:35:00 PM   
kwestby

 

Posts: 12
Joined: 22.Apr.2001
Status: offline
I am using the RJ45 connection on the 360 modem.

Prior to my upgrade I used the RJ45 on the 180 and experienced a similar behavior (as well as with the 360). You basically need to open up some ports (see above) to allow the Mission Control application to communicate.


Bottom line: Mission Control will not work with a default ISA configuration, you will need to "open up" the necessary protocols/ports. But that's to be expected :-).

- Kevin

------------------
/*
Kevin Westby
email@kevinwestby.com
http://www.kevinwestby.com
*/


(in reply to bjames)
Post #: 25
RE: Starband on ISA box - 7.Aug.2001 10:59:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
quote:
Originally posted by bjames:
Latest attempts have been driving me nuts. I spent the weekend getting real intimate with rmisa.exe <G>.
Previously, I've had great success publishing the web server with multiple sites and host headers working. Now, I can't get the listener going without crashing the isa control and the scheduled caching service. Maddening? You bet. I put off the web sites for now - all IIS services are stopped except SMTP outbound so I can send email out from some winsock apps that don't have the option of providing authentication to starband's smtp server.
Tom - I saw something about a problem with IP Pooling. Might I be another victim of this?
And on packet filtering - I have it enabled now along with ID and IP routing. However, my exernal IP is included in the LAT. I doubt it should be there, but before this point I've been seeing a firewall error that it couldn't route to the external address, so I threw it in there with the internal address range. Well, now no more error, but not reporting port scans either.

Kevin - I am meaning to nail down the ports that the RPA wants to dedicate too. Sofar, with default packet filtering set I haven't lost any functionality with chaining to as_agent, all traffic gets through. I have the secondary route set as direct to internet and there's a noticable performance drop when the rpa is bypassed. I'm not sure how crucial the nettgain2k is for good performance on the 360 yet, but the general consensus in the user groups has been to run rpa.

I'll be hammering on it some more later tonight.


Hi Bill,

And it seemed to be working so well!

Not good to put the exteranl interface in the LAT. That makes the exteranl interfaces a trusted network, and spoofers can have a heyday with that configuration. When you put the exteranl interface in the LAT, you essentially have no more external network.

I assume that there is *no* packet filtering when the external interface is in the LAT, because the packet filters only apply to the exteranl interface, which is defined by the LAT!

Not sure why your sevices are crashing. Could be the DHCP procoess and address reassignment?

Sounds like you're having fun, though

Tom

------------------
http://www.isaserver.org/shinder/



Get It Here!


(in reply to bjames)
Post #: 26
RE: Starband on ISA box - 7.Aug.2001 11:02:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
quote:
Originally posted by kwestby:
Bill - I think I have the RPA ports down now...at least according to the tackbar icon.

Open up a bidirectionl filter for all local ports with port 9876 on the HPA IP Address. Not sure if the HPA IP address is a single host or not. You can right click and select Setup on the RPA icon to get the correct remote IP address.

I still haven't got the Mission Control filter settings yet.

Tom - Will disabling the IP Routing result in the external interface having a more "stealth" appearance to external scans? Any downside to disabling IP Routing?

- Kevin



Hi Kevin,

What do you see on your port scans? You should see only ports that you've opened for packet filters, publishing rules, and dynamic packets filters (which will only accept data from the server that an outbound request was made to).

HTH,
Tom

------------------
http://www.isaserver.org/shinder/



Get It Here!


(in reply to bjames)
Post #: 27
RE: Starband on ISA box - 8.Aug.2001 4:37:00 AM   
bjames

 

Posts: 21
Joined: 22.Apr.2002
From: Washington, D.C.
Status: offline
quote:
Originally posted by tshinder:
Hi Bill,

And it seemed to be working so well!



How I wish. I knew I was in trouble when all the deliberate port scans I initiated on myself generated nothing in the alerts. But putting the external IP into the LAT and having that cure the 14120 error I have been seeing endlessly in my sleep was a little unsettling. I'm more convinced than ever now that the IP pooling is thwarting me here.

Here's a list of the current listens right now:

Active Connections

Proto Local Address Foreign Address State
TCP 0.0.0.0:25 0.0.0.0:0 LISTENING
TCP 0.0.0.0:53 0.0.0.0:0 LISTENING
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1025 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1026 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1029 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1720 0.0.0.0:0 LISTENING
TCP 0.0.0.0:3007 0.0.0.0:0 LISTENING
TCP 0.0.0.0:3008 0.0.0.0:0 LISTENING
TCP 0.0.0.0:3013 0.0.0.0:0 LISTENING
TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING
TCP 0.0.0.0:9877 0.0.0.0:0 LISTENING
TCP 0.0.0.0:12643 0.0.0.0:0 LISTENING
TCP 0.0.0.0:12670 0.0.0.0:0 LISTENING
TCP 0.0.0.0:12671 0.0.0.0:0 LISTENING
TCP 0.0.0.0:12675 0.0.0.0:0 LISTENING
TCP 0.0.0.0:12882 0.0.0.0:0 LISTENING

Now would this be a conflict between the Win2k routing table and the LAT? I'm at a loss here.

Fighting on though..
- Bill James


(in reply to bjames)
Post #: 28
RE: Starband on ISA box - 8.Aug.2001 3:36:00 PM   
bjames

 

Posts: 21
Joined: 22.Apr.2002
From: Washington, D.C.
Status: offline
Kevin: I looked over netstat on the 180's port usage and you seem to have it right on with the port 9876 connection. I'm not using the mission control at all on my setup, so that, coupled with the continuing saga of my configuration is keeping me from chasing that one down with you. Either way, we're getting closer to full ops.

Back to basic ISA config though..
Ever look at something so many times you don't even see what it is anymore?
My LAT blues were cased by my LAT being wrong. Took a look at the win2k routing table and then it was obvious. Fixed that.
I can enable packet filtering now and it's blocking as it should be. Blocking everything - even the allow filters I have enabled. I am getting an error for Packet filtering now (11003) -

Microsoft ISA Server Control failed. The
failure occurred during Reading packet filters
because the configuration property
LocalHostIPAddress of key
SOFTWARE\Microsoft\Fpc\Arrays\{F237530C-5DA7-
4E92-82D2-35A144A7FC17}\ArrayPolicy\Proxy-
Packet-Filters\{291DD86A-E5EA-4C93-B975-
2E97546F5768} is not valid.
The error description is: An invalid argument was
supplied.

Fun. I'll check that one after at least another cup of coffee.


(in reply to bjames)
Post #: 29
RE: Starband on ISA box - 9.Aug.2001 4:57:00 AM   
kwestby

 

Posts: 12
Joined: 22.Apr.2001
Status: offline
Bill - You should be able to determine which rule has the invlaid param, delete it, restart services and see if you still get the error. If no error, readd the rule and see how it goes.

Let me know how it goes.

I've recently started dropping my ip address for some reason and it isn't re-establishing :-(. Gonna go check SBUsers to see if anyone else has similar issue.

------------------
/*
Kevin Westby
email@kevinwestby.com
http://www.kevinwestby.com
*/


(in reply to bjames)
Post #: 30
RE: Starband on ISA box - 9.Aug.2001 5:14:00 AM   
kwestby

 

Posts: 12
Joined: 22.Apr.2001
Status: offline
Tom,

I've been checking my site via grc.com. It immediately detects an open port 139. After that the more complete port scan shows multiple ports open 21, 23, 25, 79....etc. Doing a fport /p shows a few of those ports, but not all....may be something on the grc.com site. But I'm still looking for a way to verify the state of my external interface. Any ideas?

------------------
/*
Kevin Westby
email@kevinwestby.com
http://www.kevinwestby.com
*/


(in reply to bjames)
Post #: 31
RE: Starband on ISA box - 10.Aug.2001 2:46:00 AM   
bjames

 

Posts: 21
Joined: 22.Apr.2002
From: Washington, D.C.
Status: offline
Hi Kevin,
I couldn't find the error with the filter in question (dns client) so I simply disabled it. That cleared that for now..
Firewall comes up, blocks everything, ID works but back comes that 14120 error!
Holy cow.

Now as for your port 139, that's the netbios over TCP/IP. You need to goto your tcp settings for the external nic and disable it on the tcp/ip advanced properties tab. Unbind client for MS networks too while you're at it. Those are the some of the first things that I axe during any server setup.

Still no 360.. grrr.
- Bill


(in reply to bjames)
Post #: 32
RE: Starband on ISA box - 8.Oct.2001 8:15:00 PM   
cking2

 

Posts: 2
Joined: 8.Oct.2001
From: Winona, MN -USA
Status: offline
I was running ISA on Win2k with the USB 180 modem. When I upgraded to the 360 using the network interface, everything still worked pretty good except that I have the DHCP renewal problem. I am doing packet filtering and have enabled the 'allow' filter for DHCP but it does not work. Ever!

The only way I can get a new lease is by rebooting or shutting of all of the ISA services and doing an IPCONFIG /renew.

I did not have this trouble with the 180 and I have not tried the USB interface on the 360. I would really like to find a fix. None of those listed in the many posts on this seem to work.

-ck


(in reply to bjames)
Post #: 33
RE: Starband on ISA box - 9.Oct.2001 6:47:00 AM   
bjames

 

Posts: 21
Joined: 22.Apr.2002
From: Washington, D.C.
Status: offline
I just went to the 360 as well and I'm seeing the same thing. But I'm additionally hindered in the packet filtering dept by the latest build of .net server. Looking for a good fix as well.

(in reply to bjames)
Post #: 34

Page:   <<   < prev  1 [2] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 General] >> Installation >> RE: Starband on ISA box Page: <<   < prev  1 [2]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts