• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Help with internal Ports please ISA 2004

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 General ] >> ISA 2004 SBS >> Help with internal Ports please ISA 2004 Page: [1]
Login
Message << Older Topic   Newer Topic >>
Help with internal Ports please ISA 2004 - 28.Nov.2005 11:13:13 PM   
Cynthia

 

Posts: 5
Joined: 24.Nov.2005
Status: offline
I need to open ports 5432 and 1031 within network. These ports are being used by a Linux box which is accessed by a XP pro workstation. there are both 192.168.X.X and 172.X.X.X in the LAT - because the Linux box is on the 192.168.X.X network the firewall closes the ports when it is accessed from the 172.X.X.X network.  Please help  I would like to avoid these ports being open to the world if possible.  Thank you.
Post #: 1
RE: Help with internal Ports please ISA 2004 - 30.Nov.2005 4:58:38 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Cynthia,

There's something missing here, like a description of your Network Topology.

Are these network IDs part of the same ISA firewall Network, or different ISA firewall Networks?

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to Cynthia)
Post #: 2
RE: Help with internal Ports please ISA 2004 - 30.Nov.2005 6:24:18 PM   
Cynthia

 

Posts: 5
Joined: 24.Nov.2005
Status: offline
Hi Tom

This is on an SBS 2003 SP1 (ISA 2004) I have 3 nics - 1 external 205.X.X.X, 2 internal 192.168.X.X and 172.X.X.X - there are 20 users on the 192 network and 10 users on the 172 network. (the 172 network is required for an application that is hosted at another site and uses static IP's) We have a seperate SQL server on the 192 network which both internal networks access from a SQL application and have no problems. There is a XP Pro computer (SCAN) on the 192 network that runs a JAVA scanning program with a linux server also on the 192 network and which gets data from the SQL server and saves the scans on the linux server.  When the clients from the 192 network access/use the SCAN to access the scanned documents there is no problem. When the clients on the 172 network access SCAN to access the documents the programs runs but they get an error that the database can't be accessed. I found that the ports were being closed by ISA. I have created a new protocol primary connection TCP:5432 and secondary connection as TCP:1031 and I created an access rule that allows the new protocol from the internal network to the internal and host networks for authenticated users and users. Still having the same problem.
 
Thanks for any and all help.
 
Cindy

(in reply to tshinder)
Post #: 3
RE: Help with internal Ports please ISA 2004 - 30.Nov.2005 8:45:11 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Cindy,

OK, I didn't realize that this was an SBS issue. The ISA firewall security model is changed on SBS, so I think the best thing to do at this point is move this to the SBS section. They might be able to help with this.

My observations, from a ISA firewall optimal configuration viewpoint, is that you need to figure out the exact protocol required to access the server resource. Is is a simple protocol requiring a single outbound connection? Or, is it a complex protocol that may require multiple primary and/or secondary connections? If secondary connections are required, you'll either need to develop an application filter to support the protocol, or install the Firewall client on the client system.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to Cynthia)
Post #: 4
RE: Help with internal Ports please ISA 2004 - 3.Dec.2005 10:51:35 AM   
sam_hunter

 

Posts: 46
Joined: 12.Nov.2005
Status: offline
When you open up the real time monitoring log can you see which rule is blocking the traffic?

(in reply to tshinder)
Post #: 5

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 General ] >> ISA 2004 SBS >> Help with internal Ports please ISA 2004 Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts