|
rebelpeon -> Port Triggering? (9.May2006 8:48:41 PM)
|
I'm currently having a problem with being able to send traffic from the perimeter to internal network. It seems if I start something (like pinging) from the internal to the perimeter something on ISA is triggered, which then allows me to ping from the perimeter to the internal. However, after some time, ISA closes this connection, and I'm not able to ping or anything else from the perimeter to the internal network. The ISA server is setup as a back firewall in the diagram below. Machine A is in the perimeter network and Machine B is in the internal network. (external/internet) router | |(perimeter/192.168.1.0)Machine A | ISA | (internal/192.168.2.0)Machine B The firewall rules for pinging is from source all protected networks to destination all protected networks. The RDP rule is for the RDP protocol to protected networks from potected networks. The network rule for perimeter - internal is routed, as is the internal - external rule. Machine A has a static route for the 192.168.2.0 network with a gateway of the ISA machine's IP on the 192.168.1.0 NIC. As I said, I can't ping Machine B from Machine A until I first ping Machine A from Machine B. However, after some time, ISA appears to close this connection so I can't ping Machine B from Machine A again. If I have an RDP rule setup the same thing happens, where I can't RDP into machine B from machine A, unless I first ping from machine b to machine a to "open" the connection. I was just wondering what exactly I have setup incorrectly, or if this is "expected" functionality? *Edit* I also forgot to mention the logs. When I can't ping from Machine A to Machine B, nothing shows up in the ISA logs, and nothing connects to the internal ISA NIC when viewed through netmon. Now, if i run ping -t from Machine B to Machine A, as soon as I ping from machine A to B, the a>b ping shows up, and then the b>a ping shows up right after it in the isa logs (and of course pinging machine a to b then works).
|
|
|
|