• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

RIP Listener

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> Access Policies >> RIP Listener Page: [1]
Login
Message << Older Topic   Newer Topic >>
RIP Listener - 9.Aug.2006 9:02:37 PM   
mgfirewall

 

Posts: 7
Joined: 9.Aug.2006
From: OC
Status: offline
I'm having trouble allowing RIP traffic to my firewall.  Below is my scenario:

ISA Server 2004 on Windows Server 2003, all patches and service packs installed.  SonicWALL 4060 firewall as default route, RAS server for dial backup for remote sites.  Remote site has Netopia R9210 router, connects via VPN policy to SonicWALL, remote clients use ISA for proxy.  When remote site DSL goes down, Netopia then dials into the RAS server and RIP broadcasts route change.  All servers and clients with RIP Listener installed pick up the change and route traffic accordingly.  The ISA server sees the traffic and logs a Denied Connection.  I've set a rule in ISA that allows protocol RIP to and from All Networks however it is still denied.  There is no rule specified in the monitor for why it is denied, just drops it.

I'm sure I missed something here, any clues out there?
Post #: 1
RE: RIP Listener - 9.Aug.2006 9:46:54 PM   
ClintD

 

Posts: 1848
Joined: 26.Jan.2001
From: Keller, TX
Status: offline
When you're in the Logging section, go to the View menu and select Add/Remove columns. Add all of the fields from the left to the right side. once they're added, log the RIP traffic getting denied again and look for the Result Code field - this usually helps illustrate why the traffic was denied.


(in reply to mgfirewall)
Post #: 2
RE: RIP Listener - 9.Aug.2006 10:33:02 PM   
mgfirewall

 

Posts: 7
Joined: 9.Aug.2006
From: OC
Status: offline
Thanks, I added the Result Code column and get this:

0xc004000d FWX_E_POLICY_RULES_DENIED.

-Mike

(in reply to mgfirewall)
Post #: 3
RE: RIP Listener - 10.Aug.2006 12:36:48 AM   
mgfirewall

 

Posts: 7
Joined: 9.Aug.2006
From: OC
Status: offline
Okay, I've resolved this.  I added the System and Network Services group to the Users Tab.  I had previously just had the All Users group there.  I can't say I understand why this is now working and do not see anything in the docs that states that you need to add this group when setting protocol specific rules but it does work now.  Thanks ClintD for your input, that led me on the right path...

-Mike

(in reply to mgfirewall)
Post #: 4
RE: RIP Listener - 10.Aug.2006 5:58:11 AM   
ClintD

 

Posts: 1848
Joined: 26.Jan.2001
From: Keller, TX
Status: offline
Whoa! Really? That's bogus and weird. I've got to test that one out myself.

You're right - typically, you leave the Users tab alone for this type of traffic (leave it set to All Users). Thanks for the info...

< Message edited by ClintD -- 10.Aug.2006 5:59:34 AM >

(in reply to mgfirewall)
Post #: 5

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> Access Policies >> RIP Listener Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts