• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Allowing SFTP thru TMG

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [Threat Management Gateway (TMG) 2010] >> General >> Allowing SFTP thru TMG Page: [1]
Login
Message << Older Topic   Newer Topic >>
Allowing SFTP thru TMG - 30.Jan.2012 3:18:13 PM   
eastmarw

 

Posts: 50
Joined: 11.Sep.2008
Status: offline
I have created an ACCESS RULE to allow SFTP traffic but for the life of me it is not working as I would expect it to. Since TMG does not come with a standard SFTP portocol I created a user defined protocol, that allows TCP port 22 and Outbound as the direction. I also created a Computer Object which is the backend webserver, that it is allowed to communicate to.

The Access rule is from everywhere, to the web server.
If I test the rule by using Filzilla, with the above configuration I don't see anykind of hit on the rule. If I change the Access Rule to to "All networks" as the "TO then I see hits on the rule but I get:

0x80074e21 FWX_E_ABORTIVE_SHUTDOWN and the Status states, "A connection was abortively closed after one of the peer ssent an RST packet".

Am I missing something in this access rule?

< Message edited by eastmarw -- 30.Jan.2012 8:36:46 PM >


_____________________________

Dream On Alice, This Ain't Wonderland
Post #: 1
RE: Allowing STFP thru TMG - 30.Jan.2012 5:46:16 PM   
railfan

 

Posts: 62
Joined: 13.Sep.2011
Status: offline
Read this article:  (This is for ISA 2006 but still valid for TMG)

http://www.isaserver.org/tutorials/Enabling-Secure-FTP-Access-Through-ISA-2006-Firewalls-Part1.html

(in reply to eastmarw)
Post #: 2
RE: Allowing SFTP thru TMG - 30.Jan.2012 8:36:17 PM   
eastmarw

 

Posts: 50
Joined: 11.Sep.2008
Status: offline
This article deals with FTP and FTPS. I am trying to allows access with SFTP or otherwise know as SSH File Transfer Protocol.

(in reply to railfan)
Post #: 3
RE: Allowing SFTP thru TMG - 30.Jan.2012 11:45:21 PM   
railfan

 

Posts: 62
Joined: 13.Sep.2011
Status: offline
As far as the TMG is concerned, SFTP or FTPS is the same as they are encrypted communication.  Try this link.  Someone in this forum claims he has success with the sFTP traffic.

http://qa.social.technet.microsoft.com/Forums/en-AU/Forefrontedgegeneral/thread/9d541e2f-4aae-4c72-a367-be32dd47438c

(in reply to eastmarw)
Post #: 4
RE: Allowing SFTP thru TMG - 1.Feb.2012 4:57:14 AM   
romvdmeulen

 

Posts: 105
Joined: 5.Aug.2011
Status: offline
To use SFTP through TMG you need to extend the SSL port range. There's a tool in "ISATOOLS" which can do that for you.

On a cmd type
> cscript isa_tpr.js /add SSH 22

It will add port 22 (ssh) to the SSL port range and enables TMG to handle the traffic. Be aware you prolly need it un-authenticated.

good luck!

(in reply to railfan)
Post #: 5
RE: Allowing SFTP thru TMG - 1.Feb.2012 4:59:57 AM   
romvdmeulen

 

Posts: 105
Joined: 5.Aug.2011
Status: offline
quote:

ORIGINAL: railfan

As far as the TMG is concerned, SFTP or FTPS is the same as they are encrypted communication.  Try this link.  Someone in this forum claims he has success with the sFTP traffic.

http://qa.social.technet.microsoft.com/Forums/en-AU/Forefrontedgegeneral/thread/9d541e2f-4aae-4c72-a367-be32dd47438c
Not true.
SFTP (SSH FTP, port 22) is not equal to FTPS (FTP Secure, port 443). SFTP is "proxy friendly" since it is only using one port, not two like the regular FTP protocol. SFTP is "just" an SSH session for file transfer operating on port 22.

(in reply to railfan)
Post #: 6
RE: Allowing SFTP thru TMG - 1.Feb.2012 8:42:28 AM   
railfan

 

Posts: 62
Joined: 13.Sep.2011
Status: offline
I am well aware of the differences between SFTP and FTPS, probably I didn't word it right.  Without getting into details, basically ISA/TMG has no clue what's happening in the secure channel in SFTP and FTPS.  So I meant to say there are quit a few things one has to do manually to allow these protocols.  Having said that, I would strongly recommend you read the RFC docs related to the aforementioned protocols.   

< Message edited by railfan -- 1.Feb.2012 8:53:30 AM >

(in reply to romvdmeulen)
Post #: 7
RE: Allowing SFTP thru TMG - 10.Feb.2012 10:36:27 AM   
clarkedragon

 

Posts: 45
Joined: 22.Apr.2009
Status: offline
Just as an additional note that may or may not help you, In my experience with TMG to get any type of FTP or FTP like service to work the client needs to have the TMG client installed and active.

Patrick

(in reply to railfan)
Post #: 8
RE: Allowing SFTP thru TMG - 14.Feb.2012 3:06:59 PM   
poiuy

 

Posts: 82
Joined: 20.Oct.2005
Status: offline
There is already a system Protocol for SSH in TMG on Port 22. You may try using that one instead of the user Defined.

You will have to look under All Protocols to find it, but it is there.

I have a rule setup to allow SSH from Internal to a Specific External Client and it is working without issue. I however do not have any incoming publishing rules using SSH.

_____________________________

poiuy the Nemisis of qwerty

(in reply to clarkedragon)
Post #: 9

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [Threat Management Gateway (TMG) 2010] >> General >> Allowing SFTP thru TMG Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts