• Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Restrict virtual connection port

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> Firewall Client >> Restrict virtual connection port Page: [1]
Message << Older Topic   Newer Topic >>
Restrict virtual connection port - 6.Sep.2004 7:57:00 PM   


Posts: 8
Joined: 20.Aug.2004
Status: offline
Hi all,

Is it possible to restrict the port range ISA uses for the virtual connection containing data sent from and to the Firewall Client? We have another firewall between our clients and ISA, and our firewall guys don't want to open all ports.

As I understood it, the FWC uses TCP 1745 for the control connection through which it receives an arbitrary port > 1024 from the server, and then establishes a connection to this high port for the "real data".

Thanks a lot,
Post #: 1
RE: Restrict virtual connection port - 7.Sep.2004 3:35:00 PM   


Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Frank,

The Firewall client connects directly to the Firewall service using 1745 to negotiate protocols and obtain name resolution information. After that, the client connects to the site using the protocols required.

So, you must allow the required traffic through all firewalls. The best plan and the one I always use is put the ISA firewall in front of the users and make the ISA firewall a member of the domain.

Any firewall should be able to perform at least stateful filtering, so the packet filter admins shouldn't have to 'open ports'.


(in reply to Groer)
Post #: 2

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> Firewall Client >> Restrict virtual connection port Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts