|
spouseele -> RE: How the FTP protocol Challenges Firewall Security article (19.Mar.2003 9:28:00 PM)
|
Hi stefano,
if you run the FTP server on the standard port number, than you should *not* install the firewall client on the FTP server and just configure the FTP server as a SecureNAT client. That means that his default gateway should point to the ISA server internal interface.
Also, there is only one FTP application filter and it is under the node Extension -> Application Filters. Moreover, as a general rule you should *never* create packet filters yourself except in some very specific situations. The protocol, site&content and publishing rules will create the needed packet filters dynamically for you.
Keep in mind that you can *not* loop through the ISA external interface. This means that internal clients should always connect to the internal servers directly, not to the published instance. For more info, check out http://www.isaserver.org/articles/14120_Errors_Discussion_and_Solution.html .
HTH, Stefaan
|
|
|
|