• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Blocking ports

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 Firewall] >> General >> Blocking ports Page: [1]
Login
Message << Older Topic   Newer Topic >>
Blocking ports - 1.Feb.2003 11:23:00 AM   
kohinoor

 

Posts: 13
Joined: 30.Jul.2002
From: Karachi
Status: offline
hi
i want to block some ports guide me through the rest.

Thanks
Post #: 1
RE: Blocking ports - 1.Feb.2003 11:32:00 AM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Imran,

what to you want to achieve? Keep in mind that ISA server is designed along the concept that everything is denied unless expressely allowed.

ISA's outbound access control is based on protocol and site&content rules. Basically a client is granted/denied access to a service with a protocol rule and to a destination with a site&content rule. The inbound access control is based on web and server publishing rules.

HTH,
Stefaan

(in reply to kohinoor)
Post #: 2
RE: Blocking ports - 1.Feb.2003 11:48:00 AM   
kohinoor

 

Posts: 13
Joined: 30.Jul.2002
From: Karachi
Status: offline
hello

thanks for your kind reply

my network was hit by sql slammer therefore Microsoft & Trend Micro recommends me to block port 1434 that's why i want to block port 1434.
Currently i set my ISA to allow all IP traffic.

(in reply to kohinoor)
Post #: 3
RE: Blocking ports - 1.Feb.2003 12:01:00 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Imran,

what do you exactly mean with "Currently i set my ISA to allow all IP traffic"? Which protocol rules and IP packet filters have you in place? Do you publish an SQL server?

BTW --- if you have an all open IP packet filter, remove it immediately! You are in big danger.

HTH,
Stefaan

(in reply to kohinoor)
Post #: 4
RE: Blocking ports - 1.Feb.2003 12:21:00 PM   
kohinoor

 

Posts: 13
Joined: 30.Jul.2002
From: Karachi
Status: offline
hello

I'm not publishing my Sql server on the Internet but I allowed all IP traffic in Protocol rules in my ISA server. My network has ISA server, SQL server, Exchange server. There are so many complaints of network slow down bcuzz of Slammer, plz guide wht do i do.

Thanks in advance

(in reply to kohinoor)
Post #: 5
RE: Blocking ports - 1.Feb.2003 1:17:00 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Imran,

if you don't have an all open IP packet filter and don't publish an SQL server, then ISA should already block inbound access to the TCP port 1434. You can verify it by looking into the IP packet filter log. If you don't find them, try a 'telnet external_IP_address 1434' from an external station. The connection should *not* succeed and you should find the blocked request in the IP packet filter log.

HTH,
Stefaan

[ February 01, 2003, 01:20 PM: Message edited by: spouseele ]

(in reply to kohinoor)
Post #: 6

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 Firewall] >> General >> Blocking ports Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts