• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Access Policy for "All IP Traffic"

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 Firewall] >> General >> Access Policy for "All IP Traffic" Page: [1]
Login
Message << Older Topic   Newer Topic >>
Access Policy for "All IP Traffic" - 9.Feb.2003 12:07:00 PM   
jimmyweston

 

Posts: 11
Joined: 10.Dec.2002
Status: offline
Hi there,

Quick question:
When a Secure NAT user has an access policy that allows him the "All IP Traffic" option, does that mean all conceivable IP traffic or only access to all the Protocol Definitions that have been defined?

For example, I gave a Cisco VPN client All IP Traffic rights just as an experiment and he couldn't connect to his VPN. I thought I would start this way and then narrow it down with other protocol definitions ,but he couldn't even access it with All Ip Traffic rights.

Thanks in advance if someone can clear this up for me.
Post #: 1
RE: Access Policy for "All IP Traffic" - 9.Feb.2003 12:12:00 PM   
spouseele

 

Posts: 12826
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi jimmyweston,

for a SecureNAT client 'all IP traffic' means all defined protocol definitions. However, keep in mind that a SecureNAT can only use simple protocol definitions (no secondary connections) unless there is an application filter on ISA supporting the complex protocols (with secondary connections).

For a Cisco VPN client, do a search in the forums and you will get a lot of posts how to get it working. You might also check out http://support.microsoft.com/default.aspx?scid=kb;en-us;812076 .

The basic setup is:

1. Create two protocol definitions:
- UDP Port 500 Send Receive : this is for the IKE protocol (key negotiation).
- UDP Port XXXX Send Receive : this is for the UDP encapsulated ESP packets. The administrator of the VPN gateway should be able to tell you the exact portnumber to use. For the older versions the port number is mostly 10000. For the latest version, the port number is 4500 by default (IETF NAT-T defined port).

2. Next, create a protocol rule who allows those two created protocols.

3. One thing you must keep in mind is that the client must be a SecureNAT client and that the firewall client must be disabled when setting up the VPN connection. Also, when certificates are involved disable filtering of IP fragments on ISA.

HTH,
Stefaan

(in reply to jimmyweston)
Post #: 2
RE: Access Policy for "All IP Traffic" - 9.Feb.2003 5:19:00 PM   
jimmyweston

 

Posts: 11
Joined: 10.Dec.2002
Status: offline
Hi again,

Thanks for that. I was obvoiusly taking "All IP Traffic" in its literal sense of allowing any and all traffic rather than the narrower definition of "All DEFINED ip traffic"

Thanks for clearing that up for me!

Jimmy

(in reply to jimmyweston)
Post #: 3
RE: Access Policy for "All IP Traffic" - 9.Feb.2003 5:38:00 PM   
spouseele

 

Posts: 12826
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Jimmy,

glad I could help! [Smile]

BTW --- keep in mind that for a Firewall client 'all IP Traffic' means effectively *all* TCP/UDP based protocols.

HTH,
Stefaan

(in reply to jimmyweston)
Post #: 4
RE: Access Policy for "All IP Traffic" - 10.Feb.2003 12:34:00 PM   
jimmyweston

 

Posts: 11
Joined: 10.Dec.2002
Status: offline
Thanks for pointing that out and I'm glad you did as I would have presumed that the Firewall client's "All IP Traffic" would have worked the same way as SNAT's and been restricted to all defined protocols.

I'm also a little surprised as I once tried to configure Kazaa for a user to work through ISA and he was a firewall client. So as an experiment I gave him All IP Traffic rights to see if he could connect to Kazaa and it didn't work until I created the protocol definition for him. Odd!

Regards,
Jimmy

(in reply to jimmyweston)
Post #: 5

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 Firewall] >> General >> Access Policy for "All IP Traffic" Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts