Ask a questionAsk a question
 

AnswerISA 2000 Filter question

  • Tuesday, June 16, 2009 10:01 AMandrewcrystal Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    Hi all,

    We have had our SBS server in for many years now and it is all running very smoothly.

    However, we recently installed some new Health and Safety software that does automatic updates, to do this we installed a database server on our server then a liveupdate programs on one of the client machines.  The update program uses port 2069 so I did what I thought would open the port correct to let the program access the net.

    Custom Filter
    Direction: Inbound
    Local Port Fixed
    Port Number: 2069
    Remote Port: All Ports

    This wouldnt work but we thought it was perhaps that the program wasnt setup to use the proxy server so we added that in and it appears to be using that.  However, whatever we do I cannot get the update program to access the internet and the developers say they do not know enough about ISA to understand why it is not working.

    Any help would be greatly appreciated as I have tried everything I can think of (including altering the filter settings above to other options - possibly not the right ones mind! lol).
     

Answers

All Replies

  • Tuesday, June 16, 2009 10:21 AMMarc.GroteMVPUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    Hi,

    if the program on the Server should access the Internet for updates, you have to create a protocol definiton with direction outbound.

    regards Marc
    www.nt-faq.de
    www.it-training-grote.de
  • Tuesday, June 16, 2009 5:48 PMElMajdalMVP, ModeratorUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Proposed Answer
    Custom Filter
    Direction: Inbound
    Local Port Fixed
    Port Number: 2069
    Remote Port: All Ports


    Hi,

    Inbound ports are used for Publishing rules, but in your case, you want yours software to get the updates from the Internet, so what you will need is to change it to Outbound .

    You might need also to set your client as SecureNet client or Firewall Client.

    HTH,
    Tarek

    _______________________________

    Tarek Majdalani
    MS Forefront Edge Security MVP
    http://www.elmajdal.net