ISA Ping??

  Hi everyone

  I've recently installed as ISA 2000 Server on a SmallBusiness 2000 Server (Windows 2000 SP4/AC/Exchange/ISA in one server). I have 2 NIC's in the server, the "external" NIC is directly connected to a ADSL modem, and has a defined IP.

  The local clients can ping the "internal" interface, but i cant ping the external interface on the server, from another computer on the internet, ex. my own machine at my home. I can port scan the server, but my scanner says it a dead "ping dead" server, and once in a while it detects port 80, even if i havent published a web server :-| When the ISA wasnt installed i could easily ping the server, even port scan the server (dont worry, its experimental, and its my own server).

  All outgoing traffic is almost blocked. My exchange POP3 connector cant retrieve mail, and my SMTP connector can send mail. My Real player cant stream anymore. And my symantec antivirus, and sybari antigen can update their virus definitions and scanners.

  What am i doing wrong?
looks like your ISA Server is blocking ICMP traffic on the external Interface.
If you want to ping the Server from outside you have to allow ICMP Traffic. I think the default in ISA Server is blocking ICMP.
cheers, jochen.
If I may note somthing here;
I think it is a good idea for you to keep the ICMP traffic closed because keeping it open will enable an attacker study your network and react in a way which may be harmful.

I also think, as _Jochen_ that the ICMP traffic is blocked. And the ISA Server suppose to do that...

Do you need a walkthrough on how to open the ports?

ShaohsAuthor Commented:
If you have one, i would be delighted. :-)
ShaohsAuthor Commented:
My second wish will be:

  What should i do about Real Player? I've opened 1090 but it still wont stream.

Third wish:

  When you open a UDP port, i got alot more choices in the trafic direction than TCP. TCP only has Inbound, Outbound and Both. UDP have 5 options. Whats the difference between these 5 options, and is it important to any "normal" applications that they should be opened?
Ron MalmsteadInformation Services ManagerCommented:
Block rules take precedent over allow rules....if you do not have an "allow all traffic" "any protocol" on "any interface" rule...then you have no access, at all, to any external destinations..(your public ip is external)...these rules are created by default on sure you didn't delete them.


I think the subject has been covered (that is unless things are not working properly for you);
Now, where is my lamp?

ShaohsAuthor Commented:
I think i got it now. I just had to set the "BackOffice Internet Access Protocol Rule" and the "BackOffice Internet Access Site and Content Rule" source to a client set with all the local ip's in. Now everyone can stream, and everything.

I created a rule in the packet filtering that allowed outgoing TCP 110 POP3 and outgoing TCP 25 SMTP. That did the trick about the mail.
I also add'ed a packet filter that deny incoming port 80. I noticed in a port scan that it was open for no reason. I cetainly didnt ask it to open port 80.

Pretty simple, once you get the hang of it.

Thanks for the answers. :)
Software Firewalls

