Solved

URGENT QUESTION

Posted on 2006-06-21
4
197 Views
Last Modified: 2013-12-04
Dear My reader ,

 

I have here something which is confusing me .

 

The Goal which I want to Implement it is :-

 

1-       Disable Internet – Completely – On All Users inside my Network, which they are using Internet through My ISA Server 2004  Std edition.

 

 

How our Infrastructure is :-

 

We have 1 ISA Server Std Edition 2003, SP2 ISA
ISA Server Configured with 2 NIC as External & Internal .
The External is Connected to HW Firewall device like CISCO PIX Firewall.
The External is Connected to My Internal LAN.
We have Our mail server hosted on Our ISP Side and we are using POP3 & SMTP  [ POP3 Account with MS-OUTLOOK 2003 ].
I have here 60 users are configured as [  SNAT / Web Proxy Client / Firewall Client ] .
 

My ISA Server configuration Firewall Policy as following :-

 

1-Puplish mail server rule for MY Server on ISP for SMTP Protocol .

2-Puplish mail server rule for My Server on  ISP for POP Protocol .

3-Access Rule for Internet .

 

To implement my goal, I did as following :-

 

I disable my Only access rule which is called OPEN Internet .

I left My Publish server role without touching it.

 

I found that , all the users are able to send , but unable to receive and using POP3 at all. And they are unable to browse internet .

 

So , why they are unable to use POP3 while they are able to use SMTP ?

 

But if I disable the Puplish server role, and I change the access rule Protocol from ALL OUTBOUND Traffic to Selected Protocols “ SMTP / POP3 “  , I found that they are able to use SMTP / POP3 but unable to browse internet .

 

My question is , why this Happen ?
0
Comment
Question by:rolamohammed
4 Comments
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 500 total points
ID: 16959318
Pop3 uses port 110 for sending and port 25 for SMTP sending. What you should do is allow the IP of the pop3 and smtp. Your rule should be something like:
Allow 10.1.2.0 255.255.255.0 any port to 1.2.3.4 port 25 (for sending)
Allow 10.1.2.0 255.255.255.0 any port to 1.2.3.4 port 110 (for sending)  10.1.2.1-254 is the subnet your users are on, and 1.2.3.4 is the smtp/pop3 server ip
For recieving you should allow:
allow 1.2.3.4 any port to 10.1.2.0 255.255.255.0 any port    again, 1.2.3.4 is the pop3 and or smtp server and the 10.1.2.0 is the private subnet.
It's called egress and ingress filtering. http://en.wikipedia.org/wiki/Egress_filtering http://en.wikipedia.org/wiki/Ingress_filtering
-rich
0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

As I write this article, I am finishing cleanup from the Qakbot virus variant found in the wild on April 18, 2011.  It was a messy beast that had varying levels of infection, speculated as being dependent on how long it resided on the infected syste…
Security measures require Windows be logged in using Standard User login (not Administrator).  Yet, sometimes an application has to be run “As Administrator” from a Standard User login.  This paper describes how to create a shortcut icon to launch a…
This Micro Tutorial will give you a basic overview how to record your screen with Microsoft Expression Encoder. This program is still free and open for the public to download. This will be demonstrated using Microsoft Expression Encoder 4.
In a recent question (https://www.experts-exchange.com/questions/28997919/Pagination-in-Adobe-Acrobat.html) here at Experts Exchange, a member asked how to add page numbers to a PDF file using Adobe Acrobat XI Pro. This short video Micro Tutorial sh…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question