Avatar of mwebb_sdmc
mwebb_sdmc
 asked on

How to open a port on ISA Server

I have been asked to do the following, open ports 44310 and 44312 on https.  Can someone help me to open these ports on the ISA server?  I tried creating a rule but don't know if I did it correctly.

Thanks in advance for any information
Microsoft Forefront ISA Server

Avatar of undefined
Last Comment
mwebb_sdmc

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
Keith Alabaster

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
SOLUTION
simonlimon

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Keith Alabaster

Simon - it is for https therefore it does not need a protocol - https is the protocol. ISA and FTMG only allows https over ports 443 and 563 out of the box.

You need to use the ISA_tpr.js script to add additional https to operate over additional ports. Once done, the existing https definition, regardless of access rule or publishing rule will include the new port number. All it requires is stopping and restarting the ISA or FTMG services after it is added.

Keith
simonlimon

Keith,
I agree with you, but this applies only if wants to perform HTTP(S) publishing. He can workaround this by just allowing access directly to the service on a specific port - Server publishing rule, therefore ISA would not care what kind of traffic it is - handle the traffic at layer 2 rather than layer 7.
Keith Alabaster

You think so?
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
simonlimon

sorry, my mistake - the correct thing to say would be to handle it layer 4 instead of layer 7.

He could do either thing, it's mwebb's choice, but handling this with HTTPS publishing would be more secure.

But again it depends on the application.
SOLUTION
amjad4

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
mwebb_sdmc

ASKER
Thanks everyone, I will try this today, I had most of it completed the way I thought it should be done with a few tweaks (thanks Amjad4).  Is there a good way to test if I have completed correctly?  I just have to go through and check my work again because the site still isn't working, but I need to make sure it is not the FW so that I can go back to IBM and let them know.

Thanks again!
simonlimon

You can check the session state and monitor what happens with these ports

TMG Console ->  logs and reporting - > logging tab
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
mwebb_sdmc

ASKER
I am sorry I don't mean to be a completely ignorant, but unfortunately on the ISA I am.  I searched google but couldn't find the correct answer.  I am now getting "Failed Connection Attempt" in my log file.  I don't think the url is correct it has a space in it, but IBM assures me it is correct.

Thanks again for all your help!
Keith Alabaster

I guess by now you have decided it cannot be done except the way I have advised?
mwebb_sdmc

ASKER
To be completely honest I am not sure if it is working or not.  I can't get to the web site, I do not know why they would make it so difficult to get to their sites when we are business partners!  Of course IBM is IBM they do what they want and we just deal with it..
Your help has saved me hundreds of hours of internet surfing.
fblack61
simonlimon

I am really curious what was the solution? Would you mind sharing?
mwebb_sdmc

ASKER
I am not sure what the resolution was, I followed all the examples and I was able to get it working.  I am not at all sure it was even the firewall because IBM had to resolve some other issues.

Thank you all for your help!