[Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

How to allow FTP Application out through ISA 2004

Posted on 2011-03-03
7
Medium Priority
?
378 Views
Last Modified: 2012-05-11
Hi,

I have a scenario where ISA 2004 is the default gateway for the network and has 2 NICs. The 2nd NIC is in a DMZ and the default gateway on the ISA is an ASA.

1 PC, Non-domain joined has an FTP application that connects out through the ISA and down a VPN that is terminating on the ASA. Basically, the FTP app fails and we can see that the IP address attempting to connect to the FTP server on the other side of the VPN is the IP address on the LAN side of the ISA server.

ISA is proxying the FTP connection. I want the source IP of the PC establishing the FTP connection to hit the FTP server. I have added in a route from the PC to the subnet where the ISA server sits so ISA is not NATing the connection.

I cannot install the ISA client on the PC and the default gateway on the PC is the ISA server.

Any suggestions?
0
Comment
Question by:davewex
  • 4
  • 3
7 Comments
 
LVL 29

Expert Comment

by:pwindell
ID: 35037342
ISA is not going to stop NATing just because you add a route.

You have to change the Network Relationship between Internal and External to Routed instead of the default "NAT".

The ASA is where you have to "add a route".
0
 

Author Comment

by:davewex
ID: 35037798
Sorry I didn't make that part clear, It is set so that it is routed instead of NAT (The ISA default gateway is the ASA - No need for a route). I have several other L2L VPNs configured in this manner with no problem.

I don't have to add any routes on the ASA as the crypto map takes care of that. The only difference between the other connections is that I have set the PC as a source instead of the subnet in the routed statement. I am going to change this an see if it makes any differenece.

I also stated that ISA is proxying the connection for FTP, when traffic hits the remote site the source address is that of the internal IP on the ISA, it is not Nating. This is what I am trying to fix. The traffic is not routing through the ASA, instead it is proxying the FTP connection.

External connections into the PC from the remote site are working as they should
0
 

Author Comment

by:davewex
ID: 35038300
No joy, looks like I will have to remove the http filter as this seems to process the traffic even though I have it configured to route.

I will try it on Monday
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 29

Expert Comment

by:pwindell
ID: 35041659
Yes,  it might do that when using the Filter,...but removing the FTP Filter will cause the FTP Communincation to fail,...the Filter is required,...except when you are using the Firewall Client.  The Firewall Client replaces the Filter's functionality with its own.
0
 

Accepted Solution

by:
davewex earned 0 total points
ID: 35126601
I upgraded the ASA software from 7.2.2 to 8.2.4 and this resolved the problem
0
 
LVL 29

Expert Comment

by:pwindell
ID: 35139805
Very good.
I always prefer to blame the ASA for problems anyway  :-)
0
 

Author Closing Comment

by:davewex
ID: 35170530
asa upgrade resolved the issue
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are three types of ISA client that can be configured - these can be individual clients or multiples of a client on each PC or server SecureNAT. A SecureNAT client for ISA server is a client machine, work station or server, that has its defa…
Microsoft's ISA Server has been its pre-eminent security product for about a decade and is still regarded amongst the well-informed as one of the best software firewalls and application gateways ever released, by any manufacturer. ISA Server has bee…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an anti-spam), the admin…
Please read the paragraph below before following the instructions in the video — there are important caveats in the paragraph that I did not mention in the video. If your PaperPort 12 or PaperPort 14 is failing to start, or crashing, or hanging, …
Suggested Courses

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question