Martyn Greville-Giddings  United Kingdom Member since 3/27/2006
Registered Users Posts: 78

 |
| 5/15/2006 10:59 PM |
|
Hi, I need to open access to FTP port 21 and HTTP port 80 for passive updates of my Kaspersky anti virus I also want to open port 8334 to access my remote mail servers control panel, I found a Java script which will open specified ports but this seems a liitle crude.
Is it possible to open these ports only to specific IP addresses within the network and is this on demand access or are they open all the time?
I promise to take out the Platinum subscription next week so I can read all the articals but I need the answer ASAP and the bank account is empty.
I'll probably take a couple of hours of your time for a quick remote health check as well, as this is my first SBS install and would like to know it went well. |
|
|
|
|
|
Michael Patrick  United States Member since 10/26/2005
Platinum Membership Posts: 1912

 |
| 5/15/2006 11:05 PM |
|
ISA2k or 2k4?
|
|
Michael Patrick
"Technology Interpreter Extraordinaire" CAD, BIM & SBS |
|
|
|
Martyn Greville-Giddings  United Kingdom Member since 3/27/2006
Registered Users Posts: 78

 |
| 5/15/2006 11:19 PM |
|
Sorry ISA 2004 new install on SBS sp1 |
|
|
|
|
|
Marina Roos  The Netherlands Member since 3/24/2005
Forum Admins Posts: 12507

 |
| 5/16/2006 12:46 AM |
|
Hi Martyn,
You will need to enable the FTP out rule in ISA, Firewall rules. You certainly don't need port 80 inbound. |
|
| Marina Roos Smallbizserver.Net Administrator | Mission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain' |
|
|
|
|
Martyn Greville-Giddings  United Kingdom Member since 3/27/2006
Registered Users Posts: 78

 |
| 5/16/2006 10:42 AM |
|
Hi, I created a new rule last night and this cured the proble but when I look at the default rule created by SBS this seems to have the same settings and dosn't work.
Is there a way to print of a copy of all the rules and compare their properties, I seem to be haveing the same problem with the NTP port for time syncing, the rule is there by default and active but the NTP access is denied in the live logging.
Can I allow access from one IP for these rules and is it a good idea? |
|
|
|
|
|
Mirko Syrer  Germany Member since 5/24/2005
Registered Users Posts: 424

 |
| 5/16/2006 12:36 PM |
|
Posted By Marina Roos on 16 May 2006 00:46
Hi Martyn,
You will need to enable the FTP out rule in ISA, Firewall rules. You certainly don't need port 80 inbound.
Hi Martyn,
did you try to activate (!!) the standard rules which were already there when you installed ISA?
By default, i.e. FTP out is disabled. You habe to right click the rule and activate it.
Mirko |
|
Best Regards, Mirko |
|
|
|
Martyn Greville-Giddings  United Kingdom Member since 3/27/2006
Registered Users Posts: 78

 |
| 5/16/2006 02:56 PM |
|
Hi, I had to reinstall ISA 2004 because it locked up everything from internet access to internal access from the computer to the server.
I've left the rules as per default after running the CEICW wizard and when I go to the FTP rule it has a small icon of a key and if I right click it I get the option to disable the rule which to me implies that it is already activated by the wizard but there is now additional Activate option. |
|
|
|
|
|
Mariette Knap  The Netherlands Member since 3/24/2005
Forum Admins Posts: 12890

 |
|
Martyn Greville-Giddings  United Kingdom Member since 3/27/2006
Registered Users Posts: 78

 |
| 5/16/2006 08:49 PM |
|
Fantastic, I followed this guide with the exception that I created a copy of the FTP Out Protocol instead of the Internet Access Rule and just opened FTP to the one server I needed access for. |
|
|
|
|
|
Kevin Amory  United States Member since 6/30/2005
Registered Users Posts: 220
 |
| 12/12/2007 07:34 PM |
|
I have followed the instructions to uncheck Read only. (Tried to attach image file of screen but it is too large.) I have hit okay, applied changes, waited over 30 minutes for changes to take affect, I have restarted the ISA service and users cannot ftp.
SBS 2003 Premium, ISA 2004, ISA Clients are installed and are automatically discovering the ISA server just fine, all other browsing works fine. I can ftp from the server. Port 21 is open on the router. When I check live logging SBS Internet Access Rule still blocks the ftp GET request.
|
|
|
|
|
|
Mariette Knap  The Netherlands Member since 3/24/2005
Forum Admins Posts: 12890

 |
| 12/12/2007 08:58 PM |
|
Kevin,
If you save the file as a png file it will probably attach just fine. Can you tell me what you see when it does not work...or if the screenshot attached I can it there :-)
|
|
| Mariëtte Knap Smallbizserver.Net Administrator | Mission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain' |
|
|
|
|
Kevin Amory  United States Member since 6/30/2005
Registered Users Posts: 220
 |
| 12/14/2007 03:26 PM |
|
The two png image files I'm trying to attach are 74kb and 21kb but it still gives me an error that they are over 100kb.
The error I get from a workstation is a Network Access Message, 502 error.
|
|
|
|
|
|
Kevin Amory  United States Member since 6/30/2005
Registered Users Posts: 220
 |
| 12/14/2007 03:39 PM |
|
Mariette, I sent the images to you in two private messages. |
|
|
|
|
|
Mariette Knap  The Netherlands Member since 3/24/2005
Forum Admins Posts: 12890

 |
|
Kevin Amory  United States Member since 6/30/2005
Registered Users Posts: 220
 |
| 12/14/2007 04:04 PM |
|
I checked every rule for Configuring FTP Option and there were three rules that gave that option and I unchecked read only on all three. They were: RULE STATUS SBS FTP Server Access Rule Disabled SBS FTP Outbound Access Rule Enabled SBS Internet Access Rule Enabled |
|
|
|
|
|
Mariette Knap  The Netherlands Member since 3/24/2005
Forum Admins Posts: 12890

 |
| 12/14/2007 06:59 PM |
|
Kevin,
From where do you try to connect to that ftp site? Is that from a workstation and does that workstation has the Firewall client installed? What is the address of the ftp site you want to connect to?
|
|
| Mariëtte Knap Smallbizserver.Net Administrator | Mission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain' |
|
|
|
|
Kevin Amory  United States Member since 6/30/2005
Registered Users Posts: 220
 |
| 12/19/2007 04:36 PM |
|
I have tried it from four different workstations. They all have the Firewall Client installed. All browse the Internet fine. The website is below. When the pages loads click on the link to upload a file. http://www.lsgnc.com/new_page_1.htm |
|
|
|
|
|
Mariette Knap  The Netherlands Member since 3/24/2005
Forum Admins Posts: 12890

 |
|
Kevin Amory  United States Member since 6/30/2005
Registered Users Posts: 220
 |
| 12/20/2007 12:58 AM |
|
Trying to upload through Internet Explorer. I have Enable FTP folder view checked and Use Passive FTP checked. I have unchecked each one individually and unchecked both together and did not get a change. |
|
|
|
|
|
Mariette Knap  The Netherlands Member since 3/24/2005
Forum Admins Posts: 12890

 |
| 12/20/2007 01:47 AM |
|
Kevin,
Just to be sure can you download a trial from ipSwitch and see if that works? Or CuteFTP if you want. I never liked IE for FTP...
|
|
| Mariëtte Knap Smallbizserver.Net Administrator | Mission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain' |
|
|
|
|