Registered users    
MembershipMembership:
Latest New UserLatest:Chris Naylor
New TodayNew Today:10
New YesterdayNew Yesterday:11
User CountOverall:23325

Private messaging    
You must be logged in to use this module.
Top 10 posters    
NamePosts
Mariette Knap12894
Marina Roos12507
Eriq Neale2114
Stan Guinn1913
Michael Patrick1912
Robert Pearman1771
Nick Pieters1425
Stewart Brown616
william warren601
Kevin D.579
Welcome unauthorized visitor    
If you want to join us in the discussions on this forum you need to register first. Registration is free! If you are already a registered user please login to join the forum.
Small Business Server Support Forum    
Subject: which ones are legitimate?
Prev Next
You are not authorized to post a reply.

Author Messages
Henri KONSTAIN User is Offline
Luxembourg
Member since
1/16/2006

Registered Users
Posts: 242

4/24/2008 10:33 AM  
On the ISA - Monitoring -  Session tab I see our internal clients as Secure NAT, Web Proxy and Firewall Client - identified with their IP addresses. All on the Internal Network - under the Source Network column.
 
But watching the tab over a period of time I see some other IP addresses defined under the Source Network as External. The Session Types are Secure NAT.
Some are displayed briefly and some are there for a while.
If I do an IP search for some of those with spamhaus.org I'm being informed that they are on some of the block lists.!
 
Is this something to worry about - are someone getting inside my network w/o me knowing - what can - or should - I do about this?
 
I'm not that proficient in going "behind the scenes" - so now I'm considering having M&M to login to my server to check if it's being abused.

SBS 2003 R2 PREMIUM SP2 - EXCHANGE 2003 SP2 - ISA SERVER 2004 SP3
Henri KONSTAIN User is Offline
Luxembourg
Member since
1/16/2006

Registered Users
Posts: 242

4/26/2008 07:38 AM  
OK maybe it will help to rephrase my question:
When viewing the sessions tab in ISA - am I supposed to see ONLY internal users and internal IP addresses there..?

SBS 2003 R2 PREMIUM SP2 - EXCHANGE 2003 SP2 - ISA SERVER 2004 SP3
Mariette Knap User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12894

4/26/2008 10:29 AM  
Henri,
 
If you server is properly configured and you do not allow anonymous sessions on your web proxy I guess those IP addresses you see are trying to logon to your server using OWA. What ports do you see those connections?

Mariëtte Knap Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Andy Sims User is Offline
United Kingdom
Member since
4/7/2005

Platinum Membership
Posts: 223

4/28/2008 09:23 AM  
I get a secure NAT for every inbound connection to exchange: I don't think this is an issue (except some hang around: http://www.smallbizserver.net/Forums/tabid/53/forumid/53/postid/51693/view/topic/Default.aspx. I followed this up on one of the MS managed newsgroups and MS were unable to help on why these sessions stayed around, or even what the ISA log for these sessions actually meant!)
Henri KONSTAIN User is Offline
Luxembourg
Member since
1/16/2006

Registered Users
Posts: 242

5/04/2008 08:09 PM  
Thanks Mariette and Andy for your replies.
 
When I installed the server I followed every step without altering anything - as far as I am aware of.
It is an all port scan - and ISA does not specify which port(s).
 
I am not really sure if anonymous access is enabled or not..? (the only user who needs access from outside the network is myself)
Would it be disabled by default at installation..?
Where do I check if it is enabled..?
If it is enabled - which steps do I need to perform to disable it..?
 
In the ISA alert I get numerous of these Configuration Errors - how can I configure to get rid of them? (I have not created any routes or etc. - the server runs 24-7 without me configuring anything - or otherwise interfering):
 
Event Type: Error
Event Source: Microsoft Firewall
Event Category: None
Event ID: 14147
Date: 2008 05 04
Time: 19:36:22
User: N/A
Computer: XXXXX
Description: ISA Server detected routes through the network adapter Server Local Area Connection that do not correlate with the network to which this network adapter belongs. When networks are configured correctly, the IP address ranges included in each array-level network must include all IP addresses that are routable through its network adapters according to their routing tables. Otherwise valid packets may be dropped as spoofed. The following ranges are included in the network's IP address ranges but are not routable through any of the network's adapters: 192.168.16.11-192.168.16.11;. Note that this event may be generated once after you add a route, create a remote site network, or configure Network Load Balancing and may be safely ignored if it does not re-occur.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
 
Also I continue to get these response errors - and I dont understand where I go to follow the highlighted advice below?:
 
Event Type: Warning
Event Source: Microsoft ISA Server Web Proxy
Event Category: None
Event ID: 23002
Date: 2008 05 04
Time: 19:23:32
User: N/A
Computer: XXXXX
Description: ISA Server was unable to decompress a response body from /DSS/Query?Type=Domain&Name=www.xxxxxxxx.com because the response was compressed by the UTF-8 method, which is not supported by ISA Server. This happens when a Web server is configured to supply responses compressed by the UTF-8 method regardless of the type of compression requested.
If you want ISA Server to block such responses, configure the policy rule's HTTP policy to block the Content-Encoding header in responses. Otherwise, such responses will be forwarded without decompression to the client and can be cached.
You can cancel or reduce the frequency of the alert generated by this event in ISA Server Management.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

SBS 2003 R2 PREMIUM SP2 - EXCHANGE 2003 SP2 - ISA SERVER 2004 SP3
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12507

5/06/2008 05:11 PM  
Hi Henri,
 
Is that IP that is listed at the first error by any change a VPN DHCP client? For the second error: EventID.Net:

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Henri KONSTAIN User is Offline
Luxembourg
Member since
1/16/2006

Registered Users
Posts: 242

5/07/2008 02:07 PM  
Marina,
It is our internal printer IP.
Krgds
Henri

SBS 2003 R2 PREMIUM SP2 - EXCHANGE 2003 SP2 - ISA SERVER 2004 SP3
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12507

5/08/2008 12:38 AM  
Hi Henri,
 
Did you add the complete internal network range in ISA, network? Did you have a look at the other error for which I gave you a link?

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Henri KONSTAIN User is Offline
Luxembourg
Member since
1/16/2006

Registered Users
Posts: 242

5/09/2008 08:29 AM  
Internal network in ISA shows the full range - yes. This is what was specified by the default installation.
 
I had a look at the link you supplied - but it still leaves me "in the blind" - I have no clue what to do about it.
 
I have finally decided to do a complete re-format and install the server from scratch - and this was done yesterday.
First thing I checked was monitoring the Session tab in ISA - and guess what: there are already external secureNAT sessions on and off..!
 
On our router I have disabled all ports except 25, 123 and 443.
Also port 80 is open but this is for our web-server which is outside the SBS network on its own network card.

SBS 2003 R2 PREMIUM SP2 - EXCHANGE 2003 SP2 - ISA SERVER 2004 SP3
Mariette Knap User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12894

5/10/2008 09:41 AM  
How many Nics do you have in your server?

Mariëtte Knap Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Henri KONSTAIN User is Offline
Luxembourg
Member since
1/16/2006

Registered Users
Posts: 242

5/11/2008 11:10 AM  
2

SBS 2003 R2 PREMIUM SP2 - EXCHANGE 2003 SP2 - ISA SERVER 2004 SP3
Mariette Knap User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12894

5/11/2008 02:13 PM  
I really don't see what the problem is:
  1. The secure Nat sessions you see are external smtp servers trying to send mail to your domain,
  2. The first error in the list was caused by a printer. Did you configure any gateways manually?,
  3. The compression error is caused by bad programming on a remote website.

Mariëtte Knap Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Henri KONSTAIN User is Offline
Luxembourg
Member since
1/16/2006

Registered Users
Posts: 242

5/11/2008 02:44 PM  
Thanks Mariette - this was exactly the answers (explanations) I was looking for
  1. Nice to know what it actually is, that I see at the sessions tab.
  2. The only gateway is the one on the router, connected to the external NIC, which I entered manually - as well as the 2 DNS servers at my ISP - when the CEICW ran after the initial setup.
  3. These compression errors - are there a way to avoid getting those displayed..? Do I really need to be informed about these..? With previous SBS installations I don't recall having ever seen those errors popping up on the Alert tab. Has something changed in the ISA service packs recently making those errors to show..? I have thicked all in both Common and DNS attacks in Intrusion detection - is this the reason for the errors showing..?

SBS 2003 R2 PREMIUM SP2 - EXCHANGE 2003 SP2 - ISA SERVER 2004 SP3
robert pearman User is Offline
United Kingdom
Member since
2/23/2007

Platinum Membership
Posts: 1771

5/12/2008 10:30 AM  
to stop that alert,

open ISA management
go to monitoring
click the alerts tab
click configure alert definitions
scroll to the bottom,

there are two alert types regarding compression, you want the one that is lower in the list,

simply untick the check box, and apply.
then apply the changes.

Just another tip, i always backup the ISA config on a regular basis - and especially before i make changes ( i know this is a minor one) it takes seconds to do so it is a good routine to get into.

To backup the entire config, right click the server name and click backup, just follow the yellow brick road and your all done.
Henri KONSTAIN User is Offline
Luxembourg
Member since
1/16/2006

Registered Users
Posts: 242

6/01/2008 12:01 PM  
Thank you for that advice Robert

SBS 2003 R2 PREMIUM SP2 - EXCHANGE 2003 SP2 - ISA SERVER 2004 SP3
You are not authorized to post a reply.



ActiveForums 3.7
Forum policy    
These Discussion Forums are dedicated to the discussion of the Small Business Server and related server and client software. For the benefit of the community please observe the following posting guidelines:
  1. No Advertising. This includes promotion of commercial products and non-commercial products which are not directly related to Small Business Server and related server and client software.
  2. No Flaming or Trolling.
  3. No Profanity, Racism, or Prejudice.
  4. Site Moderators have the final word on approving/removing a thread or post or comment.