<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Stanislas Quastana&#8217;s Guide to Intradomain Communications Including AD UUIDs</title>
	<link>http://blogs.isaserver.org/shinder/2006/04/05/stanislas-quastanas-guide-to-intradomain-communications-including-ad-uuids/</link>
	<description>Written by Dr Thomas W Shinder, consultant to Microsoft, HP and many Fortune 500 companies on ISA firewall and Web proxy deployments this blog is where administrators get information about ISA Server Universal Threat Management firewalls. Topics include how to manage, deploy, and troubleshoot ISA Server as a network firewall, Web proxy/Web cache, remote access VPN server and VPN gateway to provide a high level of network security for all corporate computers.</description>
	<pubDate>Wed,  7 Jan 2009 01:17:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: BlackPH</title>
		<link>http://blogs.isaserver.org/shinder/2006/04/05/stanislas-quastanas-guide-to-intradomain-communications-including-ad-uuids/#comment-381</link>
		<pubDate>Mon, 17 Apr 2006 14:49:36 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/04/05/stanislas-quastanas-guide-to-intradomain-communications-including-ad-uuids/#comment-381</guid>
					<description>it`s new knowlege for me. But if i want use RPC filter for FE Exchange - i will need use only 1 DC+GC :(

Very big 10x Stanislas.</description>
		<content:encoded><![CDATA[<p>it`s new knowlege for me. But if i want use RPC filter for FE Exchange - i will need use only 1 DC+GC <img src='http://blogs.isaserver.org/shinder/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>Very big 10x Stanislas.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Thomas Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2006/04/05/stanislas-quastanas-guide-to-intradomain-communications-including-ad-uuids/#comment-373</link>
		<pubDate>Sat, 15 Apr 2006 13:09:57 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/04/05/stanislas-quastanas-guide-to-intradomain-communications-including-ad-uuids/#comment-373</guid>
					<description>Hi Stanislas,
Thanks!
Tom</description>
		<content:encoded><![CDATA[<p>Hi Stanislas,<br />
Thanks!<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Stanislas Quastana</title>
		<link>http://blogs.isaserver.org/shinder/2006/04/05/stanislas-quastanas-guide-to-intradomain-communications-including-ad-uuids/#comment-371</link>
		<pubDate>Fri, 14 Apr 2006 21:21:07 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/04/05/stanislas-quastanas-guide-to-intradomain-communications-including-ad-uuids/#comment-371</guid>
					<description>Hi, 

You must use a publication rule for RPC filtering (by design the RPC filter apply only to incoming RPC traffic). It's &quot;normal&quot; (by design) that RPC filtering doesn't work with access rule 

This publication rule works also between 2 routed networks (don't forget to check source ip = client IP  adress) 

- Stanislas -</description>
		<content:encoded><![CDATA[<p>Hi, </p>
<p>You must use a publication rule for RPC filtering (by design the RPC filter apply only to incoming RPC traffic). It&#8217;s &#8220;normal&#8221; (by design) that RPC filtering doesn&#8217;t work with access rule </p>
<p>This publication rule works also between 2 routed networks (don&#8217;t forget to check source ip = client IP  adress) </p>
<p>- Stanislas -
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Thomas Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2006/04/05/stanislas-quastanas-guide-to-intradomain-communications-including-ad-uuids/#comment-365</link>
		<pubDate>Thu, 13 Apr 2006 12:35:35 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/04/05/stanislas-quastanas-guide-to-intradomain-communications-including-ad-uuids/#comment-365</guid>
					<description>The checksum issue has nothing to do with RCP UUIDs.

Make sure you're following the complete procedures in both mine and Stan's articles.

HTH,
Tom</description>
		<content:encoded><![CDATA[<p>The checksum issue has nothing to do with RCP UUIDs.</p>
<p>Make sure you&#8217;re following the complete procedures in both mine and Stan&#8217;s articles.</p>
<p>HTH,<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: BlackPH</title>
		<link>http://blogs.isaserver.org/shinder/2006/04/05/stanislas-quastanas-guide-to-intradomain-communications-including-ad-uuids/#comment-362</link>
		<pubDate>Thu, 13 Apr 2006 10:32:35 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/04/05/stanislas-quastanas-guide-to-intradomain-communications-including-ad-uuids/#comment-362</guid>
					<description>I have tried this perfect way of RPC filtering ,but nothing. Maximum result when i have - is error about wrong TCP checksum on EMP Map request level
&quot;
Internet Protocol, Src: 172.16.2.2 (172.16.2.2), Dst: 192.168.1.248 (192.168.1.248)
Transmission Control Protocol, Src Port: 1130 (1130), Dst Port: epmap (135), Seq: 117, Ack: 85, Len: 156
    Source port: 1130 (1130)
    Destination port: epmap (135)
    Sequence number: 117    (relative sequence number)
    Next sequence number: 273    (relative sequence number)
    Acknowledgement number: 85    (relative ack number)
    Header length: 20 bytes
    Flags: 0x0018 (PSH, ACK)
    Window size: 65451
    Checksum: 0x7169 [incorrect, should be 0x9142]
    SEQ/ACK analysis
        This is an ACK to the segment in frame: 6
        The RTT to ACK the segment was: 0.000029000 seconds
DCE RPC Request, Fragment: Single, FragLen: 156, Call: 1 Ctx: 0
    Version: 5
    Version (minor): 0
    Packet type: Request (0)
    Packet Flags: 0x03
    Data Representation: 10000000
    Frag Length: 156
    Auth Length: 0
    Call ID: 1
    Alloc hint: 132
    Context ID: 0
    Opnum: 3
DCE/RPC Endpoint Mapper, Map
&quot;
I used &quot;access&quot; rule, not &quot;public&quot;. DMZ and Internal have route relationship. When i remove my &quot;RPC for AD Logon&quot; filter protocol, and add predefined RPC (all interfaces) - all working fine.</description>
		<content:encoded><![CDATA[<p>I have tried this perfect way of RPC filtering ,but nothing. Maximum result when i have - is error about wrong TCP checksum on EMP Map request level<br />
&#8221;<br />
Internet Protocol, Src: 172.16.2.2 (172.16.2.2), Dst: 192.168.1.248 (192.168.1.248)<br />
Transmission Control Protocol, Src Port: 1130 (1130), Dst Port: epmap (135), Seq: 117, Ack: 85, Len: 156<br />
    Source port: 1130 (1130)<br />
    Destination port: epmap (135)<br />
    Sequence number: 117    (relative sequence number)<br />
    Next sequence number: 273    (relative sequence number)<br />
    Acknowledgement number: 85    (relative ack number)<br />
    Header length: 20 bytes<br />
    Flags: 0&#215;0018 (PSH, ACK)<br />
    Window size: 65451<br />
    Checksum: 0&#215;7169 [incorrect, should be 0&#215;9142]<br />
    SEQ/ACK analysis<br />
        This is an ACK to the segment in frame: 6<br />
        The RTT to ACK the segment was: 0.000029000 seconds<br />
DCE RPC Request, Fragment: Single, FragLen: 156, Call: 1 Ctx: 0<br />
    Version: 5<br />
    Version (minor): 0<br />
    Packet type: Request (0)<br />
    Packet Flags: 0&#215;03<br />
    Data Representation: 10000000<br />
    Frag Length: 156<br />
    Auth Length: 0<br />
    Call ID: 1<br />
    Alloc hint: 132<br />
    Context ID: 0<br />
    Opnum: 3<br />
DCE/RPC Endpoint Mapper, Map<br />
&#8221;<br />
I used &#8220;access&#8221; rule, not &#8220;public&#8221;. DMZ and Internal have route relationship. When i remove my &#8220;RPC for AD Logon&#8221; filter protocol, and add predefined RPC (all interfaces) - all working fine.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
