<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Possible SSH Publishing Solution</title>
	<link>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/</link>
	<description>Written by Dr Thomas W Shinder, consultant to Microsoft, HP and many Fortune 500 companies on ISA firewall and Web proxy deployments this blog is where administrators get information about ISA Server Universal Threat Management firewalls. Topics include how to manage, deploy, and troubleshoot ISA Server as a network firewall, Web proxy/Web cache, remote access VPN server and VPN gateway to provide a high level of network security for all corporate computers.</description>
	<pubDate>Wed,  7 Jan 2009 00:31:41 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: Emil</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-219566</link>
		<pubDate>Sat, 22 Nov 2008 12:40:11 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-219566</guid>
					<description>SFTP uses port 115. Create a non-web publishing rule and create a new protocol SFTP_IN with inbound TCP on port 115. You might hav to go to properties of the rule after you have cliecked finish and go to &quot;to&quot; and change to &quot;this request appears to come from ISA&quot;.</description>
		<content:encoded><![CDATA[<p>SFTP uses port 115. Create a non-web publishing rule and create a new protocol SFTP_IN with inbound TCP on port 115. You might hav to go to properties of the rule after you have cliecked finish and go to &#8220;to&#8221; and change to &#8220;this request appears to come from ISA&#8221;.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Pushpendu</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-209911</link>
		<pubDate>Sat, 27 Sep 2008 03:47:31 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-209911</guid>
					<description>Tried all the alternatives, still cant get SFTP to work behind ISA 2006 on ESX environment.
Can anyone please suggest something?</description>
		<content:encoded><![CDATA[<p>Tried all the alternatives, still cant get SFTP to work behind ISA 2006 on ESX environment.<br />
Can anyone please suggest something?
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Russ E</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-171934</link>
		<pubDate>Fri, 04 Apr 2008 08:48:25 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-171934</guid>
					<description>I've got a similar problem.

ESX environment
ISA 2006 STD on Win2k3E R2
OpenSSH on a Win2k3E R2 server behinds ISA
3 IPS on the box behind ISA.  ISA IS the gateway
Port is definitely open at the hardware firewall and allowing ALL protocols in and out (which is why I guess I can see it hitting ISA)
The account I am using to log in to OpenSSH is a local admin 

I look and I see that ISA initiates the connection and then I see it close a few mins later.  My client, WinSCP, gives me a network timeout error.  I look on the OpenSSH server and see that the client reached it but nothing happens.

I'm not sure that its an ISA error but I thought I would throw it out here to see if you have any suggestions.  I thought I had everything set up correctly, have looked at this blog as well as this posting:
http://forums.isaserver.org/m_2002037501/mpage_1/key_/tm.htm

Maybe I am just slow, or have been looking at it too long, but I am making no headway and am way overdue on a deadline.  I really am not that familiar with ISA but have managed to get this far but would love to bring it home.  If you dont think its an ISA problem I'd be open to any other suggestions you may have.

Thanks in advance and feel free to contact me publicly or privately...
Russ</description>
		<content:encoded><![CDATA[<p>I&#8217;ve got a similar problem.</p>
<p>ESX environment<br />
ISA 2006 STD on Win2k3E R2<br />
OpenSSH on a Win2k3E R2 server behinds ISA<br />
3 IPS on the box behind ISA.  ISA IS the gateway<br />
Port is definitely open at the hardware firewall and allowing ALL protocols in and out (which is why I guess I can see it hitting ISA)<br />
The account I am using to log in to OpenSSH is a local admin </p>
<p>I look and I see that ISA initiates the connection and then I see it close a few mins later.  My client, WinSCP, gives me a network timeout error.  I look on the OpenSSH server and see that the client reached it but nothing happens.</p>
<p>I&#8217;m not sure that its an ISA error but I thought I would throw it out here to see if you have any suggestions.  I thought I had everything set up correctly, have looked at this blog as well as this posting:<br />
<a href='http://forums.isaserver.org/m_2002037501/mpage_1/key_/tm.htm' rel='nofollow'>http://forums.isaserver.org/m_2002037501/mpage_1/k...tm.htm</a></p>
<p>Maybe I am just slow, or have been looking at it too long, but I am making no headway and am way overdue on a deadline.  I really am not that familiar with ISA but have managed to get this far but would love to bring it home.  If you dont think its an ISA problem I&#8217;d be open to any other suggestions you may have.</p>
<p>Thanks in advance and feel free to contact me publicly or privately&#8230;<br />
Russ
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: blautens</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-170813</link>
		<pubDate>Mon, 31 Mar 2008 13:13:53 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-170813</guid>
					<description>on ISA 2006 EE array, I tried creating a new publishing rule, SSH, port 22 inbound, and used Diego's suggestion of a secondary port range of 50000 to 51000, and it worked flawlessly with WS_FTP Server. Thanks, Diego!</description>
		<content:encoded><![CDATA[<p>on ISA 2006 EE array, I tried creating a new publishing rule, SSH, port 22 inbound, and used Diego&#8217;s suggestion of a secondary port range of 50000 to 51000, and it worked flawlessly with WS_FTP Server. Thanks, Diego!
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Darek</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-122274</link>
		<pubDate>Tue, 02 Oct 2007 12:09:25 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-122274</guid>
					<description>Tried the route solution using ISA 2006 but didn't work. While monitoring the ssh access ISA jumped to default last rule and did not &quot;see&quot; my publishing rule.
My successfull solution was to remove the route rule I created and to edit the publishing rule &quot;To&quot; tab by seelecting &quot;the request appear to come from the ISA server.

My2Cents</description>
		<content:encoded><![CDATA[<p>Tried the route solution using ISA 2006 but didn&#8217;t work. While monitoring the ssh access ISA jumped to default last rule and did not &#8220;see&#8221; my publishing rule.<br />
My successfull solution was to remove the route rule I created and to edit the publishing rule &#8220;To&#8221; tab by seelecting &#8220;the request appear to come from the ISA server.</p>
<p>My2Cents
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: ISA Server SSH Veröffentlichung - MCSEboard.de MCSE Forum</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-107288</link>
		<pubDate>Mon, 09 Jul 2007 21:28:30 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-107288</guid>
					<description>[...] Da gibt es ein paar Lösungsmöglichkeiten: Thomas Shinder Blog » Blog Archive » Possible SSH Publishing Solution   grizzly999 [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Da gibt es ein paar Lösungsmöglichkeiten: Thomas Shinder Blog » Blog Archive » Possible SSH Publishing Solution   grizzly999 [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Mikael Ulvesjo</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-101884</link>
		<pubDate>Fri, 08 Jun 2007 10:53:59 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-101884</guid>
					<description>I have problems connecting to external ssh services runing on a non default port ( E.g: 2222  ) from a linux client behind an ISA server, 
Do anyone have any information or theory why I fail to do this, on the server running the ssh service I can see that the client is able to connect but it fails to authenticate, I'm using certificates to authenticate and that works if I bypass the ISA proxy.</description>
		<content:encoded><![CDATA[<p>I have problems connecting to external ssh services runing on a non default port ( E.g: 2222  ) from a linux client behind an ISA server,<br />
Do anyone have any information or theory why I fail to do this, on the server running the ssh service I can see that the client is able to connect but it fails to authenticate, I&#8217;m using certificates to authenticate and that works if I bypass the ISA proxy.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: networkfreek</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-25671</link>
		<pubDate>Sat, 25 Nov 2006 04:22:54 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-25671</guid>
					<description>Hi Diego Medina
It works. Can you explain, why port 50000 - 51000 have to be open for the SSH server publishing to work? Tx</description>
		<content:encoded><![CDATA[<p>Hi Diego Medina<br />
It works. Can you explain, why port 50000 - 51000 have to be open for the SSH server publishing to work? Tx
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Jim Kobak</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-13822</link>
		<pubDate>Sat, 07 Oct 2006 16:48:47 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-13822</guid>
					<description>I am still using ISA Server 2000. I can't seem to locate any way to add a routing rule as described above. They're all related to web requests only. Am I missing something, or do I need ISA 2004 or better?

If so, anyone have an idea to publish SSH with ISA 2000?

Thanks,

Jim</description>
		<content:encoded><![CDATA[<p>I am still using ISA Server 2000. I can&#8217;t seem to locate any way to add a routing rule as described above. They&#8217;re all related to web requests only. Am I missing something, or do I need ISA 2004 or better?</p>
<p>If so, anyone have an idea to publish SSH with ISA 2000?</p>
<p>Thanks,</p>
<p>Jim
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Thomas Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-9111</link>
		<pubDate>Thu, 24 Aug 2006 15:39:20 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/11/possible-ssh-publishing-solution/#comment-9111</guid>
					<description>Hi guys,

Thanks!
Tom</description>
		<content:encoded><![CDATA[<p>Hi guys,</p>
<p>Thanks!<br />
Tom
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
