Thomas Shinder Blog RSS

All Blogs  »  Thomas Shinder Blog  »  ISA Central  »  Blog article: Clarifying ISA Firewall "Directionality" for Access and Publishing Rules

Clarifying ISA Firewall "Directionality" for Access and Publishing Rules

Tim Mullen came up with a good question the other day regarding directionality notations in his ISA Firewall’s log files. What appeared to be an inbound connection was logged as an outbound connection.

To clarify the situation, Jim Harrison came up with the following explanation, which indeed explains the situation very nicely:

===============================================

The traffic “direction” is determined by the rule.

What rule is quoted for the deny action?

If it’s the default rule, then that’s correct, because Access rules only deal in “outbound” traffic.

Since the “default deny rule” is an access rule, it deals only with “all outbound protocols”.

Here’s another conundrum to wrap up in your dilemma…

SvrPubRule

Primary Connection: TCP:666 Inbound

From: External

Access Rule

Primary Connection: TCP:666 Outbound

From External

To: Local Host

If the SPR is listed first, it will “fire” and the traffic will be listed as “inbound”

If the access rule is listed first, it will fire and the traffic will be listed as “outbound”.

===============================================

Thanks Jim!

HTH,

Tom

Thomas W Shinder, M.D.
Site: http://www.isaserver.org/

Blog: http://blogs.isaserver.org/shinder/
Book: http://tinyurl.com/3xqb7

Email: tshinder@isaserver.org

MVP — Microsoft Firewalls (ISA)

One Response to “Clarifying ISA Firewall "Directionality" for Access and Publishing Rules”

  1. Adminaid.net » Blog Archive » Clarifying ISA Firewall "Directionality" for Access and Publishing Rules Says:

    January 12th, 2008 at 1:55 pm

    […] Tim Mullen came up with a good question the other day regarding directionality notations in his ISA Firewall’s log files. What appeared to be an inbound connection was logged as an outbound connection. To clarify the situation, Jim Harrison came up with the following explanation, which indeed explains the situation very nicely: =============================================== The traffic “direction” is determined by the rule. more… […]

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Solution Center