Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Allow access to ports

Status
Not open for further replies.

prha

Technical User
May 24, 2002
288
GB
Hi,

I am completely new to ISA 2004 and have not used it before. I have inherited a server and am slowly navigating my way around. I currently have a problem with Sophos not updating polices on client machines. After speaking to their helpdesk it transpires that ISA is blocking access to specific ports. I am not 100% sure how and where I add the rule that allows my internal PC's only, to gain access to these ports?. I tried adding a rule on the firewall: allowed all outbound traffic from all internal clients to the local host and under protocol, I listed the appropriate ports. but this did not work. It does work if do not specify the ports. but does this represent a risk?. I seem to be allowing all outbound traffic access to the server from anywhere using anything. Is there no way to specify ports?

Any help appreciated.
 
I am running sophos and ISA2000 and don't have any updating problems. Few questions.

What is you network layout?
Is the Sophos Management Console on your ISa server?
 
I have EM installed on ISA server. The PC's are updating the software, but they are not picking up polices and also EM has no information on any of the PCs. all details are "unknown".
Network is windows 2003 servers perimter network behind firebox.
 
Are the pc's XP, is the firewall wall on, on them?
Are you able to push the install to the pcs?
So your network is the following

Firebox----isa---switch-----client pcs?
 
Hi,

Mixture of XP and 2000 client PC's I have sep polices for the XP and 2000 machines, I can push the installs, and they have updated to the lastes version, they have also updated the primary server location to the new location. But the schedule does not update (on default of every 5 mins) and Enterpirse Manager says unknown for each PC in terms of last updated etc

Correct on the network.

I have created a rule on the ISA server to allow all inbound on any protocol and I can now telnet into the port, but not sure how I specifically open the required port on ISA server?

Many thanks.
 
also firewall on PC's is off
 
Hi,

All sorted, found out from Sophos that had to be TCP port, so created protocol and specified ports there. All working OK now.

Many thanks for help
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top