<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Segmenting Networks with ISA 2004 – Filtering access to Domain Controllers</title><link>http://blogs.msdn.com/squasta/archive/2006/03/17/553805.aspx</link><description>Purpose This document explains how to use ISA Server 2004 as an application layer firewall between a Windows 2000 domain controller and a Windows 2000 member server. This configuration allows: - Integrate a stand alone server in a Windows 2000 Active</description><dc:language>fr-FR</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Thomas Shinder Blog  &amp;raquo; Blog Archive   &amp;raquo; Stanislas Quastana&amp;#8217;s Guide to Intradomain Communications Including AD UUIDs</title><link>http://blogs.msdn.com/squasta/archive/2006/03/17/553805.aspx#568974</link><pubDate>Wed, 05 Apr 2006 17:28:16 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:568974</guid><dc:creator>Thomas Shinder Blog  » Blog Archive   » Stanislas Quastana’s Guide to Intradomain Communications Including AD UUIDs</dc:creator><description>PingBack from &lt;a rel="nofollow" target="_new" href="http://blogs.isaserver.org/shinder/2006/04/05/stanislas-quastanas-guide-to-intradomain-communications-including-ad-uuids/"&gt;http://blogs.isaserver.org/shinder/2006/04/05/stanislas-quastanas-guide-to-intradomain-communications-including-ad-uuids/&lt;/a&gt;</description></item><item><title>re: Segmenting Networks with ISA 2004 – Filtering access to Domain Controllers</title><link>http://blogs.msdn.com/squasta/archive/2006/03/17/553805.aspx#575647</link><pubDate>Thu, 13 Apr 2006 13:30:06 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:575647</guid><dc:creator>BlackPH</dc:creator><description>I have tried this perfect way of RPC filtering ,but nothing. Maximum result when i have - is error about wrong TCP checksum on EMP Map request level &lt;BR&gt;" &lt;BR&gt;Internet Protocol, Src: 172.16.2.2 (172.16.2.2), Dst: 192.168.1.248 (192.168.1.248) &lt;BR&gt;Transmission Control Protocol, Src Port: 1130 (1130), Dst Port: epmap (135), Seq: 117, Ack: 85, Len: 156 &lt;BR&gt;&amp;nbsp; &amp;nbsp;Source port: 1130 (1130) &lt;BR&gt;&amp;nbsp; &amp;nbsp;Destination port: epmap (135) &lt;BR&gt;&amp;nbsp; &amp;nbsp;Sequence number: 117 &amp;nbsp; &amp;nbsp;(relative sequence number) &lt;BR&gt;&amp;nbsp; &amp;nbsp;Next sequence number: 273 &amp;nbsp; &amp;nbsp;(relative sequence number) &lt;BR&gt;&amp;nbsp; &amp;nbsp;Acknowledgement number: 85 &amp;nbsp; &amp;nbsp;(relative ack number) &lt;BR&gt;&amp;nbsp; &amp;nbsp;Header length: 20 bytes &lt;BR&gt;&amp;nbsp; &amp;nbsp;Flags: 0x0018 (PSH, ACK) &lt;BR&gt;&amp;nbsp; &amp;nbsp;Window size: 65451 &lt;BR&gt;&amp;nbsp; &amp;nbsp;Checksum: 0x7169 [incorrect, should be 0x9142] &lt;BR&gt;&amp;nbsp; &amp;nbsp;SEQ/ACK analysis &lt;BR&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;This is an ACK to the segment in frame: 6 &lt;BR&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;The RTT to ACK the segment was: 0.000029000 seconds &lt;BR&gt;DCE RPC Request, Fragment: Single, FragLen: 156, Call: 1 Ctx: 0 &lt;BR&gt;&amp;nbsp; &amp;nbsp;Version: 5 &lt;BR&gt;&amp;nbsp; &amp;nbsp;Version (minor): 0 &lt;BR&gt;&amp;nbsp; &amp;nbsp;Packet type: Request (0) &lt;BR&gt;&amp;nbsp; &amp;nbsp;Packet Flags: 0x03 &lt;BR&gt;&amp;nbsp; &amp;nbsp;Data Representation: 10000000 &lt;BR&gt;&amp;nbsp; &amp;nbsp;Frag Length: 156 &lt;BR&gt;&amp;nbsp; &amp;nbsp;Auth Length: 0 &lt;BR&gt;&amp;nbsp; &amp;nbsp;Call ID: 1 &lt;BR&gt;&amp;nbsp; &amp;nbsp;Alloc hint: 132 &lt;BR&gt;&amp;nbsp; &amp;nbsp;Context ID: 0 &lt;BR&gt;&amp;nbsp; &amp;nbsp;Opnum: 3 &lt;BR&gt;DCE/RPC Endpoint Mapper, Map &lt;BR&gt;" &lt;BR&gt;I used "access" rule, not "public". DMZ and Internal have route relationship. When i remove my "RPC for AD Logon" filter protocol, and add predefined RPC (all interfaces) - all working fine.</description></item><item><title>re: Segmenting Networks with ISA 2004 – Filtering access to Domain Controllers</title><link>http://blogs.msdn.com/squasta/archive/2006/03/17/553805.aspx#576322</link><pubDate>Fri, 14 Apr 2006 12:45:07 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:576322</guid><dc:creator>stanislas-quastana</dc:creator><description>&lt;P&gt;&lt;FONT face=Tahoma size=2&gt;Hi, &lt;BR&gt;&lt;BR&gt;You &lt;FONT color=#0000ff&gt;&lt;STRONG&gt;&lt;U&gt;must use a publication rule for RPC filtering&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt; (by design the RPC filter apply only to incoming traffic). It's "normal" (by design) that RPC filtering doesn't work with access rule &lt;BR&gt;&lt;BR&gt;This publication rule works between 2 routed networks (don't forget to check source ip = client IP &amp;nbsp;adress) &lt;BR&gt;&lt;BR&gt;regards&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma size=2&gt;Stanislas&lt;/FONT&gt;&lt;/P&gt;</description></item></channel></rss>