<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-410</id>
	<title>Nabble - Firewall (securityfocus.com)</title>
	<updated>2009-06-15T23:37:19Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Firewall-(securityfocus.com)-f410.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Firewall-%28securityfocus.com%29-f410.html" />
	<subtitle type="html"></subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-24048578</id>
	<title>What kind of firewall do you use? And why?</title>
	<published>2009-06-15T23:37:19Z</published>
	<updated>2009-06-17T21:15:08Z</updated>
	<author>
		<name>leni341</name>
	</author>
	<content type="html">Pros: I love &lt;b&gt;Mil Firewall&lt;/b&gt; &lt;img src=&quot;http://old.nabble.com/file/p24048578/mil-firewall-boxshot.jpg&quot; border=&quot;0&quot; /&gt; because it has real time network activity monitoring and good filtering rules for ports and addresses. 

Cons: Unfortunately it's not free. :(</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/What-kind-of-firewall-do-you-use--And-why--tp24048578p24048578.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18261366</id>
	<title>Re: iptables limit speed of SAMBA</title>
	<published>2008-07-02T23:18:25Z</published>
	<updated>2008-07-02T23:18:25Z</updated>
	<author>
		<name>Jamie Riden</name>
	</author>
	<content type="html">2008/7/2 yuan shijiang &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18261366&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;yshijiang@...&lt;/a&gt;&amp;gt;:
&lt;br&gt;&amp;gt; iptables &amp;nbsp;-A OUTPUT -p tcp -o eth0- -s 192.168.1.0/24 &amp;nbsp;--sport 445 -m
&lt;br&gt;&amp;gt; hashlimit --hashlimit 20/sec --hashlimit-mode dstip --hashlimit-name
&lt;br&gt;&amp;gt; samba -j ACCEPT
&lt;br&gt;&amp;gt; iptables &amp;nbsp;-A OUTPUT -p tcp -o eth0- -s 192.168.1.0/24 &amp;nbsp;--sport 445 -j REJECT
&lt;br&gt;&lt;br&gt;If you REJECT a packet isn't that going to close the connection?
&lt;br&gt;&lt;br&gt;Last time I needed to do linux traffic shaping I used the tc stuff
&lt;br&gt;described here: &lt;a href=&quot;http://lartc.org/howto/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lartc.org/howto/&lt;/a&gt;&lt;br&gt;&lt;br&gt;The HOWTO is pretty scary, but there's an example script here:
&lt;br&gt;&lt;a href=&quot;http://lartc.org/howto/lartc.cookbook.ultimate-tc.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lartc.org/howto/lartc.cookbook.ultimate-tc.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;&amp;nbsp;Jamie
&lt;br&gt;-- 
&lt;br&gt;Jamie Riden / &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18261366&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jamesr@...&lt;/a&gt; / &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18261366&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jamie@...&lt;/a&gt;
&lt;br&gt;UK Honeynet Project: &lt;a href=&quot;http://www.ukhoneynet.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ukhoneynet.org/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/iptables-limit-speed-of-SAMBA-tp18248757p18261366.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18248757</id>
	<title>iptables limit speed of SAMBA</title>
	<published>2008-07-01T18:18:24Z</published>
	<updated>2008-07-01T18:18:24Z</updated>
	<author>
		<name>yuan shijiang</name>
	</author>
	<content type="html">iptables &amp;nbsp;-A OUTPUT -p tcp -o eth0- -s 192.168.1.0/24 &amp;nbsp;--sport 445 -m
&lt;br&gt;hashlimit --hashlimit 20/sec --hashlimit-mode dstip --hashlimit-name
&lt;br&gt;samba -j ACCEPT
&lt;br&gt;iptables &amp;nbsp;-A OUTPUT -p tcp -o eth0- -s 192.168.1.0/24 &amp;nbsp;--sport 445 -j REJECT
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/iptables-limit-speed-of-SAMBA-tp18248757p18248757.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18227409</id>
	<title>RE: Help to remove blocking of MS outlook through ISA 2004</title>
	<published>2008-06-30T16:55:40Z</published>
	<updated>2008-06-30T16:55:40Z</updated>
	<author>
		<name>Faris Mlaeb</name>
	</author>
	<content type="html">&lt;table cellspacing='0' cellpadding='0' border='0'&gt;&lt;tr&gt;&lt;td valign='top' style='font: inherit;'&gt;&lt;P&gt;HI alll&lt;/P&gt;
&lt;P&gt;its for sure TOTALLY Wronge to make a Allow Full control Access to the internet &lt;/P&gt;
&lt;P&gt;but as I understand that &lt;FONT face=Tahoma&gt;Qaisar for test to see if there is a problem in his rule&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;but even so .. the connection will fail .as ISA Server is blocking the APP named as Outlook&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;so the rule should be ISA Allow the Outlook abd limit its connection to be using Only POP3 and SMTP&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;&lt;BR&gt;&lt;/P&gt;
&lt;DIV align=center&gt;&lt;B&gt;&lt;SPAN style=&quot;COLOR: #1f497d&quot;&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;FONT color=#0000bf&gt;Faris Mlaeb&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/DIV&gt;
&lt;DIV class=MsoNormal style=&quot;MARGIN: 0in 0in 0pt; TEXT-ALIGN: center&quot; align=center&gt;&lt;SPAN style=&quot;COLOR: #1f497d&quot;&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri color=#0000bf&gt;&lt;STRONG&gt;Technical Manager&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV align=center&gt;&lt;FONT face=Calibri&gt;&lt;FONT color=#0000bf size=3&gt;&lt;STRONG&gt;Network Administrator&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;BR&gt;&lt;BR&gt;--- On &lt;B&gt;Fri, 6/27/08, Thor (Hammer of God) &lt;I&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18227409&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;thor@...&lt;/a&gt;&amp;gt;&lt;/I&gt;&lt;/B&gt; wrote:&lt;BR&gt;
&lt;BLOCKQUOTE style=&quot;PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: rgb(16,16,255) 2px solid&quot;&gt;From: Thor (Hammer of God) &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18227409&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;thor@...&lt;/a&gt;&amp;gt;&lt;BR&gt;Subject: RE: Help to remove blocking of MS outlook through ISA 2004&lt;BR&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18227409&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;BR&gt;Date: Friday, June 27, 2008, 7:57 AM&lt;BR&gt;&lt;BR&gt;
&lt;DIV id=yiv1199108104&gt;


&lt;DIV class=Section1&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;Wow.&amp;nbsp; I'm not saying this to be mean spirited, but when you create rules to &quot;allow all&quot; in order to fix mail access from Outlook, things have gone horribly wrong.&amp;nbsp; You now no longer have a firewall in ISA -- you now have what we call &quot;a router.&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;t&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style=&quot;BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: blue 1.5pt solid; PADDING-TOP: 0in; BORDER-BOTTOM: medium none&quot;&gt;
&lt;DIV&gt;
&lt;DIV style=&quot;BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 3pt; BORDER-BOTTOM: medium none&quot;&gt;
&lt;P class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma', 'sans-serif'&quot;&gt;From:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma', 'sans-serif'&quot;&gt; Qaisar Naseem [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18227409&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;qaisarn@...&lt;/a&gt;] &lt;BR&gt;&lt;B&gt;Sent:&lt;/B&gt; Friday, June 27, 2008 6:48 AM&lt;BR&gt;&lt;B&gt;To:&lt;/B&gt; Faris Mlaeb&lt;BR&gt;&lt;B&gt;Cc:&lt;/B&gt; Thor (Hammer of God); &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18227409&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;BR&gt;&lt;B&gt;Subject:&lt;/B&gt; Re: Help to remove blocking of MS outlook through ISA 2004&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;Dear Mr. Faris.&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;Thanks a lot. I did the same what you have and solved the problem. &lt;/P&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;Thanks again.&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal style=&quot;MARGIN-BOTTOM: 12pt&quot;&gt;Qaisar&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;On Tue, Jun 24, 2008 at 2:20 AM, Faris Mlaeb &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18227409&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;farisnt@...&lt;/a&gt;&amp;gt; wrote:&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;P&gt;HI&lt;/P&gt;
&lt;P&gt;This is normal for ISA and you can fix this by going to:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Open the ISA Server Console and expand the Configuration, and select General, and then Click on &quot;Define Firewall Client Settings&quot;, You will have a new Window for the &quot;Firewall Client Settings&quot;&lt;BR&gt;Click on the Application Tab and from the list select Outlook&lt;BR&gt;You will notice that its like this:&lt;BR&gt;Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;1&lt;BR&gt;change the value to be &lt;BR&gt;Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;0&lt;/P&gt;
&lt;P&gt;and on the Firewall client on the user PC&amp;nbsp; make sure that you click on Detect Now Or simply restart your Computer&lt;/P&gt;
&lt;P&gt;This work for me perfect&lt;/P&gt;
&lt;P&gt;Have a nice time&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that if the value is not present .. then&amp;nbsp; simply create it&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;COLOR: #888888&quot;&gt;&lt;BR&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;P class=MsoNormal style=&quot;TEXT-ALIGN: center&quot; align=center&gt;&lt;B&gt;&lt;SPAN style=&quot;COLOR: #0000bf; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;Faris Mlaeb&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style=&quot;COLOR: #888888&quot;&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style=&quot;TEXT-ALIGN: center&quot; align=center&gt;&lt;STRONG&gt;&lt;SPAN style=&quot;COLOR: #0000bf; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;Technical Manager&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style=&quot;COLOR: #888888&quot;&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style=&quot;TEXT-ALIGN: center&quot; align=center&gt;&lt;STRONG&gt;&lt;SPAN style=&quot;COLOR: #0000bf; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;Network Administrator&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style=&quot;COLOR: #888888&quot;&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal style=&quot;MARGIN-BOTTOM: 12pt&quot;&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal style=&quot;MARGIN-BOTTOM: 12pt&quot;&gt;----- Original Message ----&lt;BR&gt;From: Thor (Hammer of God) &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18227409&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;thor@...&lt;/a&gt;&amp;gt;&lt;BR&gt;To: Qaisar Naseem &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18227409&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;qaisarn@...&lt;/a&gt;&amp;gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18227409&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;BR&gt;Sent: Monday, June 23, 2008 5:33:33 PM&lt;BR&gt;Subject: RE: Help to remove blocking of MS outlook through ISA 2004&lt;/P&gt;
&lt;DIV&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;What protocols are you using to connect to the server?&amp;nbsp; I'm assuming you are talking about an internal Outlook client connecting to an external server.&amp;nbsp; What kind of ISA client is the host?&amp;nbsp; Are you using SNAT or FWC?&amp;nbsp; &amp;nbsp;A little infoz, please.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;t&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;-----------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;Check out Tim Mullen's &quot;Microsoft Ninjitsu&quot; training at Blackhat Vegas 2008. &lt;BR&gt;There are also some other great NGS classes lead by world-class researchers and trainers available.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&lt;A href=&quot;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&quot; target=_blank rel=&quot;nofollow&quot;&gt;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style=&quot;BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: blue 1.5pt solid; PADDING-TOP: 0in; BORDER-BOTTOM: medium none&quot;&gt;
&lt;DIV&gt;
&lt;DIV style=&quot;BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 3pt; BORDER-BOTTOM: medium none&quot;&gt;
&lt;P&gt;&lt;B&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt&quot;&gt;From:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt&quot;&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18227409&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18227409&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] &lt;B&gt;On Behalf Of &lt;/B&gt;Qaisar Naseem&lt;BR&gt;&lt;B&gt;Sent:&lt;/B&gt; Friday, June 20, 2008 9:02 AM&lt;BR&gt;&lt;B&gt;To:&lt;/B&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18227409&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;BR&gt;&lt;B&gt;Subject:&lt;/B&gt; Help to remove blocking of MS outlook through ISA 2004&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;P&gt;Hi,&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P&gt;I am using Windows server 2003 network with ISA 2004 as proxy. I am having problem in passing MS outlook requests. Even I created a firewall rule to allow all outbound traffic to external, but unable to solve the problem. Outlook configuration is quite OK as when I by pass proxy, it works fine.&lt;BR&gt;&lt;BR&gt;-- &lt;BR&gt;Qaisar Naseem&lt;BR&gt;Network Admin&lt;BR&gt;Express News TV&lt;BR&gt;+923457263848 &lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;P class=MsoNormal&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;-- &lt;BR&gt;Qaisar Naseem&lt;BR&gt;Network Admin&lt;BR&gt;Express News TV&lt;BR&gt;+923457263848 &lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br&gt;

      </content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Help-to-remove-blocking-of-MS-outlook-through-ISA-2004-tp18069334p18227409.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18205018</id>
	<title>RE: Help to remove blocking of MS outlook through ISA 2004</title>
	<published>2008-06-27T07:57:45Z</published>
	<updated>2008-06-27T07:57:45Z</updated>
	<author>
		<name>Thor (Hammer of God)</name>
	</author>
	<content type="html">&lt;html&gt;

&lt;head&gt;
&lt;META http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 12 (filtered medium)&quot;&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Wow.&amp;nbsp; I'm not saying this to be mean spirited, but when you
create rules to &amp;quot;allow all&amp;quot; in order to fix mail access from Outlook,
things have gone horribly wrong.&amp;nbsp; You now no longer have a firewall in ISA --
you now have what we call &amp;quot;a router.&amp;quot;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;t&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;div style='border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt'&gt;

&lt;div&gt;

&lt;div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;From:&lt;/span&gt;&lt;/b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt; Qaisar Naseem
[mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18205018&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;qaisarn@...&lt;/a&gt;] &lt;br&gt;
&lt;b&gt;Sent:&lt;/b&gt; Friday, June 27, 2008 6:48 AM&lt;br&gt;
&lt;b&gt;To:&lt;/b&gt; Faris Mlaeb&lt;br&gt;
&lt;b&gt;Cc:&lt;/b&gt; Thor (Hammer of God); &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18205018&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;br&gt;
&lt;b&gt;Subject:&lt;/b&gt; Re: Help to remove blocking of MS outlook through ISA 2004&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&lt;/p&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;Dear Mr. Faris.&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;Thanks a lot. I did the same what you have and solved the
problem. &lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;Thanks again.&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=MsoNormal style='margin-bottom:12.0pt'&gt;Qaisar&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;On Tue, Jun 24, 2008 at 2:20 AM, Faris Mlaeb &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18205018&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;farisnt@...&lt;/a&gt;&amp;gt; wrote:&lt;/p&gt;

&lt;div&gt;

&lt;div&gt;

&lt;p&gt;HI&lt;/p&gt;

&lt;p&gt;This is normal for ISA and you can fix this by going to:&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Open the ISA Server Console and expand the Configuration, and select
General, and then Click on &amp;quot;Define Firewall Client Settings&amp;quot;, You
will have a new Window for the &amp;quot;Firewall Client Settings&amp;quot;&lt;br&gt;
Click on the Application Tab and from the list select Outlook&lt;br&gt;
You will notice that its like this:&lt;br&gt;
Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;1&lt;br&gt;
change the value to be &lt;br&gt;
Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;0&lt;/p&gt;

&lt;p&gt;and on the Firewall client on the user PC&amp;nbsp; make sure that you click on
Detect Now Or simply restart your Computer&lt;/p&gt;

&lt;p&gt;This work for me perfect&lt;/p&gt;

&lt;p&gt;Have a nice time&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Note that if the value is not present .. then&amp;nbsp; simply create it&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;&lt;span style='color:#888888'&gt;&lt;br&gt;
&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;p class=MsoNormal align=center style='text-align:center'&gt;&lt;b&gt;&lt;span style='font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#0000BF'&gt;Faris Mlaeb&lt;/span&gt;&lt;/b&gt;&lt;span style='color:#888888'&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal align=center style='text-align:center'&gt;&lt;strong&gt;&lt;span style='font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#0000BF'&gt;Technical Manager&lt;/span&gt;&lt;/strong&gt;&lt;span style='color:#888888'&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal align=center style='text-align:center'&gt;&lt;strong&gt;&lt;span style='font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#0000BF'&gt;Network Administrator&lt;/span&gt;&lt;/strong&gt;&lt;span style='color:#888888'&gt;&lt;/span&gt;&lt;/p&gt;

&lt;div&gt;

&lt;div&gt;

&lt;div&gt;

&lt;p class=MsoNormal style='margin-bottom:12.0pt'&gt;&amp;nbsp;&lt;/p&gt;

&lt;div&gt;

&lt;p class=MsoNormal style='margin-bottom:12.0pt'&gt;----- Original Message ----&lt;br&gt;
From: Thor (Hammer of God) &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18205018&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;thor@...&lt;/a&gt;&amp;gt;&lt;br&gt;
To: Qaisar Naseem &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18205018&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;qaisarn@...&lt;/a&gt;&amp;gt;;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18205018&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;br&gt;
Sent: Monday, June 23, 2008 5:33:33 PM&lt;br&gt;
Subject: RE: Help to remove blocking of MS outlook through ISA 2004&lt;/p&gt;

&lt;div&gt;

&lt;p&gt;&lt;span style='font-size:11.0pt;color:#1F497D'&gt;What protocols are you using to
connect to the server?&amp;nbsp; I'm assuming you are talking about an internal
Outlook client connecting to an external server.&amp;nbsp; What kind of ISA client
is the host?&amp;nbsp; Are you using SNAT or FWC?&amp;nbsp; &amp;nbsp;A little infoz,
please.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:11.0pt;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:11.0pt;color:#1F497D'&gt;t&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:11.0pt;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:11.0pt;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:11.0pt;color:#1F497D'&gt;-----------&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:11.0pt;color:#1F497D'&gt;Check out Tim Mullen's
&amp;quot;Microsoft Ninjitsu&amp;quot; training at Blackhat Vegas 2008. &lt;br&gt;
There are also some other great NGS classes lead by world-class researchers and
trainers available.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:11.0pt;color:#1F497D'&gt;&lt;a href=&quot;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:11.0pt;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:11.0pt;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:11.0pt;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;div style='border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt'&gt;

&lt;div&gt;

&lt;div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'&gt;

&lt;p&gt;&lt;b&gt;&lt;span style='font-size:10.0pt'&gt;From:&lt;/span&gt;&lt;/b&gt;&lt;span style='font-size:
10.0pt'&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18205018&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;
[mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18205018&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;]
&lt;b&gt;On Behalf Of &lt;/b&gt;Qaisar Naseem&lt;br&gt;
&lt;b&gt;Sent:&lt;/b&gt; Friday, June 20, 2008 9:02 AM&lt;br&gt;
&lt;b&gt;To:&lt;/b&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18205018&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;br&gt;
&lt;b&gt;Subject:&lt;/b&gt; Help to remove blocking of MS outlook through ISA 2004&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;div&gt;

&lt;p&gt;Hi,&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p&gt;I am using Windows server 2003 network with ISA 2004 as proxy. I am having
problem in passing MS outlook requests. Even I created a firewall rule to allow
all outbound traffic to external, but unable to solve the problem. Outlook
configuration is quite OK as when I by pass proxy, it works fine.&lt;br&gt;
&lt;br&gt;
-- &lt;br&gt;
Qaisar Naseem&lt;br&gt;
Network Admin&lt;br&gt;
Express News TV&lt;br&gt;
+923457263848 &lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
-- &lt;br&gt;
Qaisar Naseem&lt;br&gt;
Network Admin&lt;br&gt;
Express News TV&lt;br&gt;
+923457263848 &lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Help-to-remove-blocking-of-MS-outlook-through-ISA-2004-tp18069334p18205018.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18204987</id>
	<title>Re: Help to remove blocking of MS outlook through ISA 2004</title>
	<published>2008-06-27T06:48:24Z</published>
	<updated>2008-06-27T06:48:24Z</updated>
	<author>
		<name>Qaisar Naseem</name>
	</author>
	<content type="html">&lt;div&gt;Dear Mr. Faris.&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Thanks a lot. I did the same what you have and solved the problem. &lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Thanks again.&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Qaisar&lt;br&gt;&lt;br&gt;&lt;/div&gt;
&lt;div class=&quot;gmail_quote&quot;&gt;On Tue, Jun 24, 2008 at 2:20 AM, Faris Mlaeb &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204987&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;farisnt@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid&quot;&gt;
&lt;div&gt;
&lt;div style=&quot;FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york, times, serif&quot;&gt;
&lt;p&gt;HI&lt;/p&gt;
&lt;p&gt;This is normal for ISA and you can fix this by going to:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Open the ISA Server Console and expand the Configuration, and select General, and then Click on &amp;quot;Define Firewall Client Settings&amp;quot;, You will have a new Window for the &amp;quot;Firewall Client Settings&amp;quot;&lt;br&gt;Click on the Application Tab and from the list select Outlook&lt;br&gt;
You will notice that its like this:&lt;br&gt;Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;1&lt;br&gt;change the value to be &lt;br&gt;Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;0&lt;/p&gt;
&lt;p&gt;and on the Firewall client on the user PC&amp;nbsp; make sure that you click on Detect Now Or simply restart your Computer&lt;/p&gt;
&lt;p&gt;This work for me perfect&lt;/p&gt;
&lt;p&gt;Have a nice time&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Note that if the value is not present .. then&amp;nbsp; simply create it&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;font color=&quot;#888888&quot;&gt;
&lt;div&gt;&lt;/div&gt;
&lt;div&gt;&lt;br&gt;&amp;nbsp;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;&lt;b&gt;&lt;span style=&quot;COLOR: #1f497d&quot;&gt;&lt;font size=&quot;3&quot;&gt;&lt;font face=&quot;Calibri&quot;&gt;&lt;font color=&quot;#0000bf&quot;&gt;Faris Mlaeb&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style=&quot;MARGIN: 0in 0in 0pt; TEXT-ALIGN: center&quot; align=&quot;center&quot;&gt;&lt;span style=&quot;COLOR: #1f497d&quot;&gt;&lt;font size=&quot;3&quot;&gt;&lt;font face=&quot;Calibri&quot; color=&quot;#0000bf&quot;&gt;&lt;strong&gt;Technical Manager&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot;&gt;&lt;font face=&quot;Calibri&quot;&gt;&lt;font color=&quot;#0000bf&quot; size=&quot;3&quot;&gt;&lt;strong&gt;Network Administrator&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/div&gt;&lt;/font&gt;
&lt;div&gt;
&lt;div&gt;&lt;/div&gt;
&lt;div class=&quot;Wj3C7c&quot;&gt;
&lt;div style=&quot;FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york, times, serif&quot;&gt;&lt;br&gt;&lt;br&gt;
&lt;div style=&quot;FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york, times, serif&quot;&gt;----- Original Message ----&lt;br&gt;From: Thor (Hammer of God) &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204987&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;thor@...&lt;/a&gt;&amp;gt;&lt;br&gt;
To: Qaisar Naseem &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204987&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;qaisarn@...&lt;/a&gt;&amp;gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204987&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;br&gt;Sent: Monday, June 23, 2008 5:33:33 PM&lt;br&gt;
Subject: RE: Help to remove blocking of MS outlook through ISA 2004&lt;br&gt;&lt;br&gt;
&lt;div&gt;
&lt;p&gt;&lt;span style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;What protocols are you using to connect to the server?&amp;nbsp; I&amp;#39;m assuming you are talking about an internal Outlook client connecting to an external server.&amp;nbsp; What kind of ISA client is the host?&amp;nbsp; Are you using SNAT or FWC?&amp;nbsp; &amp;nbsp;A little infoz, please.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;t&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;-----------&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;Check out Tim Mullen&amp;#39;s &amp;quot;Microsoft Ninjitsu&amp;quot; training at Blackhat Vegas 2008. &lt;br&gt;There are also some other great NGS classes lead by world-class researchers and trainers available.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&lt;a href=&quot;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;div style=&quot;BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: blue 1.5pt solid; PADDING-TOP: 0in; BORDER-BOTTOM: medium none&quot;&gt;
&lt;div&gt;
&lt;div style=&quot;BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 3pt; BORDER-BOTTOM: medium none&quot;&gt;
&lt;p&gt;&lt;b&gt;&lt;span style=&quot;FONT-SIZE: 10pt&quot;&gt;From:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;FONT-SIZE: 10pt&quot;&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204987&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204987&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] &lt;b&gt;On Behalf Of &lt;/b&gt;Qaisar Naseem&lt;br&gt;
&lt;b&gt;Sent:&lt;/b&gt; Friday, June 20, 2008 9:02 AM&lt;br&gt;&lt;b&gt;To:&lt;/b&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204987&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;br&gt;&lt;b&gt;Subject:&lt;/b&gt; Help to remove blocking of MS outlook through ISA 2004&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;div&gt;
&lt;p&gt;Hi,&lt;/p&gt;&lt;/div&gt;
&lt;div&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;
&lt;div&gt;
&lt;p&gt;I am using Windows server 2003 network with ISA 2004 as proxy. I am having problem in passing MS outlook requests. Even I created a firewall rule to allow all outbound traffic to external, but unable to solve the problem. Outlook configuration is quite OK as when I by pass proxy, it works fine.&lt;br&gt;
&lt;br&gt;-- &lt;br&gt;Qaisar Naseem&lt;br&gt;Network Admin&lt;br&gt;Express News TV&lt;br&gt;+923457263848 &lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;Qaisar Naseem&lt;br&gt;Network Admin&lt;br&gt;
Express News TV&lt;br&gt;+923457263848 
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Help-to-remove-blocking-of-MS-outlook-through-ISA-2004-tp18069334p18204987.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18204925</id>
	<title>Re: Recommendations</title>
	<published>2008-06-27T00:32:58Z</published>
	<updated>2008-06-27T00:32:58Z</updated>
	<author>
		<name>Johann Spies</name>
	</author>
	<content type="html">On Wed, Jun 25, 2008 at 07:55:31PM +0300, Paolo Supino wrote:
&lt;br&gt;&amp;gt; -----BEGIN PGP SIGNED MESSAGE----- ~ 
&lt;br&gt;&lt;br&gt;&amp;gt; How much of a turnkey solution
&lt;br&gt;&amp;gt; are you looking for? If you have the time to sit down do some
&lt;br&gt;&amp;gt; development and integration than using PF on OpenBSD would give you
&lt;br&gt;&amp;gt; an awesome solution... &amp;nbsp;~ I don't think it will be a very big
&lt;br&gt;&amp;gt; project, look at integrating usernames/IP addresses (or anything
&lt;br&gt;&amp;gt; else) with PF's anchors ...
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;Thanks to you, Daniel and Rick for responding. &amp;nbsp;I will certainly look
&lt;br&gt;at the PF-solution on openbsd.
&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;Johann
&lt;br&gt;-- 
&lt;br&gt;Johann Spies &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Telefoon: 021-808 4036
&lt;br&gt;Informasietegnologie, Universiteit van Stellenbosch
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;quot;For I am not ashamed of the gospel of Christ: for it 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; is the power of God unto salvation to every one that 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; believeth; to the Jew first, and also to the Greek.&amp;quot; &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Romans 1:16 
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Recommendations-tp18119235p18204925.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18204888</id>
	<title>RE: Help to remove blocking of MS outlook through ISA 2004</title>
	<published>2008-06-26T21:45:06Z</published>
	<updated>2008-06-26T21:45:06Z</updated>
	<author>
		<name>Thor (Hammer of God)</name>
	</author>
	<content type="html">&lt;html&gt;

&lt;head&gt;
&lt;META http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 12 (filtered medium)&quot;&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body link=&quot;#000000&quot; vlink=&quot;#000000&quot;&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Sorry, but if you had to create an All outbound from int to ext,
then you've done something wrong on your rule.&amp;nbsp; The firewall client is great,
but it is not a necessity -- of course, you would want it to ensure
authenticated access to rules based on domain membership for non-web traffic,
but that's another story.&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;ISA blocks all traffic by default.&amp;nbsp; If you allow POP3 from the
client to the server, it works, and without the need for adding the
&amp;quot;enable&amp;quot; tag in the FWC config&amp;nbsp; (without question).&amp;nbsp; &lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Least Privilege dictates that you only allow what you need, only
to where you need it, and only to those that need it.&amp;nbsp; Enabling outlook.exe
itself for all access is overkill and unnecessary.&amp;nbsp; If you POP3 rule didn't
work, you either had an authentication problem, or didn't create the rule
properly (like you used POP3 Server instead of POP3 or something like that).&amp;nbsp;
The logs will tell you everything you need to know in order to troubleshoot
that.&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;t&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;-----------&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Check out Tim Mullen's &amp;quot;Microsoft Ninjitsu&amp;quot; training
at Blackhat Vegas 2008. &lt;br&gt;
There are also some other great NGS classes lead by world-class researchers and
trainers available.&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;div style='border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt'&gt;

&lt;div&gt;

&lt;div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;From:&lt;/span&gt;&lt;/b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] &lt;b&gt;On Behalf
Of &lt;/b&gt;Faris Mlaeb&lt;br&gt;
&lt;b&gt;Sent:&lt;/b&gt; Thursday, June 26, 2008 9:25 AM&lt;br&gt;
&lt;b&gt;To:&lt;/b&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;; Thor (Hammer of God)&lt;br&gt;
&lt;b&gt;Subject:&lt;/b&gt; RE: Help to remove blocking of MS outlook through ISA 2004&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&lt;/p&gt;

&lt;table class=MsoNormalTable border=0 cellspacing=0 cellpadding=0&gt;
 &lt;tr&gt;
  &lt;td valign=top style='padding:0in 0in 0in 0in'&gt;
  &lt;p align=center style='text-align:center'&gt;&amp;nbsp;&lt;/p&gt;
  &lt;p&gt;Hi &lt;br&gt;
  As it seem .. and even if he dont have Firewall Client installed, he should
  install it &lt;br&gt;
  I have Such a problem where client in my network have a problem can not
  connect to a POP3 Server using MS Outlook &lt;br&gt;
  I had Create a Rule that allow POP3 and also a Rule to Allow ALLOUTBOUND
  TRAFFIC From Internal To External To All Users, But as it seem that ISA
  Server is configured to Block the Connection for Outlook what ever the
  Portocol that is being sent to the external as its in ISA Server ((
  OutLook&amp;nbsp;disable&amp;nbsp;&amp;nbsp; 1))&lt;br&gt;
  Anyway&lt;br&gt;
  As Qaisar Naseem says ((Even I created a firewall rule to allow all outbound
  traffic to external, but unable to solve the problem)), so it seem that
  enabling so will help&lt;br&gt;
  Anyway .. do you have a Better method for enabling this and Allowing the
  outlook to connect to the external without having to change it from ISA&lt;/p&gt;
  &lt;p&gt;Thanks alot&lt;br&gt;
  &lt;br&gt;
  &lt;br&gt;
  --- On &lt;b&gt;Wed, 6/25/08, Thor (Hammer of God) &lt;i&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;thor@...&lt;/a&gt;&amp;gt;&lt;/i&gt;&lt;/b&gt;
  wrote:&lt;/p&gt;
  &lt;blockquote style='border:none;border-left:solid #1010FF 1.5pt;padding:0in 0in 0in 4.0pt;
  margin-left:3.75pt;margin-top:5.0pt;margin-bottom:5.0pt'&gt;
  &lt;p class=MsoNormal style='margin-bottom:12.0pt'&gt;From: Thor (Hammer of God)
  &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;thor@...&lt;/a&gt;&amp;gt;&lt;br&gt;
  Subject: RE: Help to remove blocking of MS outlook through ISA 2004&lt;br&gt;
  To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;br&gt;
  Date: Wednesday, June 25, 2008, 11:49 AM&lt;/p&gt;
  &lt;div id=yiv556117278&gt;
  &lt;div&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;A
  couple of things:&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;One,
  you don't know that he is running a firewall client. &amp;nbsp;Secondly it is
  never recommended to just enable full access to an overall application when
  you can more finely restrict access based on protocol.&amp;nbsp;&amp;nbsp; The client
  may simply be using POP3 -- it would be silly to just &amp;quot;allow
  Outlook&amp;quot; as an application to all of your firewall clients when you can
  just allow POP3 (or whatever it is) to only the clients that need it.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;t&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
  &lt;div style='border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt'&gt;
  &lt;div&gt;
  &lt;div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;From:&lt;/span&gt;&lt;/b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;
  &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] &lt;b&gt;On
  Behalf Of &lt;/b&gt;Faris Mlaeb&lt;br&gt;
  &lt;b&gt;Sent:&lt;/b&gt; Monday, June 23, 2008 2:20 PM&lt;br&gt;
  &lt;b&gt;To:&lt;/b&gt; Thor (Hammer of God); Qaisar Naseem; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;br&gt;
  &lt;b&gt;Subject:&lt;/b&gt; Re: Help to remove blocking of MS outlook through ISA 2004&lt;/span&gt;&lt;/p&gt;
  &lt;/div&gt;
  &lt;/div&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&amp;nbsp;&lt;/p&gt;
  &lt;div&gt;
  &lt;p&gt;HI&lt;/p&gt;
  &lt;p&gt;This is normal for ISA and you can fix this by going to:&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&lt;/p&gt;
  &lt;p&gt;Open the ISA Server Console and expand the Configuration, and select
  General, and then Click on &amp;quot;Define Firewall Client Settings&amp;quot;, You
  will have a new Window for the &amp;quot;Firewall Client Settings&amp;quot;&lt;br&gt;
  Click on the Application Tab and from the list select Outlook&lt;br&gt;
  You will notice that its like this:&lt;br&gt;
  Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;1&lt;br&gt;
  change the value to be &lt;br&gt;
  Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;0&lt;/p&gt;
  &lt;p&gt;and on the Firewall client on the user PC&amp;nbsp; make sure that you click
  on Detect Now Or simply restart your Computer&lt;/p&gt;
  &lt;p&gt;This work for me perfect&lt;/p&gt;
  &lt;p&gt;Have a nice time&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&lt;/p&gt;
  &lt;p&gt;Note that if the value is not present .. then&amp;nbsp; simply create it&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&lt;/p&gt;
  &lt;div&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;br&gt;
  &amp;nbsp;&lt;/p&gt;
  &lt;/div&gt;
  &lt;p class=MsoNormal align=center style='mso-margin-top-alt:auto;mso-margin-bottom-alt:
  auto;text-align:center'&gt;&lt;b&gt;&lt;span style='font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
  color:#0000BF'&gt;Faris Mlaeb&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
  &lt;p class=MsoNormal align=center style='mso-margin-top-alt:auto;mso-margin-bottom-alt:
  auto;text-align:center'&gt;&lt;strong&gt;&lt;span style='font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
  color:#0000BF'&gt;Technical Manager&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
  &lt;p class=MsoNormal align=center style='mso-margin-top-alt:auto;mso-margin-bottom-alt:
  auto;text-align:center'&gt;&lt;strong&gt;&lt;span style='font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
  color:#0000BF'&gt;Network Administrator&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
  &lt;div&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;margin-bottom:12.0pt'&gt;&amp;nbsp;&lt;/p&gt;
  &lt;div&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;margin-bottom:12.0pt'&gt;-----
  Original Message ----&lt;br&gt;
  From: Thor (Hammer of God) &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;thor@...&lt;/a&gt;&amp;gt;&lt;br&gt;
  To: Qaisar Naseem &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;qaisarn@...&lt;/a&gt;&amp;gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;br&gt;
  Sent: Monday, June 23, 2008 5:33:33 PM&lt;br&gt;
  Subject: RE: Help to remove blocking of MS outlook through ISA 2004&lt;/p&gt;
  &lt;div&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;What
  protocols are you using to connect to the server?&amp;nbsp; I'm assuming you are
  talking about an internal Outlook client connecting to an external
  server.&amp;nbsp; What kind of ISA client is the host?&amp;nbsp; Are you using SNAT
  or FWC?&amp;nbsp; &amp;nbsp;A little infoz, please.&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;t&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;-----------&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;Check
  out Tim Mullen's &amp;quot;Microsoft Ninjitsu&amp;quot; training at Blackhat Vegas
  2008. &lt;br&gt;
  There are also some other great NGS classes lead by world-class researchers
  and trainers available.&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;&lt;a href=&quot;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;&lt;u&gt;&lt;span style='color:blue'&gt;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&lt;/span&gt;&lt;/u&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
  &lt;div style='border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt'&gt;
  &lt;div&gt;
  &lt;div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&lt;b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;From:&lt;/span&gt;&lt;/b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;
  &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=12&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=13&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] &lt;b&gt;On
  Behalf Of &lt;/b&gt;Qaisar Naseem&lt;br&gt;
  &lt;b&gt;Sent:&lt;/b&gt; Friday, June 20, 2008 9:02 AM&lt;br&gt;
  &lt;b&gt;To:&lt;/b&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18204888&amp;i=14&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;br&gt;
  &lt;b&gt;Subject:&lt;/b&gt; Help to remove blocking of MS outlook through ISA 2004&lt;/span&gt;&lt;/p&gt;
  &lt;/div&gt;
  &lt;/div&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&amp;nbsp;&lt;/p&gt;
  &lt;div&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;Hi,&lt;/p&gt;
  &lt;/div&gt;
  &lt;div&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&amp;nbsp;&lt;/p&gt;
  &lt;/div&gt;
  &lt;div&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;I
  am using Windows server 2003 network with ISA 2004 as proxy. I am having
  problem in passing MS outlook requests. Even I created a firewall rule to
  allow all outbound traffic to external, but unable to solve the problem.
  Outlook configuration is quite OK as when I by pass proxy, it works fine.&lt;br&gt;
  &lt;br&gt;
  -- &lt;br&gt;
  Qaisar Naseem&lt;br&gt;
  Network Admin&lt;br&gt;
  Express News TV&lt;br&gt;
  +923457263848 &lt;/p&gt;
  &lt;/div&gt;
  &lt;/div&gt;
  &lt;/div&gt;
  &lt;/div&gt;
  &lt;/div&gt;
  &lt;/div&gt;
  &lt;p class=MsoNormal style='mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'&gt;&amp;nbsp;&lt;/p&gt;
  &lt;/div&gt;
  &lt;/div&gt;
  &lt;/div&gt;
  &lt;/blockquote&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
&lt;/table&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Help-to-remove-blocking-of-MS-outlook-through-ISA-2004-tp18069334p18204888.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18145328</id>
	<title>RE: Help to remove blocking of MS outlook through ISA 2004</title>
	<published>2008-06-26T09:25:21Z</published>
	<updated>2008-06-26T09:25:21Z</updated>
	<author>
		<name>Faris Mlaeb</name>
	</author>
	<content type="html">&lt;table cellspacing='0' cellpadding='0' border='0'&gt;&lt;tr&gt;&lt;td valign='top' style='font: inherit;'&gt;&lt;P align=center&gt;&lt;FONT face=Calibri&gt;&lt;FONT color=#0000bf size=3&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi &lt;BR&gt;As it seem .. and even if he dont have Firewall Client installed, he should install it &lt;BR&gt;I have Such a problem where client in my network have a problem can not connect to a POP3 Server using MS Outlook &lt;BR&gt;I had Create a Rule that allow POP3 and also a Rule to Allow ALLOUTBOUND TRAFFIC From Internal To External To All Users, But as it seem that ISA Server is configured to Block the Connection for Outlook what ever the Portocol that is being sent to the external as its in ISA Server (( OutLook&amp;nbsp;disable&amp;nbsp;&amp;nbsp; 1))&lt;BR&gt;Anyway&lt;BR&gt;As Qaisar Naseem says ((Even I created a firewall rule to allow all outbound traffic to external, but unable to solve the problem)), so it seem that enabling so will help&lt;BR&gt;Anyway .. do you have a Better method for enabling this and Allowing the outlook to connect to the external without having to change it from ISA&lt;/P&gt;
&lt;P&gt;Thanks alot&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;--- On &lt;B&gt;Wed, 6/25/08, Thor (Hammer of God) &lt;I&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18145328&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;thor@...&lt;/a&gt;&amp;gt;&lt;/I&gt;&lt;/B&gt; wrote:&lt;BR&gt;&lt;/P&gt;
&lt;BLOCKQUOTE style=&quot;PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: rgb(16,16,255) 2px solid&quot;&gt;From: Thor (Hammer of God) &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18145328&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;thor@...&lt;/a&gt;&amp;gt;&lt;BR&gt;Subject: RE: Help to remove blocking of MS outlook through ISA 2004&lt;BR&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18145328&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;BR&gt;Date: Wednesday, June 25, 2008, 11:49 AM&lt;BR&gt;&lt;BR&gt;
&lt;DIV id=yiv556117278&gt;


&lt;DIV class=Section1&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;A couple of things:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;One, you don't know that he is running a firewall client. &amp;nbsp;Secondly it is never recommended to just enable full access to an overall application when you can more finely restrict access based on protocol.&amp;nbsp;&amp;nbsp; The client may simply be using POP3 -- it would be silly to just &quot;allow Outlook&quot; as an application to all of your firewall clients when you can just allow POP3 (or whatever it is) to only the clients that need it.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;t&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style=&quot;BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: blue 1.5pt solid; PADDING-TOP: 0in; BORDER-BOTTOM: medium none&quot;&gt;
&lt;DIV&gt;
&lt;DIV style=&quot;BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 3pt; BORDER-BOTTOM: medium none&quot;&gt;
&lt;P class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma', 'sans-serif'&quot;&gt;From:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma', 'sans-serif'&quot;&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18145328&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18145328&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] &lt;B&gt;On Behalf Of &lt;/B&gt;Faris Mlaeb&lt;BR&gt;&lt;B&gt;Sent:&lt;/B&gt; Monday, June 23, 2008 2:20 PM&lt;BR&gt;&lt;B&gt;To:&lt;/B&gt; Thor (Hammer of God); Qaisar Naseem; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18145328&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;BR&gt;&lt;B&gt;Subject:&lt;/B&gt; Re: Help to remove blocking of MS outlook through ISA 2004&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;P&gt;HI&lt;/P&gt;
&lt;P&gt;This is normal for ISA and you can fix this by going to:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Open the ISA Server Console and expand the Configuration, and select General, and then Click on &quot;Define Firewall Client Settings&quot;, You will have a new Window for the &quot;Firewall Client Settings&quot;&lt;BR&gt;Click on the Application Tab and from the list select Outlook&lt;BR&gt;You will notice that its like this:&lt;BR&gt;Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;1&lt;BR&gt;change the value to be &lt;BR&gt;Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;0&lt;/P&gt;
&lt;P&gt;and on the Firewall client on the user PC&amp;nbsp; make sure that you click on Detect Now Or simply restart your Computer&lt;/P&gt;
&lt;P&gt;This work for me perfect&lt;/P&gt;
&lt;P&gt;Have a nice time&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that if the value is not present .. then&amp;nbsp; simply create it&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;&lt;BR&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;
&lt;P class=MsoNormal style=&quot;TEXT-ALIGN: center&quot; align=center&gt;&lt;B&gt;&lt;SPAN style=&quot;COLOR: #0000bf; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;Faris Mlaeb&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style=&quot;TEXT-ALIGN: center&quot; align=center&gt;&lt;STRONG&gt;&lt;SPAN style=&quot;COLOR: #0000bf; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;Technical Manager&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=MsoNormal style=&quot;TEXT-ALIGN: center&quot; align=center&gt;&lt;STRONG&gt;&lt;SPAN style=&quot;COLOR: #0000bf; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;Network Administrator&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal style=&quot;MARGIN-BOTTOM: 12pt&quot;&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal style=&quot;MARGIN-BOTTOM: 12pt&quot;&gt;----- Original Message ----&lt;BR&gt;From: Thor (Hammer of God) &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18145328&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;thor@...&lt;/a&gt;&amp;gt;&lt;BR&gt;To: Qaisar Naseem &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18145328&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;qaisarn@...&lt;/a&gt;&amp;gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18145328&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;BR&gt;Sent: Monday, June 23, 2008 5:33:33 PM&lt;BR&gt;Subject: RE: Help to remove blocking of MS outlook through ISA 2004&lt;/P&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;What protocols are you using to connect to the server?&amp;nbsp; I'm assuming you are talking about an internal Outlook client connecting to an external server.&amp;nbsp; What kind of ISA client is the host?&amp;nbsp; Are you using SNAT or FWC?&amp;nbsp; &amp;nbsp;A little infoz, please.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;t&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;-----------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;Check out Tim Mullen's &quot;Microsoft Ninjitsu&quot; training at Blackhat Vegas 2008. &lt;BR&gt;There are also some other great NGS classes lead by world-class researchers and trainers available.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&lt;A href=&quot;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&quot; target=_blank rel=&quot;nofollow&quot;&gt;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style=&quot;BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: blue 1.5pt solid; PADDING-TOP: 0in; BORDER-BOTTOM: medium none&quot;&gt;
&lt;DIV&gt;
&lt;DIV style=&quot;BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 3pt; BORDER-BOTTOM: medium none&quot;&gt;
&lt;P class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma', 'sans-serif'&quot;&gt;From:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma', 'sans-serif'&quot;&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18145328&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18145328&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] &lt;B&gt;On Behalf Of &lt;/B&gt;Qaisar Naseem&lt;BR&gt;&lt;B&gt;Sent:&lt;/B&gt; Friday, June 20, 2008 9:02 AM&lt;BR&gt;&lt;B&gt;To:&lt;/B&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18145328&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;BR&gt;&lt;B&gt;Subject:&lt;/B&gt; Help to remove blocking of MS outlook through ISA 2004&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;Hi,&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;I am using Windows server 2003 network with ISA 2004 as proxy. I am having problem in passing MS outlook requests. Even I created a firewall rule to allow all outbound traffic to external, but unable to solve the problem. Outlook configuration is quite OK as when I by pass proxy, it works fine.&lt;BR&gt;&lt;BR&gt;-- &lt;BR&gt;Qaisar Naseem&lt;BR&gt;Network Admin&lt;BR&gt;Express News TV&lt;BR&gt;+923457263848 &lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br&gt;

      </content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Help-to-remove-blocking-of-MS-outlook-through-ISA-2004-tp18069334p18145328.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18145069</id>
	<title>Re: Recommendations</title>
	<published>2008-06-25T22:59:14Z</published>
	<updated>2008-06-25T22:59:14Z</updated>
	<author>
		<name>Rick Zhong</name>
	</author>
	<content type="html">HI,
&lt;br&gt;From the problem you described, I find the customized accounting
&lt;br&gt;program is the main issue. You may want to upgrade/re-develop the
&lt;br&gt;program to make it charge by userid+source ip. If this will satisfy
&lt;br&gt;your requirement, then it is not necessary to change the firewall.
&lt;br&gt;Anyway if you change the firewall, I guess you still need to make
&lt;br&gt;changes to the accounting program.
&lt;br&gt;&lt;br&gt;regards,
&lt;br&gt;Rick
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Information (In)Security @ Where It Matters - &lt;a href=&quot;http://blog.rickzhong.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://blog.rickzhong.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;On Thu, Jun 26, 2008 at 12:56 AM, Daniel Clemens
&lt;br&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18145069&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;daniel.clemens@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Jun 24, 2008, at 1:40 AM, Johann Spies wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; We have to either renew the licence on our Checkpoint Firewall-1 NG
&lt;br&gt;&amp;gt;&amp;gt; (and upgrade it) or change to another software solution for our
&lt;br&gt;&amp;gt;&amp;gt; firewall setup.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I would upgrade. Keep things simple with what you already know.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Our approximately 25000 users pay for internet, some of them use a
&lt;br&gt;&amp;gt;&amp;gt; pay-as-you-go-system. &amp;nbsp;At the moment the accounting is done by custom
&lt;br&gt;&amp;gt;&amp;gt; programs that reads the active connections in the FW-memory. &amp;nbsp;We have
&lt;br&gt;&amp;gt;&amp;gt; two problems with the present setup:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; 1. FW-1 does not connect the user and the traffic in memory or always
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;in the logs. Only the source IP. &amp;nbsp;So it is impossible for us to
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;handle accounting for different users using the same IP.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; 2. FW-1 does not end active connections immediately after a user has
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp;logged off.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; 1) What would be an acceptable connection teardown timeout value?
&lt;br&gt;&amp;gt; 2) active connections will timeout or tear down within minutes of a
&lt;br&gt;&amp;gt; connection.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; We are in a process of evaluating different options. &amp;nbsp;One of them is
&lt;br&gt;&amp;gt;&amp;gt; NuFw - an open source product.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Any recommendations of other products you know of will be appreciated.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Regards
&lt;br&gt;&amp;gt;&amp;gt; Johann
&lt;br&gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt; Johann Spies &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Telefoon: 021-808 4036
&lt;br&gt;&amp;gt;&amp;gt; Informasietegnologie, Universiteit van Stellenbosch
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp;&amp;quot;Children, obey your parents in the Lord: for this is
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; right.&amp;quot; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Ephesians 6:1
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Recommendations-tp18119235p18145069.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18123239</id>
	<title>RE: Help to remove blocking of MS outlook through ISA 2004</title>
	<published>2008-06-25T11:49:47Z</published>
	<updated>2008-06-25T11:49:47Z</updated>
	<author>
		<name>Thor (Hammer of God)</name>
	</author>
	<content type="html">&lt;html&gt;

&lt;head&gt;
&lt;META http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 12 (filtered medium)&quot;&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;A couple of things:&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;One, you don't know that he is running a firewall client. &amp;nbsp;Secondly
it is never recommended to just enable full access to an overall application
when you can more finely restrict access based on protocol.&amp;nbsp;&amp;nbsp; The client may
simply be using POP3 -- it would be silly to just &amp;quot;allow Outlook&amp;quot; as
an application to all of your firewall clients when you can just allow POP3 (or
whatever it is) to only the clients that need it.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;t&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;div style='border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt'&gt;

&lt;div&gt;

&lt;div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;From:&lt;/span&gt;&lt;/b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18123239&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18123239&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] &lt;b&gt;On Behalf
Of &lt;/b&gt;Faris Mlaeb&lt;br&gt;
&lt;b&gt;Sent:&lt;/b&gt; Monday, June 23, 2008 2:20 PM&lt;br&gt;
&lt;b&gt;To:&lt;/b&gt; Thor (Hammer of God); Qaisar Naseem; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18123239&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;br&gt;
&lt;b&gt;Subject:&lt;/b&gt; Re: Help to remove blocking of MS outlook through ISA 2004&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&lt;/p&gt;

&lt;div&gt;

&lt;p&gt;HI&lt;/p&gt;

&lt;p&gt;This is normal for ISA and you can fix this by going to:&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Open the ISA Server Console and expand the Configuration, and select
General, and then Click on &amp;quot;Define Firewall Client Settings&amp;quot;, You
will have a new Window for the &amp;quot;Firewall Client Settings&amp;quot;&lt;br&gt;
Click on the Application Tab and from the list select Outlook&lt;br&gt;
You will notice that its like this:&lt;br&gt;
Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;1&lt;br&gt;
change the value to be &lt;br&gt;
Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;0&lt;/p&gt;

&lt;p&gt;and on the Firewall client on the user PC&amp;nbsp; make sure that you click on
Detect Now Or simply restart your Computer&lt;/p&gt;

&lt;p&gt;This work for me perfect&lt;/p&gt;

&lt;p&gt;Have a nice time&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Note that if the value is not present .. then&amp;nbsp; simply create it&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;&lt;br&gt;
&amp;nbsp;&lt;/p&gt;

&lt;/div&gt;

&lt;p class=MsoNormal align=center style='text-align:center'&gt;&lt;b&gt;&lt;span style='font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#0000BF'&gt;Faris Mlaeb&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class=MsoNormal align=center style='text-align:center'&gt;&lt;strong&gt;&lt;span style='font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#0000BF'&gt;Technical Manager&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p class=MsoNormal align=center style='text-align:center'&gt;&lt;strong&gt;&lt;span style='font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#0000BF'&gt;Network Administrator&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;div&gt;

&lt;p class=MsoNormal style='margin-bottom:12.0pt'&gt;&amp;nbsp;&lt;/p&gt;

&lt;div&gt;

&lt;p class=MsoNormal style='margin-bottom:12.0pt'&gt;----- Original Message ----&lt;br&gt;
From: Thor (Hammer of God) &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18123239&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;thor@...&lt;/a&gt;&amp;gt;&lt;br&gt;
To: Qaisar Naseem &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18123239&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;qaisarn@...&lt;/a&gt;&amp;gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18123239&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;br&gt;
Sent: Monday, June 23, 2008 5:33:33 PM&lt;br&gt;
Subject: RE: Help to remove blocking of MS outlook through ISA 2004&lt;/p&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;What protocols are you using to connect to the server?&amp;nbsp; I'm
assuming you are talking about an internal Outlook client connecting to an
external server.&amp;nbsp; What kind of ISA client is the host?&amp;nbsp; Are you using
SNAT or FWC?&amp;nbsp; &amp;nbsp;A little infoz, please.&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;t&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;-----------&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Check out Tim Mullen's &amp;quot;Microsoft Ninjitsu&amp;quot; training
at Blackhat Vegas 2008. &lt;br&gt;
There are also some other great NGS classes lead by world-class researchers and
trainers available.&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;a href=&quot;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;div style='border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt'&gt;

&lt;div&gt;

&lt;div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;From:&lt;/span&gt;&lt;/b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18123239&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18123239&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] &lt;b&gt;On Behalf
Of &lt;/b&gt;Qaisar Naseem&lt;br&gt;
&lt;b&gt;Sent:&lt;/b&gt; Friday, June 20, 2008 9:02 AM&lt;br&gt;
&lt;b&gt;To:&lt;/b&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18123239&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;br&gt;
&lt;b&gt;Subject:&lt;/b&gt; Help to remove blocking of MS outlook through ISA 2004&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&lt;/p&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;Hi,&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;I am using Windows server 2003 network with ISA 2004 as
proxy. I am having problem in passing MS outlook requests. Even I created a
firewall rule to allow all outbound traffic to external, but unable to solve
the problem. Outlook configuration is quite OK as when I by pass proxy, it
works fine.&lt;br&gt;
&lt;br&gt;
-- &lt;br&gt;
Qaisar Naseem&lt;br&gt;
Network Admin&lt;br&gt;
Express News TV&lt;br&gt;
+923457263848 &lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Help-to-remove-blocking-of-MS-outlook-through-ISA-2004-tp18069334p18123239.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18123215</id>
	<title>Re: Recommendations</title>
	<published>2008-06-25T09:56:54Z</published>
	<updated>2008-06-25T09:56:54Z</updated>
	<author>
		<name>Daniel Clemens</name>
	</author>
	<content type="html">&lt;br&gt;&lt;br&gt;&lt;br&gt;On Jun 24, 2008, at 1:40 AM, Johann Spies wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; We have to either renew the licence on our Checkpoint Firewall-1 NG
&lt;br&gt;&amp;gt; (and upgrade it) or change to another software solution for our
&lt;br&gt;&amp;gt; firewall setup.
&lt;br&gt;&lt;br&gt;I would upgrade. Keep things simple with what you already know.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Our approximately 25000 users pay for internet, some of them use a
&lt;br&gt;&amp;gt; pay-as-you-go-system. &amp;nbsp;At the moment the accounting is done by custom
&lt;br&gt;&amp;gt; programs that reads the active connections in the FW-memory. &amp;nbsp;We have
&lt;br&gt;&amp;gt; two problems with the present setup:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; 1. FW-1 does not connect the user and the traffic in memory or always
&lt;br&gt;&amp;gt; &amp;nbsp; in the logs. Only the source IP. &amp;nbsp;So it is impossible for us to
&lt;br&gt;&amp;gt; &amp;nbsp; handle accounting for different users using the same IP.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; 2. FW-1 does not end active connections immediately after a user has
&lt;br&gt;&amp;gt; &amp;nbsp; logged off.
&lt;/div&gt;&lt;br&gt;&lt;br&gt;1) What would be an acceptable connection teardown timeout value?
&lt;br&gt;2) active connections will timeout or tear down within minutes of a &amp;nbsp;
&lt;br&gt;connection.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; We are in a process of evaluating different options. &amp;nbsp;One of them is
&lt;br&gt;&amp;gt; NuFw - an open source product.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Any recommendations of other products you know of will be appreciated.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Regards
&lt;br&gt;&amp;gt; Johann
&lt;br&gt;&amp;gt; -- 
&lt;br&gt;&amp;gt; Johann Spies &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Telefoon: 021-808 4036
&lt;br&gt;&amp;gt; Informasietegnologie, Universiteit van Stellenbosch
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;quot;Children, obey your parents in the Lord: for this is
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;right.&amp;quot; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Ephesians 6:1
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Recommendations-tp18119235p18123215.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18123188</id>
	<title>Re: Recommendations</title>
	<published>2008-06-25T09:55:31Z</published>
	<updated>2008-06-25T09:55:31Z</updated>
	<author>
		<name>Paolo Supino-3</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;Hi
&lt;br&gt;&lt;br&gt;~ &amp;nbsp;How much of a turnkey solution are you looking for? If you have the
&lt;br&gt;time to sit down do some development and integration than using PF on
&lt;br&gt;OpenBSD would give you an awesome solution...
&lt;br&gt;~ &amp;nbsp;I don't think it will be a very big project, look at integrating
&lt;br&gt;usernames/IP addresses (or anything else) with PF's anchors ...
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;- --
&lt;br&gt;ttyl
&lt;br&gt;Paolo
&lt;br&gt;&lt;br&gt;&lt;br&gt;Johann Spies wrote:
&lt;br&gt;| We have to either renew the licence on our Checkpoint Firewall-1 NG
&lt;br&gt;| (and upgrade it) or change to another software solution for our
&lt;br&gt;| firewall setup.
&lt;br&gt;|
&lt;br&gt;| Our approximately 25000 users pay for internet, some of them use a
&lt;br&gt;| pay-as-you-go-system. &amp;nbsp;At the moment the accounting is done by custom
&lt;br&gt;| programs that reads the active connections in the FW-memory. &amp;nbsp;We have
&lt;br&gt;| two problems with the present setup:
&lt;br&gt;|
&lt;br&gt;| 1. FW-1 does not connect the user and the traffic in memory or always
&lt;br&gt;| &amp;nbsp; &amp;nbsp;in the logs. Only the source IP. &amp;nbsp;So it is impossible for us to
&lt;br&gt;| &amp;nbsp; &amp;nbsp;handle accounting for different users using the same IP.
&lt;br&gt;|
&lt;br&gt;| 2. FW-1 does not end active connections immediately after a user has
&lt;br&gt;| &amp;nbsp; &amp;nbsp;logged off.
&lt;br&gt;|
&lt;br&gt;| We are in a process of evaluating different options. &amp;nbsp;One of them is
&lt;br&gt;| NuFw - an open source product.
&lt;br&gt;|
&lt;br&gt;| Any recommendations of other products you know of will be appreciated.
&lt;br&gt;|
&lt;br&gt;| Regards
&lt;br&gt;| Johann
&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.8 (Darwin)
&lt;br&gt;Comment: Using GnuPG with Mozilla - &lt;a href=&quot;http://enigmail.mozdev.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://enigmail.mozdev.org&lt;/a&gt;&lt;br&gt;&lt;br&gt;iEYEARECAAYFAkhieIIACgkQRrCnED/jZ/h86ACfbhk082MPunvUCddSnayhzymV
&lt;br&gt;qWEAoJKRe46OIK1l9fs6Hqnh+SMbsLVA
&lt;br&gt;=EMSk
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Recommendations-tp18119235p18123188.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18119235</id>
	<title>Recommendations</title>
	<published>2008-06-23T23:40:43Z</published>
	<updated>2008-06-23T23:40:43Z</updated>
	<author>
		<name>Johann Spies</name>
	</author>
	<content type="html">We have to either renew the licence on our Checkpoint Firewall-1 NG
&lt;br&gt;(and upgrade it) or change to another software solution for our
&lt;br&gt;firewall setup.
&lt;br&gt;&lt;br&gt;Our approximately 25000 users pay for internet, some of them use a
&lt;br&gt;pay-as-you-go-system. &amp;nbsp;At the moment the accounting is done by custom
&lt;br&gt;programs that reads the active connections in the FW-memory. &amp;nbsp;We have
&lt;br&gt;two problems with the present setup: 
&lt;br&gt;&lt;br&gt;1. FW-1 does not connect the user and the traffic in memory or always
&lt;br&gt;&amp;nbsp; &amp;nbsp;in the logs. Only the source IP. &amp;nbsp;So it is impossible for us to
&lt;br&gt;&amp;nbsp; &amp;nbsp;handle accounting for different users using the same IP.
&lt;br&gt;&lt;br&gt;2. FW-1 does not end active connections immediately after a user has
&lt;br&gt;&amp;nbsp; &amp;nbsp;logged off.
&lt;br&gt;&lt;br&gt;We are in a process of evaluating different options. &amp;nbsp;One of them is
&lt;br&gt;NuFw - an open source product.
&lt;br&gt;&lt;br&gt;Any recommendations of other products you know of will be appreciated.
&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;Johann
&lt;br&gt;-- 
&lt;br&gt;Johann Spies &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Telefoon: 021-808 4036
&lt;br&gt;Informasietegnologie, Universiteit van Stellenbosch
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;quot;Children, obey your parents in the Lord: for this is 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; right.&amp;quot; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Ephesians 6:1 
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Recommendations-tp18119235p18119235.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18117988</id>
	<title>Re: Help to remove blocking of MS outlook through ISA 2004</title>
	<published>2008-06-23T14:20:09Z</published>
	<updated>2008-06-23T14:20:09Z</updated>
	<author>
		<name>Faris Mlaeb</name>
	</author>
	<content type="html">&lt;html&gt;&lt;head&gt;&lt;/head&gt;&lt;body&gt;&lt;div style=&quot;font-family:times new roman, new york, times, serif;font-size:12pt&quot;&gt;&lt;P&gt;HI&lt;/P&gt;
&lt;P&gt;This is normal for ISA and you can fix this by going to:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Open the ISA Server Console and expand the Configuration, and select General, and then Click on &quot;Define Firewall Client Settings&quot;, You will have a new Window for the &quot;Firewall Client Settings&quot;&lt;BR&gt;Click on the Application Tab and from the list select Outlook&lt;BR&gt;You will notice that its like this:&lt;BR&gt;Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;1&lt;BR&gt;change the value to be &lt;BR&gt;Outlook&amp;nbsp;&amp;nbsp;Disable&amp;nbsp;&amp;nbsp;0&lt;/P&gt;
&lt;P&gt;and on the Firewall client on the user PC&amp;nbsp; make sure that you click on Detect Now Or simply restart your Computer&lt;/P&gt;
&lt;P&gt;This work for me perfect&lt;/P&gt;
&lt;P&gt;Have a nice time&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that if the value is not present .. then&amp;nbsp; simply create it&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;BR&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV align=center&gt;&lt;B&gt;&lt;SPAN style=&quot;COLOR: #1f497d&quot;&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;FONT color=#0000bf&gt;Faris Mlaeb&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/DIV&gt;
&lt;DIV class=MsoNormal style=&quot;MARGIN: 0in 0in 0pt; TEXT-ALIGN: center&quot; align=center&gt;&lt;SPAN style=&quot;COLOR: #1f497d&quot;&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri color=#0000bf&gt;&lt;STRONG&gt;Technical Manager&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV align=center&gt;&lt;FONT face=Calibri&gt;&lt;FONT color=#0000bf size=3&gt;&lt;STRONG&gt;Network Administrator&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV style=&quot;FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york, times, serif&quot;&gt;&lt;BR&gt;&lt;BR&gt;
&lt;DIV style=&quot;FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york, times, serif&quot;&gt;----- Original Message ----&lt;BR&gt;From: Thor (Hammer of God) &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18117988&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;thor@...&lt;/a&gt;&amp;gt;&lt;BR&gt;To: Qaisar Naseem &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18117988&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;qaisarn@...&lt;/a&gt;&amp;gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18117988&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;BR&gt;Sent: Monday, June 23, 2008 5:33:33 PM&lt;BR&gt;Subject: RE: Help to remove blocking of MS outlook through ISA 2004&lt;BR&gt;&lt;BR&gt;


&lt;DIV class=Section1&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;What protocols are you using to connect to the server?&amp;nbsp; I'm assuming you are talking about an internal Outlook client connecting to an external server.&amp;nbsp; What kind of ISA client is the host?&amp;nbsp; Are you using SNAT or FWC?&amp;nbsp; &amp;nbsp;A little infoz, please.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;t&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;-----------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;Check out Tim Mullen's &quot;Microsoft Ninjitsu&quot; training at Blackhat Vegas 2008. &lt;BR&gt;There are also some other great NGS classes lead by world-class researchers and trainers available.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&lt;A href=&quot;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&quot; target=_blank rel=&quot;nofollow&quot;&gt;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri', 'sans-serif'&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style=&quot;BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: blue 1.5pt solid; PADDING-TOP: 0in; BORDER-BOTTOM: medium none&quot;&gt;
&lt;DIV&gt;
&lt;DIV style=&quot;BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 3pt; BORDER-BOTTOM: medium none&quot;&gt;
&lt;P class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma', 'sans-serif'&quot;&gt;From:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma', 'sans-serif'&quot;&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18117988&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18117988&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] &lt;B&gt;On Behalf Of &lt;/B&gt;Qaisar Naseem&lt;BR&gt;&lt;B&gt;Sent:&lt;/B&gt; Friday, June 20, 2008 9:02 AM&lt;BR&gt;&lt;B&gt;To:&lt;/B&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18117988&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;BR&gt;&lt;B&gt;Subject:&lt;/B&gt; Help to remove blocking of MS outlook through ISA 2004&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;Hi,&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P class=MsoNormal&gt;I am using Windows server 2003 network with ISA 2004 as proxy. I am having problem in passing MS outlook requests. Even I created a firewall rule to allow all outbound traffic to external, but unable to solve the problem. Outlook configuration is quite OK as when I by pass proxy, it works fine.&lt;BR&gt;&lt;BR&gt;-- &lt;BR&gt;Qaisar Naseem&lt;BR&gt;Network Admin&lt;BR&gt;Express News TV&lt;BR&gt;+923457263848 &lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/div&gt;&lt;br&gt;

      &lt;/body&gt;&lt;/html&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Help-to-remove-blocking-of-MS-outlook-through-ISA-2004-tp18069334p18117988.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18072064</id>
	<title>RE: Help to remove blocking of MS outlook through ISA 2004</title>
	<published>2008-06-23T07:33:33Z</published>
	<updated>2008-06-23T07:33:33Z</updated>
	<author>
		<name>Thor (Hammer of God)</name>
	</author>
	<content type="html">&lt;html&gt;

&lt;head&gt;
&lt;meta http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 12 (filtered medium)&quot;&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;What protocols are you using to connect to the server?&amp;nbsp; I'm
assuming you are talking about an internal Outlook client connecting to an
external server.&amp;nbsp; What kind of ISA client is the host?&amp;nbsp; Are you using
SNAT or FWC?&amp;nbsp; &amp;nbsp;A little infoz, please.&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;t&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;-----------&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Check out Tim Mullen's &amp;quot;Microsoft Ninjitsu&amp;quot; training
at Blackhat Vegas 2008. &lt;br&gt;
There are also some other great NGS classes lead by world-class researchers and
trainers available.&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;http://www.blackhat.com/html/bh-usa-08/train-bh-usa-08-tm-ms-bbe.html&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;div style='border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt'&gt;

&lt;div&gt;

&lt;div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;From:&lt;/span&gt;&lt;/b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18072064&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18072064&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] &lt;b&gt;On Behalf
Of &lt;/b&gt;Qaisar Naseem&lt;br&gt;
&lt;b&gt;Sent:&lt;/b&gt; Friday, June 20, 2008 9:02 AM&lt;br&gt;
&lt;b&gt;To:&lt;/b&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18072064&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&lt;br&gt;
&lt;b&gt;Subject:&lt;/b&gt; Help to remove blocking of MS outlook through ISA 2004&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&lt;/p&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;Hi,&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&lt;/p&gt;

&lt;/div&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;I am using Windows server 2003 network with ISA 2004 as
proxy. I am having problem in passing MS outlook requests. Even I created a
firewall rule to allow all outbound traffic to external, but unable to solve
the problem. Outlook configuration is quite OK as when I by pass proxy, it
works fine.&lt;br&gt;
&lt;br&gt;
-- &lt;br&gt;
Qaisar Naseem&lt;br&gt;
Network Admin&lt;br&gt;
Express News TV&lt;br&gt;
+923457263848 &lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Help-to-remove-blocking-of-MS-outlook-through-ISA-2004-tp18069334p18072064.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18069334</id>
	<title>Help to remove blocking of MS outlook through ISA 2004</title>
	<published>2008-06-20T09:01:50Z</published>
	<updated>2008-06-20T09:01:50Z</updated>
	<author>
		<name>Qaisar Naseem</name>
	</author>
	<content type="html">&lt;div&gt;Hi,&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;I am using Windows server 2003 network with ISA 2004 as proxy. I am having problem in passing MS outlook requests. Even I created a firewall rule to allow all outbound traffic to external, but unable to solve the problem. Outlook configuration is quite OK as when I by pass proxy, it works fine.&lt;br clear=&quot;all&quot;&gt;
&lt;br&gt;-- &lt;br&gt;Qaisar Naseem&lt;br&gt;Network Admin&lt;br&gt;Express News TV&lt;br&gt;+923457263848 &lt;/div&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Help-to-remove-blocking-of-MS-outlook-through-ISA-2004-tp18069334p18069334.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17809946</id>
	<title>Re: Can phase 2 proxy-id be modified on SonicWall VPN's?</title>
	<published>2008-06-12T13:08:29Z</published>
	<updated>2008-06-12T13:08:29Z</updated>
	<author>
		<name>adamamesh</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;I've run into, believe it or not, the exact same issue, to the letter. &amp;nbsp;I was wondering if you had any luck, since this was so long ago.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-Can-phase-2-proxy-id-be-modified-on-SonicWall-VPN%27s--tp17809946p17809946.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17803070</id>
	<title>RE: virtual firewalls -- compliance</title>
	<published>2008-06-11T20:29:13Z</published>
	<updated>2008-06-11T20:29:13Z</updated>
	<author>
		<name>Craig Wright-2</name>
	</author>
	<content type="html">&lt;br&gt;See &amp;quot;Santa Claus, Unicorns, and PCI Compliant Products&amp;quot;
&lt;br&gt;&lt;br&gt;There's no such thing as a &amp;quot;PCI Compliant&amp;quot; product (excepting PEDs).
&lt;br&gt;&lt;br&gt;Note: There is a &amp;quot;Listing of PCI Security Standards Council Approved PIN Entry Devices&amp;quot; at: &lt;a href=&quot;https://www.pcisecuritystandards.org/pin/pedapprovallist.html_&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.pcisecuritystandards.org/pin/pedapprovallist.html_&lt;/a&gt;. The PED's are the only products to have PCI SSC approval.
&lt;br&gt;&lt;br&gt;Strange... A google search on &amp;quot; site:www.icsalabs.com PCI Stonesoft&amp;quot; gets nothing.
&lt;br&gt;&lt;br&gt;Stonesoft is ICSA labs certified - it is not a PCI compliant product as there is no such thing. ICSA is testing Web Application Firewalls for PCI-DSS standards compatibility - this is not the same thing.
&lt;br&gt;&lt;a href=&quot;http://www.icsalabs.com/icsa/topic.php?tid=8913$2e2258c8-68384de7$d1d5-02872c54&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.icsalabs.com/icsa/topic.php?tid=8913$2e2258c8-68384de7$d1d5-02872c54&lt;/a&gt;&lt;br&gt;&lt;br&gt;Notice that Stonesoft is not a WAF.
&lt;br&gt;&lt;br&gt;I do not even know of a PCI &amp;quot;Product capability assurance report&amp;quot; for stonesoft. If there is it is really new - that is after this email.
&lt;br&gt;&lt;br&gt;Next, Stonbesoft is ONLY ICSA certified in NAT mode and NOT bridge mode. If you read the report you will see: &amp;quot;The StoneGate was a router-based product that packet filtered network services inbound and outbound. While the Stonegate does supports an IP only bridging mode, the product was configured in NAT mode for inbound and outbound services &amp;quot;
&lt;br&gt;&lt;br&gt;On top of this, there are issues that have to be addressed when installing it to make it pass a PCI audit. In the ICSA test there where a number of issues that Stonesoft needed to fix:
&lt;br&gt;&amp;quot;The following logging criteria violations were found by the Network Security Lab team during testing and addressed by Stonesoft Inc:
&lt;br&gt;. The product did not log certain ICMP messages sent directly to or through it.
&lt;br&gt;. The product did not log certain raw IP Protocols directed to or through it.
&lt;br&gt;. The product allowed TCP packets inbound and outbound without a properly established TCP
&lt;br&gt;. session for RSSP services.
&lt;br&gt;. The product was susceptible to a variety of trivial Denial-of-Service attacks.
&lt;br&gt;. The product incorrectly terminated TCP connections when sent spoofed/invalid RST packets.&amp;quot;
&lt;br&gt;&lt;br&gt;So it is NOT PCI compliant. It may be setup within a control framework that could be PCI compliant, this is NOT the same thing.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;Craig Wright GSE
&lt;br&gt;&lt;br&gt;&lt;br&gt;Craig Wright
&lt;br&gt;Manager, Risk Advisory Services
&lt;br&gt;&lt;br&gt;Direct : +61 2 9286 5497
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17803070&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Craig.Wright@...&lt;/a&gt;
&lt;br&gt;+61 417 683 914
&lt;br&gt;&lt;br&gt;BDO Kendalls (NSW-VIC) Pty. Ltd.
&lt;br&gt;Level 19, 2 Market Street Sydney NSW 2000
&lt;br&gt;GPO BOX 2551 Sydney NSW 2001
&lt;br&gt;Fax +61 2 9993 9497
&lt;br&gt;&lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&lt;br&gt;&lt;br&gt;The information in this email and any attachments is confidential. If you are not the named addressee you must not read, print, copy, distribute, or use in any way this transmission or any information it contains. If you have received this message in error, please notify the sender by return email, destroy all copies and delete it from your system.
&lt;br&gt;&lt;br&gt;Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls. You may not rely on this message as advice unless subsequently confirmed by fax or letter signed by a Partner or Director of BDO Kendalls. It is your responsibility to scan this communication and any files attached for computer viruses and other defects. BDO Kendalls does not accept liability for any loss or damage however caused which may result from this communication or any files attached. A full version of the BDO Kendalls disclaimer, and our Privacy statement, can be found on the BDO Kendalls website at &lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&amp;nbsp;or by emailing mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17803070&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;administrator@...&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;BDO Kendalls is a national association of separate partnerships and entities. Liability limited by a scheme approved under Professional Standards Legislation.
&lt;br&gt;-----Original Message-----
&lt;br&gt;&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17803070&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17803070&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of styler
&lt;br&gt;Sent: Wednesday, 11 June 2008 10:40 PM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17803070&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;
&lt;br&gt;Subject: Re: virtual firewalls -- compliance
&lt;br&gt;&lt;br&gt;&lt;br&gt;All,
&lt;br&gt;&lt;br&gt;Just wanted to throw this in - we're using a virtual firewall from Stonesoft
&lt;br&gt;(see link) in our environment:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.stonesoft.com/en/products_and_solutions/solutions/technology_solutions/virtual_environments/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.stonesoft.com/en/products_and_solutions/solutions/technology_solutions/virtual_environments/&lt;/a&gt;&lt;br&gt;&lt;br&gt;It's been certified by ICSA labs as PCI compliant and multiple virtual
&lt;br&gt;firewalls can be centrally managed. &amp;nbsp;I've also heard that they're IPS
&lt;br&gt;product will certified for use soon.
&lt;br&gt;&lt;br&gt;Sam
&lt;br&gt;Firewall Administrator
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Terry-7 wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hello all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I am throwing around the idea of using linux firewalls in vmware for
&lt;br&gt;&amp;gt; customer environments. &amp;nbsp;The customers may or may not have
&lt;br&gt;&amp;gt; HIPAA/PCI/sOX/etc requirements. &amp;nbsp;This is in the planning stages. &amp;nbsp;Any
&lt;br&gt;&amp;gt; of you have experience heading down this route? &amp;nbsp;PCIDSS doesn't
&lt;br&gt;&amp;gt; explicitly state problems with virtual firewalls, it seems to focus on
&lt;br&gt;&amp;gt; the logic of the rules.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;--
&lt;br&gt;View this message in context: &lt;a href=&quot;http://www.nabble.com/virtual-firewalls----compliance-tp17157866p17776593.html&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/virtual-firewalls----compliance-tp17157866p17776593.html&lt;/a&gt;&lt;br&gt;Sent from the Firewall (securityfocus.com) mailing list archive at Nabble.com.
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17803070.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17776593</id>
	<title>Re: virtual firewalls -- compliance</title>
	<published>2008-06-11T05:40:11Z</published>
	<updated>2008-06-11T05:40:11Z</updated>
	<author>
		<name>styler</name>
	</author>
	<content type="html">All,
&lt;br&gt;&lt;br&gt;Just wanted to throw this in - we're using a virtual firewall from Stonesoft (see link) in our environment:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.stonesoft.com/en/products_and_solutions/solutions/technology_solutions/virtual_environments/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.stonesoft.com/en/products_and_solutions/solutions/technology_solutions/virtual_environments/&lt;/a&gt;&lt;br&gt;&lt;br&gt;It's been certified by ICSA labs as PCI compliant and multiple virtual firewalls can be centrally managed. &amp;nbsp;I've also heard that they're IPS product will certified for use soon.
&lt;br&gt;&lt;br&gt;Sam
&lt;br&gt;Firewall Administrator
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;Terry-7 wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Hello all,
&lt;br&gt;&lt;br&gt;I am throwing around the idea of using linux firewalls in vmware for
&lt;br&gt;customer environments. &amp;nbsp;The customers may or may not have
&lt;br&gt;HIPAA/PCI/sOX/etc requirements. &amp;nbsp;This is in the planning stages. &amp;nbsp;Any
&lt;br&gt;of you have experience heading down this route? &amp;nbsp;PCIDSS doesn't
&lt;br&gt;explicitly state problems with virtual firewalls, it seems to focus on
&lt;br&gt;the logic of the rules.
&lt;br&gt;&lt;br&gt;Thanks!
&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17776593.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17781155</id>
	<title>Which gateway solution to choose?</title>
	<published>2008-06-10T16:40:32Z</published>
	<updated>2008-06-10T16:40:32Z</updated>
	<author>
		<name>Mark SInister</name>
	</author>
	<content type="html">Hi All,&lt;br&gt;&lt;br&gt;We are in the process of reviewing our entire Security Gateway (3 Gateway Point)&lt;br&gt;&lt;br&gt;We are trying to replace MailMarshal and N2H2 with a hardware base solution&lt;br&gt;&lt;br&gt;Issues on&lt;br&gt;&lt;br&gt;Primary&lt;br&gt;&lt;br&gt;Email Filtering (Anti-Virus, Spam, Reporting etc)&lt;br&gt;
Web Filtering&lt;br&gt;Hardware Base&lt;br&gt;&lt;br&gt;Secondary&lt;br&gt;&lt;br&gt;A Firewall, IDS, Proxy, NAC or a VPN included would be a bonus.&lt;br&gt;&lt;br&gt;Below are the two products that we are reviewing at the moment&lt;br&gt;&lt;br&gt;1. Sophos Enterprise Security&amp;nbsp; &amp;amp; Control&lt;br&gt;
&lt;br&gt;Sophos PureMessage for Notes/Domino ES1000 (Hardware)&lt;br&gt;Sophos Web Application WS1000 (Hardware)&lt;br&gt;Sophos Integrated Network Access Control (NAC)&lt;br&gt;Sophos Enterprise Anti-virus&amp;nbsp; &amp;amp;&amp;nbsp; Client Firewall ( We are already using this product)&lt;br&gt;
&lt;br&gt;2. Smoothwall (Hardware)&lt;br&gt;&lt;br&gt;Firewall&lt;br&gt;Web content Filtering&lt;br&gt;Email Security&lt;br&gt;VPN Gateway&lt;br&gt;Intrusion Detection (IDS)&lt;br&gt;Internal Firewall&lt;br&gt;Load Balancer&lt;br&gt;&amp;nbsp;&lt;br&gt;Please keep in mind with budget cost since the Sophos product is great, but it will cost us over $40K, where compare with SmoothWall $15K est&lt;br&gt;
&lt;br&gt;I would like to know from people&amp;#39;s opinion on the products above, such as is advantages, disadvantages they&amp;#39;ve come across or any other products they can recommend as well.&lt;br&gt;&lt;br&gt;Cheers&lt;br&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Which-gateway-solution-to-choose--tp17781155p17781155.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17371696</id>
	<title>Re: virtual firewalls -- compliance</title>
	<published>2008-05-20T15:19:35Z</published>
	<updated>2008-05-20T15:19:35Z</updated>
	<author>
		<name>David M. Zendzian</name>
	</author>
	<content type="html">One more note on this topic.
&lt;br&gt;&lt;br&gt;In doing some searches I found the following PCI discussion regarding 
&lt;br&gt;2.2.1 (single use of machine):
&lt;br&gt;&lt;a href=&quot;http://forum.aegenis.com/archive/index.php?t-61.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://forum.aegenis.com/archive/index.php?t-61.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;I know this won't settle the argument :) but hopefully it will continue 
&lt;br&gt;the discussion (offline?) where people can determine what is needed to 
&lt;br&gt;accept virtualization for both firewalls and production servers in 
&lt;br&gt;compliant environments.
&lt;br&gt;&lt;br&gt;David
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17371696.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17371724</id>
	<title>firewall configuration framework</title>
	<published>2008-05-20T13:44:01Z</published>
	<updated>2008-05-20T13:44:01Z</updated>
	<author>
		<name>Gustavo Rios-2</name>
	</author>
	<content type="html">Dear friends,
&lt;br&gt;&lt;br&gt;in order to reduce some time settings network firewalls i wrote a
&lt;br&gt;framework i would like your comments on. Of course, i did not to pass
&lt;br&gt;the ideia of being a lazy professional, but there are settings all the
&lt;br&gt;same everywhere. For instance, rule to prevent packets incoming with a
&lt;br&gt;source address different from that &amp;nbsp;of the interface network (IP
&lt;br&gt;spoofing attack).
&lt;br&gt;&lt;br&gt;I am using openbsd, so for filter rules, the last match wins, for
&lt;br&gt;packet rewrite (nat/rdr) the first match winds. Do you have any
&lt;br&gt;suggestions on what i could improve. I am working on OpenBSD 4.3 and
&lt;br&gt;here you got my /etc/pf.conf. Any another rule is loaded by usage of a
&lt;br&gt;loaded externally, from a file.
&lt;br&gt;I am providing /etc/pf.conf file and two other to be loaded with a
&lt;br&gt;load firewall directive, they are: /etc/pf/feif and /etc/pf/fiif_0.
&lt;br&gt;&lt;br&gt;Any comments and suggestions are highly appreciated.
&lt;br&gt;&lt;br&gt;# /etc/pf.conf
&lt;br&gt;#
&lt;br&gt;# Macros
&lt;br&gt;#
&lt;br&gt;########
&lt;br&gt;&lt;br&gt;EIF = &amp;quot;&amp;quot;
&lt;br&gt;IIF_0 = &amp;quot;&amp;quot;
&lt;br&gt;IIF_1 = &amp;quot;&amp;quot;
&lt;br&gt;IIF_2 = &amp;quot;&amp;quot;
&lt;br&gt;&lt;br&gt;########
&lt;br&gt;#
&lt;br&gt;# Tables
&lt;br&gt;#
&lt;br&gt;########
&lt;br&gt;&lt;br&gt;table &amp;lt;rfc1918&amp;gt; persist const { 10/8 172.16/12 192.168/16 }
&lt;br&gt;table &amp;lt;net&amp;gt; persist { $IIF_0:network $IIF_1:network $IIF_2:network }
&lt;br&gt;table &amp;lt;badhosts&amp;gt; persist
&lt;br&gt;&lt;br&gt;#########
&lt;br&gt;#
&lt;br&gt;# Options
&lt;br&gt;#
&lt;br&gt;#########
&lt;br&gt;&lt;br&gt;set loginterface $EIF
&lt;br&gt;set skip on lo0
&lt;br&gt;set debug misc
&lt;br&gt;set state-policy if-bound
&lt;br&gt;set block-policy return
&lt;br&gt;&lt;br&gt;#######################
&lt;br&gt;#
&lt;br&gt;# Traffic Normalization
&lt;br&gt;#
&lt;br&gt;#######################
&lt;br&gt;&lt;br&gt;scrub out on $EIF max-mss 1452
&lt;br&gt;&lt;br&gt;##########
&lt;br&gt;#
&lt;br&gt;# Queueing
&lt;br&gt;#
&lt;br&gt;##########
&lt;br&gt;&lt;br&gt;#############
&lt;br&gt;#
&lt;br&gt;# Translation (first match wins). Only appliable if $EIF is a public address.
&lt;br&gt;#
&lt;br&gt;#############
&lt;br&gt;&lt;br&gt;nat-anchor &amp;quot;ftp-proxy/*&amp;quot;
&lt;br&gt;&lt;br&gt;nat-anchor neif on $EIF
&lt;br&gt;nat-anchor niif_0 on $IIF_0
&lt;br&gt;nat-anchor niif_1 on $IIF_1
&lt;br&gt;nat-anchor niif_2 on $IIF_2
&lt;br&gt;&lt;br&gt;rdr-anchor &amp;quot;ftp-proxy/*&amp;quot;
&lt;br&gt;&lt;br&gt;rdr-anchor reif on $EIF
&lt;br&gt;rdr-anchor riif_0 on $IIF_0
&lt;br&gt;&lt;br&gt;rdr-anchor riif_1 on $IIF_1
&lt;br&gt;rdr-anchor riif_2 on $IIF_2
&lt;br&gt;&lt;br&gt;##################
&lt;br&gt;#
&lt;br&gt;# Packet Filtering (last match wins)
&lt;br&gt;#
&lt;br&gt;##################
&lt;br&gt;&lt;br&gt;# let's block everything by default
&lt;br&gt;block log all
&lt;br&gt;&lt;br&gt;anchor &amp;quot;ftp-proxy/*&amp;quot;
&lt;br&gt;&lt;br&gt;anchor feif on $EIF
&lt;br&gt;anchor fiif_0 on $IIF_0
&lt;br&gt;anchor fiif_1 on $IIF_1
&lt;br&gt;anchor fiif_2 on $IIF_2
&lt;br&gt;&lt;br&gt;# default on loopback interface
&lt;br&gt;block in log on !lo0 from (lo0:network)
&lt;br&gt;&lt;br&gt;# default on each internal interface (private address)
&lt;br&gt;block in log on $IIF_0 from ($IIF_0:broadcast)
&lt;br&gt;block in log on !$IIF_0 from ($IIF_0:network)
&lt;br&gt;block in log on !$IIF_0 to ($IIF_0:broadcast)
&lt;br&gt;block in log on $IIF_0 to 127/8 ! tagged RDR_0
&lt;br&gt;&lt;br&gt;block in log on $IIF_1 from ($IIF_1:broadcast)
&lt;br&gt;block in log on !$IIF_1 from ($IIF_1:network)
&lt;br&gt;block in log on !$IIF_1 to ($IIF_1:broadcast)
&lt;br&gt;block in log on $IIF_1 to 127/8 ! tagged RDR_1
&lt;br&gt;&lt;br&gt;block in log on $IIF_2 from ($IIF_2:broadcast)
&lt;br&gt;block in log on !$IIF_2 from ($IIF_2:network)
&lt;br&gt;block in log on !$IIF_2 to ($IIF_2:broadcast)
&lt;br&gt;block in log on $IIF_2 to 127/8 ! tagged RDR_2
&lt;br&gt;&lt;br&gt;# default on external interface (public address)
&lt;br&gt;block in log on !$EIF from ($EIF)
&lt;br&gt;block in log on $EIF to 127/8 ! tagged RDR
&lt;br&gt;&lt;br&gt;# default general rules
&lt;br&gt;block in log from 255.255.255.255
&lt;br&gt;block in log to 0/8
&lt;br&gt;&lt;br&gt;# /etc/pf/feif
&lt;br&gt;#
&lt;br&gt;# Macros
&lt;br&gt;#
&lt;br&gt;########
&lt;br&gt;&lt;br&gt;EIF = &amp;quot;&amp;quot;
&lt;br&gt;&lt;br&gt;# this host itself
&lt;br&gt;pass in log to ($EIF) ! tagged RDR
&lt;br&gt;pass out log from ($EIF) ! tagged NAT
&lt;br&gt;&lt;br&gt;pass out log proto tcp from ($EIF) to any port { www https } tagged NAT
&lt;br&gt;&lt;br&gt;# /etc/pf/fiif_0
&lt;br&gt;#
&lt;br&gt;# Macros
&lt;br&gt;#
&lt;br&gt;########
&lt;br&gt;&lt;br&gt;IIF_0 = &amp;quot;&amp;quot;
&lt;br&gt;&lt;br&gt;# this host itself
&lt;br&gt;pass in log from ($IIF_0:network) to { ($IIF_0) ($IIF_0:broadcast) }
&lt;br&gt;pass out log from ($IIF_0) to ($IIF_0:network)
&lt;br&gt;&lt;br&gt;pass in log proto tcp from ($IIF_0:network) to !($IIF_0) port { www https }
&lt;br&gt;pass in log proto tcp from ($IIF_0:network) to (lo0:0) port 8021 tagged RDR_0
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/firewall-configuration-framework-tp17371724p17371724.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17347603</id>
	<title>Re: virtual firewalls -- compliance</title>
	<published>2008-05-20T06:23:54Z</published>
	<updated>2008-05-20T06:23:54Z</updated>
	<author>
		<name>David M. Zendzian</name>
	</author>
	<content type="html">I would disagree with the premise that virtual servers conflict with the 
&lt;br&gt;single function requirement because the function of a virtual server is 
&lt;br&gt;to provide virtualized servers and as such is a logical equivalent of 
&lt;br&gt;mainframe logical partitions (a less mature equivalent, but similar model).
&lt;br&gt;&lt;br&gt;Yes i will agree that current virtualization is nowhere as mature as 
&lt;br&gt;mainframe logical partitions. However giving the need and path the 
&lt;br&gt;technology is going those controls will advance to such a point that 
&lt;br&gt;virtualization will have similar acceptance as logical partitions 
&lt;br&gt;currently do.
&lt;br&gt;&lt;br&gt;I would also point out that you can get mainframe based virtualization 
&lt;br&gt;from IBM and that shared hosting and mainframe systems are able to be 
&lt;br&gt;meet the intent of PCI and other compliant requirements.
&lt;br&gt;&lt;br&gt;So i basically see the host virtualization server as having one primary 
&lt;br&gt;service which is to run controlled virtualized servers, each of those 
&lt;br&gt;virtual servers would then have its own host requirements.
&lt;br&gt;&lt;br&gt;For it to meet the various compliance requirements the host server will 
&lt;br&gt;need to have extensive controls to mitigate the risks inherent to 
&lt;br&gt;virtualization, but i believe that the intent of the control 
&lt;br&gt;requirements can be met with existing tools and technologies.
&lt;br&gt;&lt;br&gt;As for the exploits out there...there will always be exploits and the 
&lt;br&gt;cat-n-mouse game between hackers and IT personnel but there is also the 
&lt;br&gt;balance between security and cost. I know many readers of this list 
&lt;br&gt;subscribe to a zero tollerance policy, but not every ecommerce site is 
&lt;br&gt;going to spend 2000+ per month plus 50k in hardware to sell online.
&lt;br&gt;&lt;br&gt;In fact if we follow the model of single use and prior exploits people 
&lt;br&gt;would have to use dedicated equipment for: Firewalls, Load Balancers, 
&lt;br&gt;Switches, Routers, Web Servers, Database Servers, DNS servers, etc... 
&lt;br&gt;Just about everything in the past has had exploits, but does that mean 
&lt;br&gt;we can't use them in a compliant environment? Or does it mean that we 
&lt;br&gt;are unable to use them in a hosted environment? Does that mean that we &amp;nbsp;
&lt;br&gt;have to get rid of all mainframes if they are providing virtual 
&lt;br&gt;configurations or not the same function on all logical partitions? How 
&lt;br&gt;about databases? With the use of stored procedures databases are more 
&lt;br&gt;than storage repositories, they are actually part of the applications 
&lt;br&gt;that use them. If we have multiple applications, all doing extensive 
&lt;br&gt;stored procedures and application hooks, does that mean we can't use 
&lt;br&gt;them in a compliant environment because it is not single function or 
&lt;br&gt;that an exploit in one application could effect the others?
&lt;br&gt;&lt;br&gt;So what is the solution? Totally secure the environment to a point where 
&lt;br&gt;operations and security cost more than the environment brings in, or 
&lt;br&gt;find a combination of best practices that allows a business to hopefully 
&lt;br&gt;make more than it costs to operate.
&lt;br&gt;&lt;br&gt;&amp;nbsp;From an assessors viewpoint, i do not think that anyone can say 
&lt;br&gt;virtualization is plug-n-play accepted it will come down to 
&lt;br&gt;configuration standards, expertise of the team, tools and techniques in 
&lt;br&gt;use and how the assessment of these controls goes (the same controls 
&lt;br&gt;could be in use in multiple companies, but the level of expertise of the 
&lt;br&gt;staff and the deployment and use of tools can vary widely).
&lt;br&gt;&lt;br&gt;Like it was said before, it will come to a judges ruling if there was 
&lt;br&gt;negligence or incompetence involved in a compromise. Just saying broadly 
&lt;br&gt;that there are risks and possible exploits for a system do not make 
&lt;br&gt;someone negligent in their duties by deploying such a system.
&lt;br&gt;&lt;br&gt;So how about instead of just dissing the idea and looking for why it 
&lt;br&gt;can't be done, we instead have a discussion on how did these other 
&lt;br&gt;technologies become accepted for hosting use and what will it take to 
&lt;br&gt;meet the intent of the compliance requirements.
&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;David M. Zendzian
&lt;br&gt;&lt;br&gt;PS And yes I have a vested interest in this as I am a Managing Partner 
&lt;br&gt;with ZZ Servers, a Business Hosting provider that provides not only 
&lt;br&gt;virtual firewalls but also virtual servers that are commonly used in 
&lt;br&gt;combination with collocated and leased services. &amp;nbsp;I also am QSA 
&lt;br&gt;certified and would rather spend my time working with partners on how to 
&lt;br&gt;best secure and understand their environment than tell them that they 
&lt;br&gt;&amp;quot;can't do that&amp;quot; and to just close up shop or go out &amp; spend 100K for a 
&lt;br&gt;&amp;quot;Real&amp;quot; solution :-D
&lt;br&gt;&lt;br&gt;Craig Wright wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; From a compliance perspective, separate devices is just that. It does not matter if virtual hosts do or do not work, the are the same device and thus are a single device with multiple purposes.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Whether you can or if it will work is irrelevant. This is something where a breach is decided in court. As usch all that matters is how a judge will read this.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Craig
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Craig Wright
&lt;br&gt;&amp;gt; Manager, Risk Advisory Services
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Direct : +61 2 9286 5497
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17347603&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Craig.Wright@...&lt;/a&gt;
&lt;br&gt;&amp;gt; +61 417 683 914
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; BDO Kendalls (NSW-VIC) Pty. Ltd.
&lt;br&gt;&amp;gt; Level 19, 2 Market Street Sydney NSW 2000
&lt;br&gt;&amp;gt; GPO BOX 2551 Sydney NSW 2001
&lt;br&gt;&amp;gt; Fax +61 2 9993 9497
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The information in this email and any attachments is confidential. If you are not the named addressee you must not read, print, copy, distribute, or use in any way this transmission or any information it contains. If you have received this message in error, please notify the sender by return email, destroy all copies and delete it from your system.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls. You may not rely on this message as advice unless subsequently confirmed by fax or letter signed by a Partner or Director of BDO Kendalls. It is your responsibility to scan this communication and any files attached for computer viruses and other defects. BDO Kendalls does not accept liability for any loss or damage however caused which may result from this communication or any files attached. A full version of the BDO Kendalls disclaimer, and our Privacy statement, can be found on the BDO Kendalls website at &lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&amp;nbsp;or by emailing mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17347603&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;administrator@...&lt;/a&gt;.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; BDO Kendalls is a national association of separate partnerships and entities. Liability limited by a scheme approved under Professional Standards Legislation.
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; From: Dan Lynch [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17347603&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;DLynch@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; Sent: Tuesday, 13 May 2008 2:53 AM
&lt;br&gt;&amp;gt; To: Craig Wright; Terry; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17347603&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: RE: virtual firewalls -- compliance
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I find this discussion interesting from a slightly different angle than
&lt;br&gt;&amp;gt; the perspective of PCI or other standards compliance.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I tend to agree with Craig's view that there is inadequate segregation
&lt;br&gt;&amp;gt; between guests running on different VMs of the same host, whether they
&lt;br&gt;&amp;gt; be application servers or virtualized security appliances. There are
&lt;br&gt;&amp;gt; multiple demonstrated guest breakout techniques for nearly all
&lt;br&gt;&amp;gt; virtualization technologies.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Still, let me directly quote the supervisor of our Windows admin team:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt; &amp;quot;Department of Homeland Security and NSA have
&lt;br&gt;&amp;gt;&amp;gt; certified the VMware virtual switch and OS as being
&lt;br&gt;&amp;gt;&amp;gt; equivalent to physical separation.&amp;quot;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; He's referring to ESX3 -- the platform on which his group hopes to run
&lt;br&gt;&amp;gt; multiple virtualized DMZ-based public Windows Server 2003 web servers,
&lt;br&gt;&amp;gt; with the host OS directly connected to a private internal network. This
&lt;br&gt;&amp;gt; is a strategy on which I requested comments from the list only a few
&lt;br&gt;&amp;gt; weeks ago.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thoughts?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Dan Lynch, CISSP
&lt;br&gt;&amp;gt; Information Technology Analyst
&lt;br&gt;&amp;gt; County of Placer
&lt;br&gt;&amp;gt; Auburn, CA
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17347603&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17347603&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of Craig Wright
&lt;br&gt;&amp;gt;&amp;gt; Sent: Friday, May 09, 2008 4:51 PM
&lt;br&gt;&amp;gt;&amp;gt; To: Terry; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17347603&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; Subject: RE: virtual firewalls -- compliance
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; PCI-DSS v1.1 states at 1.4
&lt;br&gt;&amp;gt;&amp;gt; &amp;quot;Prohibit direct public access between external networks and
&lt;br&gt;&amp;gt;&amp;gt; any system component that stores cardholder data&amp;quot;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; A virtual system is a direct access. You have trusted and
&lt;br&gt;&amp;gt;&amp;gt; untrusted on the same component. HIPAA is worse. You have a
&lt;br&gt;&amp;gt;&amp;gt; number of hosts at different levels shared. This is a law
&lt;br&gt;&amp;gt;&amp;gt; suit waiting to occur.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Other standards are the same. All I have to say is this is a
&lt;br&gt;&amp;gt;&amp;gt; BAD idea. BAD!
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt;&amp;gt; Craig Wright (GSE-Compliance)
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Craig Wright
&lt;br&gt;&amp;gt;&amp;gt; Manager, Risk Advisory Services
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Direct : +61 2 9286 5497
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17347603&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Craig.Wright@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; +61 417 683 914
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; BDO Kendalls (NSW-VIC) Pty. Ltd.
&lt;br&gt;&amp;gt;&amp;gt; Level 19, 2 Market Street Sydney NSW 2000 GPO BOX 2551 Sydney
&lt;br&gt;&amp;gt;&amp;gt; NSW 2001 Fax +61 2 9993 9497 &lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; The information in this email and any attachments is
&lt;br&gt;&amp;gt;&amp;gt; confidential. If you are not the named addressee you must not
&lt;br&gt;&amp;gt;&amp;gt; read, print, copy, distribute, or use in any way this
&lt;br&gt;&amp;gt;&amp;gt; transmission or any information it contains. If you have
&lt;br&gt;&amp;gt;&amp;gt; received this message in error, please notify the sender by
&lt;br&gt;&amp;gt;&amp;gt; return email, destroy all copies and delete it from your system.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Any views expressed in this message are those of the
&lt;br&gt;&amp;gt;&amp;gt; individual sender and not necessarily endorsed by BDO
&lt;br&gt;&amp;gt;&amp;gt; Kendalls. You may not rely on this message as advice unless
&lt;br&gt;&amp;gt;&amp;gt; subsequently confirmed by fax or letter signed by a Partner
&lt;br&gt;&amp;gt;&amp;gt; or Director of BDO Kendalls. It is your responsibility to
&lt;br&gt;&amp;gt;&amp;gt; scan this communication and any files attached for computer
&lt;br&gt;&amp;gt;&amp;gt; viruses and other defects. BDO Kendalls does not accept
&lt;br&gt;&amp;gt;&amp;gt; liability for any loss or damage however caused which may
&lt;br&gt;&amp;gt;&amp;gt; result from this communication or any files attached. A full
&lt;br&gt;&amp;gt;&amp;gt; version of the BDO Kendalls disclaimer, and our Privacy
&lt;br&gt;&amp;gt;&amp;gt; statement, can be found on the BDO Kendalls website at
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&amp;nbsp;or by emailing mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17347603&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;administrator@...&lt;/a&gt;.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; BDO Kendalls is a national association of separate
&lt;br&gt;&amp;gt;&amp;gt; partnerships and entities. Liability limited by a scheme
&lt;br&gt;&amp;gt;&amp;gt; approved under Professional Standards Legislation.
&lt;br&gt;&amp;gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17347603&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17347603&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of Terry
&lt;br&gt;&amp;gt;&amp;gt; Sent: Friday, 9 May 2008 5:37 AM
&lt;br&gt;&amp;gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17347603&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; Subject: virtual firewalls -- compliance
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Hello all,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I am throwing around the idea of using linux firewalls in
&lt;br&gt;&amp;gt;&amp;gt; vmware for customer environments. &amp;nbsp;The customers may or may
&lt;br&gt;&amp;gt;&amp;gt; not have HIPAA/PCI/sOX/etc requirements. &amp;nbsp;This is in the
&lt;br&gt;&amp;gt;&amp;gt; planning stages. &amp;nbsp;Any of you have experience heading down
&lt;br&gt;&amp;gt;&amp;gt; this route? &amp;nbsp;PCIDSS doesn't explicitly state problems with
&lt;br&gt;&amp;gt;&amp;gt; virtual firewalls, it seems to focus on the logic of the rules.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17347603.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17347036</id>
	<title>Re: Cisco 501 Pix</title>
	<published>2008-05-19T15:19:50Z</published>
	<updated>2008-05-19T15:19:50Z</updated>
	<author>
		<name>kcs_135</name>
	</author>
	<content type="html">I have a similar setup except my setup looks like this:
&lt;br&gt;cable modem --&amp;gt; pix --&amp;gt; wrt54gs. &amp;nbsp;
&lt;br&gt;&lt;br&gt;My setup works very nicely. &amp;nbsp;I had to do some routing because I have different subnets. &amp;nbsp;You may need to put some routes on your Linksys (they don't route very well). &amp;nbsp;It may not be a bad idea to switch them around (put the Pix behind the cable modem and put the Linksys hehind the Pix). &amp;nbsp;Besides being the better first line of defense, the Pix will give you more control over your NATing or PATing and routing.
&lt;br&gt;&lt;br&gt;If everything works as it should, you'll see the right kind of traffic and be protected by 2 firewalls.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-Cisco-501-Pix-tp17347036p17347036.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17218101</id>
	<title>Re: virtual firewalls -- compliance</title>
	<published>2008-05-12T22:25:41Z</published>
	<updated>2008-05-12T22:25:41Z</updated>
	<author>
		<name>Chris Brenton</name>
	</author>
	<content type="html">&lt;br&gt;On Thu, May 8, 2008 at 3:37 PM, Terry &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218101&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;td3201@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Hello all,
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; I am throwing around the idea of using linux firewalls in
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; vmware for customer environments. &amp;nbsp;The customers may or may
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; not have
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; HIPAA/PCI/sOX/etc requirements. &amp;nbsp;This is in the planning
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; stages. &amp;nbsp;Any of you have experience heading down this route?
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; PCIDSS doesn't explicitly state problems with virtual
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; firewalls, it seems to focus on the logic of the rules.
&lt;br&gt;&lt;br&gt;&amp;lt;soap box&amp;gt;
&lt;br&gt;Personally, I hate using specs to try and define the level of security.
&lt;br&gt;They tend to reflect the lowest common denominator and motivate
&lt;br&gt;organizations to &amp;quot;audit well&amp;quot; rather than perform a true risk analysis
&lt;br&gt;and deploy a security solution which matches that business need.
&lt;br&gt;&amp;lt;/soap box&amp;gt;
&lt;br&gt;&lt;br&gt;The above specs are general enough that a pass/fail is going to depend
&lt;br&gt;on who is doing the analysis. For example as you mentioned above,
&lt;br&gt;section 1 of PCI does not define a required architecture for a firewall.
&lt;br&gt;So if you are running virtual it's going to depend on the auditor's
&lt;br&gt;interpretation of PCI as to whether you pass/fail. Of course these days
&lt;br&gt;auditing is a commodity. If you don't like the results you get from one
&lt;br&gt;auditor, simply bring in another. There is nothing in PCI that says you
&lt;br&gt;can't do that. ;-)
&lt;br&gt;&lt;br&gt;I think the bigger question here is &amp;quot;Is vitalizing a perimeter device a
&lt;br&gt;good idea for our environment?&amp;quot;. It certainly has some pluses in that it
&lt;br&gt;can reduce hardware costs and simplify management. I can see where
&lt;br&gt;vitalization would be attractive to anyone selling a managed security
&lt;br&gt;solution. This is why you are seeing companies like Fortinet, Juniper,
&lt;br&gt;Cisco, Checkpoint, etc. moving their higher end products into this
&lt;br&gt;arena. 
&lt;br&gt;&lt;br&gt;When we start asking ourselves &amp;quot;is it safe?&amp;quot; however I think the answer
&lt;br&gt;changes a bit. If I'm running two virtual firewalls for two different
&lt;br&gt;clients, I'm relying on bug free software to maintain that separation.
&lt;br&gt;Personally I have yet to see a single vendor prove they can write code
&lt;br&gt;well enough for that. 
&lt;br&gt;&lt;br&gt;In my travels I've seen clients get whacked because they have relied on
&lt;br&gt;VLANs to segregate their DMZ and internal network (which can be argued
&lt;br&gt;is a &amp;quot;virtual system&amp;quot; because its nothing more than multiple virtual
&lt;br&gt;switches running on a single piece of hardware). So now let's move that
&lt;br&gt;problematic technology to the underlying architecture of the firewall...
&lt;br&gt;and what could possibly go wrong. ;-)
&lt;br&gt;&lt;br&gt;So the bottom line is I would rely on a risk assessment rather than a
&lt;br&gt;specification to decide if it's a good idea. If from a business
&lt;br&gt;perspective the benefits outweigh the potential security risks, you are
&lt;br&gt;good to go. If you decide virtual systems introduces too much of a risk
&lt;br&gt;exposure, avoid the implementation.
&lt;br&gt;&lt;br&gt;HTH,
&lt;br&gt;Chris
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17218101.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17218165</id>
	<title>RE: virtual firewalls -- compliance</title>
	<published>2008-05-12T14:24:13Z</published>
	<updated>2008-05-12T14:24:13Z</updated>
	<author>
		<name>Craig Wright-2</name>
	</author>
	<content type="html">&lt;br&gt;From a compliance perspective, separate devices is just that. It does not matter if virtual hosts do or do not work, the are the same device and thus are a single device with multiple purposes.
&lt;br&gt;&lt;br&gt;Whether you can or if it will work is irrelevant. This is something where a breach is decided in court. As usch all that matters is how a judge will read this.
&lt;br&gt;&lt;br&gt;Craig
&lt;br&gt;&lt;br&gt;&lt;br&gt;Craig Wright
&lt;br&gt;Manager, Risk Advisory Services
&lt;br&gt;&lt;br&gt;Direct : +61 2 9286 5497
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218165&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Craig.Wright@...&lt;/a&gt;
&lt;br&gt;+61 417 683 914
&lt;br&gt;&lt;br&gt;BDO Kendalls (NSW-VIC) Pty. Ltd.
&lt;br&gt;Level 19, 2 Market Street Sydney NSW 2000
&lt;br&gt;GPO BOX 2551 Sydney NSW 2001
&lt;br&gt;Fax +61 2 9993 9497
&lt;br&gt;&lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&lt;br&gt;&lt;br&gt;The information in this email and any attachments is confidential. If you are not the named addressee you must not read, print, copy, distribute, or use in any way this transmission or any information it contains. If you have received this message in error, please notify the sender by return email, destroy all copies and delete it from your system.
&lt;br&gt;&lt;br&gt;Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls. You may not rely on this message as advice unless subsequently confirmed by fax or letter signed by a Partner or Director of BDO Kendalls. It is your responsibility to scan this communication and any files attached for computer viruses and other defects. BDO Kendalls does not accept liability for any loss or damage however caused which may result from this communication or any files attached. A full version of the BDO Kendalls disclaimer, and our Privacy statement, can be found on the BDO Kendalls website at &lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&amp;nbsp;or by emailing mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218165&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;administrator@...&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;BDO Kendalls is a national association of separate partnerships and entities. Liability limited by a scheme approved under Professional Standards Legislation.
&lt;br&gt;-----Original Message-----
&lt;br&gt;&lt;br&gt;From: Dan Lynch [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218165&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;DLynch@...&lt;/a&gt;]
&lt;br&gt;Sent: Tuesday, 13 May 2008 2:53 AM
&lt;br&gt;To: Craig Wright; Terry; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218165&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;
&lt;br&gt;Subject: RE: virtual firewalls -- compliance
&lt;br&gt;&lt;br&gt;I find this discussion interesting from a slightly different angle than
&lt;br&gt;the perspective of PCI or other standards compliance.
&lt;br&gt;&lt;br&gt;I tend to agree with Craig's view that there is inadequate segregation
&lt;br&gt;between guests running on different VMs of the same host, whether they
&lt;br&gt;be application servers or virtualized security appliances. There are
&lt;br&gt;multiple demonstrated guest breakout techniques for nearly all
&lt;br&gt;virtualization technologies.
&lt;br&gt;&lt;br&gt;Still, let me directly quote the supervisor of our Windows admin team:
&lt;br&gt;&lt;br&gt;&amp;gt;&amp;quot;Department of Homeland Security and NSA have
&lt;br&gt;&amp;gt; certified the VMware virtual switch and OS as being
&lt;br&gt;&amp;gt; equivalent to physical separation.&amp;quot;
&lt;br&gt;&lt;br&gt;He's referring to ESX3 -- the platform on which his group hopes to run
&lt;br&gt;multiple virtualized DMZ-based public Windows Server 2003 web servers,
&lt;br&gt;with the host OS directly connected to a private internal network. This
&lt;br&gt;is a strategy on which I requested comments from the list only a few
&lt;br&gt;weeks ago.
&lt;br&gt;&lt;br&gt;Thoughts?
&lt;br&gt;&lt;br&gt;&lt;br&gt;Dan Lynch, CISSP
&lt;br&gt;Information Technology Analyst
&lt;br&gt;County of Placer
&lt;br&gt;Auburn, CA
&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218165&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;
&lt;br&gt;&amp;gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218165&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of Craig Wright
&lt;br&gt;&amp;gt; Sent: Friday, May 09, 2008 4:51 PM
&lt;br&gt;&amp;gt; To: Terry; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218165&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: RE: virtual firewalls -- compliance
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; PCI-DSS v1.1 states at 1.4
&lt;br&gt;&amp;gt; &amp;quot;Prohibit direct public access between external networks and
&lt;br&gt;&amp;gt; any system component that stores cardholder data&amp;quot;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; A virtual system is a direct access. You have trusted and
&lt;br&gt;&amp;gt; untrusted on the same component. HIPAA is worse. You have a
&lt;br&gt;&amp;gt; number of hosts at different levels shared. This is a law
&lt;br&gt;&amp;gt; suit waiting to occur.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Other standards are the same. All I have to say is this is a
&lt;br&gt;&amp;gt; BAD idea. BAD!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; Craig Wright (GSE-Compliance)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Craig Wright
&lt;br&gt;&amp;gt; Manager, Risk Advisory Services
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Direct : +61 2 9286 5497
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218165&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Craig.Wright@...&lt;/a&gt;
&lt;br&gt;&amp;gt; +61 417 683 914
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; BDO Kendalls (NSW-VIC) Pty. Ltd.
&lt;br&gt;&amp;gt; Level 19, 2 Market Street Sydney NSW 2000 GPO BOX 2551 Sydney
&lt;br&gt;&amp;gt; NSW 2001 Fax +61 2 9993 9497 &lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The information in this email and any attachments is
&lt;br&gt;&amp;gt; confidential. If you are not the named addressee you must not
&lt;br&gt;&amp;gt; read, print, copy, distribute, or use in any way this
&lt;br&gt;&amp;gt; transmission or any information it contains. If you have
&lt;br&gt;&amp;gt; received this message in error, please notify the sender by
&lt;br&gt;&amp;gt; return email, destroy all copies and delete it from your system.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Any views expressed in this message are those of the
&lt;br&gt;&amp;gt; individual sender and not necessarily endorsed by BDO
&lt;br&gt;&amp;gt; Kendalls. You may not rely on this message as advice unless
&lt;br&gt;&amp;gt; subsequently confirmed by fax or letter signed by a Partner
&lt;br&gt;&amp;gt; or Director of BDO Kendalls. It is your responsibility to
&lt;br&gt;&amp;gt; scan this communication and any files attached for computer
&lt;br&gt;&amp;gt; viruses and other defects. BDO Kendalls does not accept
&lt;br&gt;&amp;gt; liability for any loss or damage however caused which may
&lt;br&gt;&amp;gt; result from this communication or any files attached. A full
&lt;br&gt;&amp;gt; version of the BDO Kendalls disclaimer, and our Privacy
&lt;br&gt;&amp;gt; statement, can be found on the BDO Kendalls website at
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&amp;nbsp;or by emailing mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218165&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;administrator@...&lt;/a&gt;.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; BDO Kendalls is a national association of separate
&lt;br&gt;&amp;gt; partnerships and entities. Liability limited by a scheme
&lt;br&gt;&amp;gt; approved under Professional Standards Legislation.
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218165&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;
&lt;br&gt;&amp;gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218165&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of Terry
&lt;br&gt;&amp;gt; Sent: Friday, 9 May 2008 5:37 AM
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218165&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: virtual firewalls -- compliance
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hello all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I am throwing around the idea of using linux firewalls in
&lt;br&gt;&amp;gt; vmware for customer environments. &amp;nbsp;The customers may or may
&lt;br&gt;&amp;gt; not have HIPAA/PCI/sOX/etc requirements. &amp;nbsp;This is in the
&lt;br&gt;&amp;gt; planning stages. &amp;nbsp;Any of you have experience heading down
&lt;br&gt;&amp;gt; this route? &amp;nbsp;PCIDSS doesn't explicitly state problems with
&lt;br&gt;&amp;gt; virtual firewalls, it seems to focus on the logic of the rules.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17218165.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17218108</id>
	<title>RE: virtual firewalls -- compliance</title>
	<published>2008-05-12T09:53:01Z</published>
	<updated>2008-05-12T09:53:01Z</updated>
	<author>
		<name>Dan Lynch-4</name>
	</author>
	<content type="html">I find this discussion interesting from a slightly different angle than
&lt;br&gt;the perspective of PCI or other standards compliance.
&lt;br&gt;&lt;br&gt;I tend to agree with Craig's view that there is inadequate segregation
&lt;br&gt;between guests running on different VMs of the same host, whether they
&lt;br&gt;be application servers or virtualized security appliances. There are
&lt;br&gt;multiple demonstrated guest breakout techniques for nearly all
&lt;br&gt;virtualization technologies.
&lt;br&gt;&lt;br&gt;Still, let me directly quote the supervisor of our Windows admin team:
&lt;br&gt;&lt;br&gt;&amp;gt;&amp;quot;Department of Homeland Security and NSA have
&lt;br&gt;&amp;gt; certified the VMware virtual switch and OS as being
&lt;br&gt;&amp;gt; equivalent to physical separation.&amp;quot;
&lt;br&gt;&lt;br&gt;He's referring to ESX3 -- the platform on which his group hopes to run
&lt;br&gt;multiple virtualized DMZ-based public Windows Server 2003 web servers,
&lt;br&gt;with the host OS directly connected to a private internal network. This
&lt;br&gt;is a strategy on which I requested comments from the list only a few
&lt;br&gt;weeks ago.
&lt;br&gt;&lt;br&gt;Thoughts?
&lt;br&gt;&lt;br&gt;&lt;br&gt;Dan Lynch, CISSP
&lt;br&gt;Information Technology Analyst
&lt;br&gt;County of Placer
&lt;br&gt;Auburn, CA
&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218108&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; 
&lt;br&gt;&amp;gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218108&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of Craig Wright
&lt;br&gt;&amp;gt; Sent: Friday, May 09, 2008 4:51 PM
&lt;br&gt;&amp;gt; To: Terry; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218108&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: RE: virtual firewalls -- compliance
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; PCI-DSS v1.1 states at 1.4
&lt;br&gt;&amp;gt; &amp;quot;Prohibit direct public access between external networks and 
&lt;br&gt;&amp;gt; any system component that stores cardholder data&amp;quot;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; A virtual system is a direct access. You have trusted and 
&lt;br&gt;&amp;gt; untrusted on the same component. HIPAA is worse. You have a 
&lt;br&gt;&amp;gt; number of hosts at different levels shared. This is a law 
&lt;br&gt;&amp;gt; suit waiting to occur.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Other standards are the same. All I have to say is this is a 
&lt;br&gt;&amp;gt; BAD idea. BAD!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; Craig Wright (GSE-Compliance)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Craig Wright
&lt;br&gt;&amp;gt; Manager, Risk Advisory Services
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Direct : +61 2 9286 5497
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218108&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Craig.Wright@...&lt;/a&gt;
&lt;br&gt;&amp;gt; +61 417 683 914
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; BDO Kendalls (NSW-VIC) Pty. Ltd.
&lt;br&gt;&amp;gt; Level 19, 2 Market Street Sydney NSW 2000 GPO BOX 2551 Sydney 
&lt;br&gt;&amp;gt; NSW 2001 Fax +61 2 9993 9497 &lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The information in this email and any attachments is 
&lt;br&gt;&amp;gt; confidential. If you are not the named addressee you must not 
&lt;br&gt;&amp;gt; read, print, copy, distribute, or use in any way this 
&lt;br&gt;&amp;gt; transmission or any information it contains. If you have 
&lt;br&gt;&amp;gt; received this message in error, please notify the sender by 
&lt;br&gt;&amp;gt; return email, destroy all copies and delete it from your system.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Any views expressed in this message are those of the 
&lt;br&gt;&amp;gt; individual sender and not necessarily endorsed by BDO 
&lt;br&gt;&amp;gt; Kendalls. You may not rely on this message as advice unless 
&lt;br&gt;&amp;gt; subsequently confirmed by fax or letter signed by a Partner 
&lt;br&gt;&amp;gt; or Director of BDO Kendalls. It is your responsibility to 
&lt;br&gt;&amp;gt; scan this communication and any files attached for computer 
&lt;br&gt;&amp;gt; viruses and other defects. BDO Kendalls does not accept 
&lt;br&gt;&amp;gt; liability for any loss or damage however caused which may 
&lt;br&gt;&amp;gt; result from this communication or any files attached. A full 
&lt;br&gt;&amp;gt; version of the BDO Kendalls disclaimer, and our Privacy 
&lt;br&gt;&amp;gt; statement, can be found on the BDO Kendalls website at 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&amp;nbsp;or by emailing mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218108&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;administrator@...&lt;/a&gt;.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; BDO Kendalls is a national association of separate 
&lt;br&gt;&amp;gt; partnerships and entities. Liability limited by a scheme 
&lt;br&gt;&amp;gt; approved under Professional Standards Legislation.
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218108&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; 
&lt;br&gt;&amp;gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218108&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of Terry
&lt;br&gt;&amp;gt; Sent: Friday, 9 May 2008 5:37 AM
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218108&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: virtual firewalls -- compliance
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hello all,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I am throwing around the idea of using linux firewalls in 
&lt;br&gt;&amp;gt; vmware for customer environments. &amp;nbsp;The customers may or may 
&lt;br&gt;&amp;gt; not have HIPAA/PCI/sOX/etc requirements. &amp;nbsp;This is in the 
&lt;br&gt;&amp;gt; planning stages. &amp;nbsp;Any of you have experience heading down 
&lt;br&gt;&amp;gt; this route? &amp;nbsp;PCIDSS doesn't explicitly state problems with 
&lt;br&gt;&amp;gt; virtual firewalls, it seems to focus on the logic of the rules.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17218108.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17218084</id>
	<title>Re: virtual firewalls -- compliance</title>
	<published>2008-05-12T00:37:18Z</published>
	<updated>2008-05-12T00:37:18Z</updated>
	<author>
		<name>Babu N</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;Are you a service provider trying to provide secure access to your 
&lt;br&gt;customers using a virtual firewall ?
&lt;br&gt;&lt;br&gt;If so, you need to consider the following:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- Whether to use OS-based virtualization (OpenVZ type) or 
&lt;br&gt;hyper-visor based virtualization ( Xen/VmWare type)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- performance implications of virtual firewalls. They tend to be 
&lt;br&gt;lower compared to physical devices due to binary 
&lt;br&gt;translation/instruction conversion.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- Usage of Intel-VT/AMD-V as underlying hardware
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- inter-VM access control issues.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;Babu
&lt;br&gt;&lt;br&gt;&lt;br&gt;At 01:07 AM 5/9/2008, Terry wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;Hello all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;I am throwing around the idea of using linux firewalls in vmware for
&lt;br&gt;&amp;gt;customer environments. &amp;nbsp;The customers may or may not have
&lt;br&gt;&amp;gt;HIPAA/PCI/sOX/etc requirements. &amp;nbsp;This is in the planning stages. &amp;nbsp;Any
&lt;br&gt;&amp;gt;of you have experience heading down this route? &amp;nbsp;PCIDSS doesn't
&lt;br&gt;&amp;gt;explicitly state problems with virtual firewalls, it seems to focus on
&lt;br&gt;&amp;gt;the logic of the rules.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Thanks!
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;********************************************************************************
&lt;br&gt;This email message (including any attachments) is for the sole use of the intended recipient(s) 
&lt;br&gt;and may contain confidential, proprietary and privileged information. Any unauthorized review, 
&lt;br&gt;use, disclosure or distribution is prohibited. If you are not the intended recipient, 
&lt;br&gt;please immediately notify the sender by reply email and destroy all copies of the original message. 
&lt;br&gt;Thank you.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Intoto Inc. 
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17218084.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17218006</id>
	<title>RE: virtual firewalls -- compliance</title>
	<published>2008-05-11T12:39:02Z</published>
	<updated>2008-05-11T12:39:02Z</updated>
	<author>
		<name>Craig Wright-2</name>
	</author>
	<content type="html">&lt;br&gt;&lt;br&gt;Hi,
&lt;br&gt;You do not need to specifically ban Something (Such as this).
&lt;br&gt;&lt;br&gt;Virtual hosts are ok as long as they are Single purpose devices.
&lt;br&gt;&lt;br&gt;PCI does not allow running dns and web on the Same Component -let alone separate Security Zones
&lt;br&gt;&lt;br&gt;So this is a big no no to which I would add the phrase &amp;quot;Contribitory Negligence&amp;quot; to any &amp;quot;Security professional&amp;quot; that Could even think of doing this.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;Craig Wright GSE-Compliance
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Craig Wright
&lt;br&gt;Manager, Risk Advisory Services
&lt;br&gt;&lt;br&gt;Direct : +61 2 9286 5497
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218006&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Craig.Wright@...&lt;/a&gt;
&lt;br&gt;+61 417 683 914
&lt;br&gt;&lt;br&gt;BDO Kendalls (NSW-VIC) Pty. Ltd.
&lt;br&gt;Level 19, 2 Market Street Sydney NSW 2000
&lt;br&gt;GPO BOX 2551 Sydney NSW 2001
&lt;br&gt;Fax +61 2 9993 9497
&lt;br&gt;www.bdo.com.au&amp;lt;&lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;The information in this email and any attachments is confidential. If you are not the named addressee you must not read, print, copy, distribute, or use in any way this transmission or any information it contains. If you have received this message in error, please notify the sender by return email, destroy all copies and delete it from your system.
&lt;br&gt;&lt;br&gt;Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls. You may not rely on this message as advice unless subsequently confirmed by fax or letter signed by a Partner or Director of BDO Kendalls. It is your responsibility to scan this communication and any files attached for computer viruses and other defects. BDO Kendalls does not accept liability for any loss or damage however caused which may result from this communication or any files attached. A full version of the BDO Kendalls disclaimer, and our Privacy statement, can be found on the BDO Kendalls website at &lt;a href=&quot;http://www.bdo.com.au&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au&lt;/a&gt;&amp;lt;&lt;a href=&quot;http://www.bdo.com.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bdo.com.au/&lt;/a&gt;&amp;gt; or by emailing &amp;nbsp;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218006&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;administrator@...&lt;/a&gt;&amp;lt;mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218006&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;administrator@...&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;BDO Kendalls is a national association of separate partnerships and entities. Liability limited by a scheme approved under Professional Standards Legislation.
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;From: &amp;quot;Erik Harrison&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218006&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;eharrison@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &amp;quot;Terry&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218006&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;td3201@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Cc: &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218006&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218006&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Sent: 12/05/08 3:20 AM
&lt;br&gt;Subject: Re: virtual firewalls -- compliance
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;That's an interesting problem. For PCI - at least in my interpretation (please correct me if you do these assessments for a living) - as long as the VM parent, or the linux VM children are not controlled or accessed by other customers and you as the provider (or whoever manages the box) adhere to the DSS requirements, it should audit well. It's about segregation, logical or physical, as long as a client doesnt have access to break out and tamper with config which could alter their segregation, I think it's fine.
&lt;br&gt;&lt;br&gt;Now, if you're going to host multiple customers behind those firewalls, you'll want to VLAN each of them and probably not share a netblock among them - again for isolation purposes.
&lt;br&gt;&lt;br&gt;But again.. I'm not specialized in this area. If you find the answer to this, please let me know. I'd love to get this straight as well.
&lt;br&gt;&lt;br&gt;On Thu, May 8, 2008 at 3:37 PM, Terry &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218006&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;td3201@...&lt;/a&gt;&amp;lt;mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17218006&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;td3201@...&lt;/a&gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;Hello all,
&lt;br&gt;&lt;br&gt;I am throwing around the idea of using linux firewalls in vmware for
&lt;br&gt;customer environments. &amp;nbsp;The customers may or may not have
&lt;br&gt;HIPAA/PCI/sOX/etc requirements. &amp;nbsp;This is in the planning stages. &amp;nbsp;Any
&lt;br&gt;of you have experience heading down this route? &amp;nbsp;PCIDSS doesn't
&lt;br&gt;explicitly state problems with virtual firewalls, it seems to focus on
&lt;br&gt;the logic of the rules.
&lt;br&gt;&lt;br&gt;Thanks!
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17218006.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17175642</id>
	<title>Re: virtual firewalls -- compliance</title>
	<published>2008-05-10T18:35:48Z</published>
	<updated>2008-05-10T18:35:48Z</updated>
	<author>
		<name>David M. Zendzian</name>
	</author>
	<content type="html">I've been thinking about this one for a while as I have both a hosting 
&lt;br&gt;service &amp; do PCI work on an almost daily basis.
&lt;br&gt;&lt;br&gt;What I have come to conclude is that you will most likely want to put 
&lt;br&gt;your firewall devices (virtual or otherwise) on different physical 
&lt;br&gt;hardware from the other application servers you are running. &amp;nbsp;You will 
&lt;br&gt;also want to be sure that the external firewall segments are plugged 
&lt;br&gt;into different switches from your internal segments (different physical 
&lt;br&gt;devices are better than VLANs)
&lt;br&gt;&lt;br&gt;Now you can set it up having your firewalls as just another virtual 
&lt;br&gt;machine, but life will be easier to show separation of duties, &amp;quot;one 
&lt;br&gt;primary use&amp;quot; (yes vmware/xen/etc will all have multiple servers 
&lt;br&gt;together, and it depends on the assessor validating your environment, 
&lt;br&gt;but I personally feel that firewall and networking devices are 
&lt;br&gt;definitely different functions that application/web/db/mail/... servers 
&lt;br&gt;and as such I recommend that firewall devices be on different physical 
&lt;br&gt;devices from your other application servers.
&lt;br&gt;&lt;br&gt;I would also like to point out that within the virtual host server, you 
&lt;br&gt;will find that both network &amp; server requirements are both mixed 
&lt;br&gt;together as you are most likely brining multiple vlans into the host 
&lt;br&gt;server and then allocating access to each vlan (bridges under xen, etc) 
&lt;br&gt;to each virtual server. As such, you now have network &amp; server 
&lt;br&gt;characteristics combined into a single device.
&lt;br&gt;&lt;br&gt;This will make it more difficult to show that each component is properly 
&lt;br&gt;configured, maintained &amp; monitored. You will need to be sure to have all 
&lt;br&gt;of your documentation in order and use as many tools as possible to 
&lt;br&gt;standardize how each function is maintained and securely monitored.
&lt;br&gt;&lt;br&gt;Also, will the virtual host machine be maintained by the same core team 
&lt;br&gt;as the firewall / database / web / mail / etc services?
&lt;br&gt;&lt;br&gt;And you mentioned PCI doesn't specifically mention virtual firewalls, 
&lt;br&gt;that is true, but it does specify firewall/router/server configuration 
&lt;br&gt;standards, policies, change management, security monitoring and a host 
&lt;br&gt;of other requirements that will need to be met even if you have only one 
&lt;br&gt;customer needing to have compliant services.
&lt;br&gt;&lt;br&gt;Good luck
&lt;br&gt;David M. Zendzian
&lt;br&gt;Managing Partner
&lt;br&gt;ZZ Servers, LLC: &lt;a href=&quot;http://www.zzservers.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.zzservers.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;PS you may want to consider other platforms if you are reselling 
&lt;br&gt;virtualization ;)
&lt;br&gt;&lt;br&gt;Terry wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I am throwing around the idea of using linux firewalls in vmware for
&lt;br&gt;&amp;gt; customer environments. &amp;nbsp;The customers may or may not have
&lt;br&gt;&amp;gt; HIPAA/PCI/sOX/etc requirements. &amp;nbsp;This is in the planning stages. &amp;nbsp;Any
&lt;br&gt;&amp;gt; of you have experience heading down this route? &amp;nbsp;PCIDSS doesn't
&lt;br&gt;&amp;gt; explicitly state problems with virtual firewalls, it seems to focus on
&lt;br&gt;&amp;gt; the logic of the rules.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17175642.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17175628</id>
	<title>Re: virtual firewalls -- compliance</title>
	<published>2008-05-10T16:18:45Z</published>
	<updated>2008-05-10T16:18:45Z</updated>
	<author>
		<name>Erik Harrison-3</name>
	</author>
	<content type="html">That&amp;#39;s an interesting problem. For PCI - at least in my interpretation (please correct me if you do these assessments for a living) - as long as the VM parent, or the linux VM children are not controlled or accessed by other customers and you as the provider (or whoever manages the box) adhere to the DSS requirements, it should audit well. It&amp;#39;s about segregation, logical or physical, as long as a client doesnt have access to break out and tamper with config which could alter their segregation, I think it&amp;#39;s fine. &lt;br&gt;
&lt;br&gt;Now, if you&amp;#39;re going to host multiple customers behind those firewalls, you&amp;#39;ll want to VLAN each of them and probably not share a netblock among them - again for isolation purposes.&lt;br&gt;&lt;br&gt;But again.. I&amp;#39;m not specialized in this area. If you find the answer to this, please let me know. I&amp;#39;d love to get this straight as well.&lt;br&gt;
&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, May 8, 2008 at 3:37 PM, Terry &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17175628&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;td3201@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
Hello all,&lt;br&gt;
&lt;br&gt;
I am throwing around the idea of using linux firewalls in vmware for&lt;br&gt;
customer environments. &amp;nbsp;The customers may or may not have&lt;br&gt;
HIPAA/PCI/sOX/etc requirements. &amp;nbsp;This is in the planning stages. &amp;nbsp;Any&lt;br&gt;
of you have experience heading down this route? &amp;nbsp;PCIDSS doesn&amp;#39;t&lt;br&gt;
explicitly state problems with virtual firewalls, it seems to focus on&lt;br&gt;
the logic of the rules.&lt;br&gt;
&lt;br&gt;
Thanks!&lt;br&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17175628.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17175613</id>
	<title>Re: virtual firewalls -- compliance</title>
	<published>2008-05-10T07:08:37Z</published>
	<updated>2008-05-10T07:08:37Z</updated>
	<author>
		<name>Ron Brown-2</name>
	</author>
	<content type="html">I may be old fashioned, but for me (and the environment I admin) firewalls need to be dedicated systems, running on dedicated hardware with discreet physical network interfaces. While I'm all for virtualization of application servers, in a security role I can't support the concept of a security device sharing it's hardware with any other applications in a production environment, as the benefits (space, power, hvac, cost savings, etc) are outweighed by the additional possible attack vectors that would be introduced by the host system and neighboring VM's. &amp;nbsp;Also, while I am not aware of any specific reference to this in the various regulatory requirements, one of the questions asked of me in a recent HIPAA audit was something to the effect of &amp;quot;do any of your network perimeter devices serve any purpose other than that of security and access control?&amp;quot; 
&lt;br&gt;&lt;br&gt;Just my opinion though :-)
&lt;br&gt;&lt;br&gt;Cheers!
&lt;br&gt;&lt;br&gt;Ron
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Terry &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17175613&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;td3201@...&lt;/a&gt;&amp;gt; 5/8/2008 3:37 PM &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;Hello all,
&lt;br&gt;&lt;br&gt;I am throwing around the idea of using linux firewalls in vmware for
&lt;br&gt;customer environments. &amp;nbsp;The customers may or may not have
&lt;br&gt;HIPAA/PCI/sOX/etc requirements. &amp;nbsp;This is in the planning stages. &amp;nbsp;Any
&lt;br&gt;of you have experience heading down this route? &amp;nbsp;PCIDSS doesn't
&lt;br&gt;explicitly state problems with virtual firewalls, it seems to focus on
&lt;br&gt;the logic of the rules.
&lt;br&gt;&lt;br&gt;Thanks!
&lt;br&gt;&lt;br&gt;&lt;br&gt;CONFIDENTIALITY NOTICE: &amp;nbsp;This email message, including any attachments, is for the use of the intended recipient(s) only and may contain information that is privileged, confidential, and prohibited from unauthorized disclosure under applicable law. &amp;nbsp;If you are not the intended recipient of this message, any dissemination, distribution, or copying of this message is strictly prohibited. &amp;nbsp;If you received this message in error, please notify the sender by reply email and destroy all copies of the original message and attachments.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17175613.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17175555</id>
	<title>Re: virtual firewalls -- compliance</title>
	<published>2008-05-10T07:02:59Z</published>
	<updated>2008-05-10T07:02:59Z</updated>
	<author>
		<name>Chris Clymer-2</name>
	</author>
	<content type="html">Terry wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I am throwing around the idea of using linux firewalls in vmware for
&lt;br&gt;&amp;gt; customer environments. &amp;nbsp;The customers may or may not have
&lt;br&gt;&amp;gt; HIPAA/PCI/sOX/etc requirements. &amp;nbsp;This is in the planning stages. &amp;nbsp;Any
&lt;br&gt;&amp;gt; of you have experience heading down this route? &amp;nbsp;PCIDSS doesn't
&lt;br&gt;&amp;gt; explicitly state problems with virtual firewalls, it seems to focus on
&lt;br&gt;&amp;gt; the logic of the rules.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks!
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;I'm pretty sure that none of the aforementioned requirements explicitly
&lt;br&gt;denies running your firewalls in virtualization. &amp;nbsp;However, unless the
&lt;br&gt;purpose of the firewall is strictly to manage the traffic in and out of
&lt;br&gt;virtual servers on the same host the firewall is on, I would strongly
&lt;br&gt;advocate not virtualizing your firewall.
&lt;br&gt;&lt;br&gt;Virtualization has obvious wonderful performance and cost benefits, but
&lt;br&gt;placing your security devices into it has the potential to greatly
&lt;br&gt;increase their exposure. &amp;nbsp;There was an excellent presentation done at
&lt;br&gt;last years SANSFire which demonstrated multiple ways to jump from a
&lt;br&gt;virtual guest to the host...and therefore have the ability to do
&lt;br&gt;anything you want to any guest on that system.
&lt;br&gt;&lt;br&gt;So unless this is for a lab environment, spend a few extra bucks and buy
&lt;br&gt;hardware for your firewalls. &amp;nbsp;You'll be glad you did.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17175555.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17175553</id>
	<title>Re: virtual firewalls -- compliance</title>
	<published>2008-05-09T17:00:03Z</published>
	<updated>2008-05-09T17:00:03Z</updated>
	<author>
		<name>Joseph Jenkins</name>
	</author>
	<content type="html">That is true that it doesn't say anything about whether the firewalls &amp;nbsp;
&lt;br&gt;need to be physical devices or not. &amp;nbsp;The only thing I would be wary of &amp;nbsp;
&lt;br&gt;is what is coming down in the next version which is supposed to be out &amp;nbsp;
&lt;br&gt;in a couple of months.
&lt;br&gt;On May 8, 2008, at 12:37 PM, Terry wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I am throwing around the idea of using linux firewalls in vmware for
&lt;br&gt;&amp;gt; customer environments. &amp;nbsp;The customers may or may not have
&lt;br&gt;&amp;gt; HIPAA/PCI/sOX/etc requirements. &amp;nbsp;This is in the planning stages. &amp;nbsp;Any
&lt;br&gt;&amp;gt; of you have experience heading down this route? &amp;nbsp;PCIDSS doesn't
&lt;br&gt;&amp;gt; explicitly state problems with virtual firewalls, it seems to focus on
&lt;br&gt;&amp;gt; the logic of the rules.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks!
&lt;/div&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/virtual-firewalls----compliance-tp17157866p17175553.html" />
</entry>

</feed>
