RE: ISA 2004 FTP SSL

From: Jim Harrison (ISA) (jmharr_at_microsoft.com)
Date: 06/24/05

  • Next message: Jim Harrison (ISA): "RE: Using Messenger Service for 'Net Send' Functionality --- Dangerous?Why?"
    Date: Fri, 24 Jun 2005 12:20:40 -0700
    To: "MOYA Yves" <MOYA@ifb-france.com>, <focus-ms@securityfocus.com>
    
    

    This is a common problem with FTPS.
    ISA can't "see into" the traffic to adjust the traffic policies as it
    does with "normal" FTP.

    Maybe these will help:
    http://isaserver.org/pages/search.asp?query=ftp

    Jim Harrison
    Security Business Unit (ISA SE)
    "When you come to a fork in the road, take it."
    --Yogi Berra

    -----Original Message-----
    From: MOYA Yves [mailto:MOYA@ifb-france.com]
    Sent: Friday, June 24, 2005 10:46 AM
    To: focus-ms@securityfocus.com
    Subject: ISA 2004 FTP SSL

    Hello,

    I need some help for publishing a ftp serveur with SSL

    client --- Internet --- ISA --- IIS

    IIS 6.0 cannot do ftp with ssl so I want ssl connexion only between
    Client and ISA.

    And classic ftp between ISA and IIS 6.0

    client --- FTPS 990 ---- ISA --- FTP 21 ---IIS

    I try publishing my ftp site like https, but isa says "http 1.1 error
    400 bad data" to clients.

    Noway to use ssl without publishing secure site web ?

    Thanks for the help,

    Yves

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Jim Harrison (ISA): "RE: Using Messenger Service for 'Net Send' Functionality --- Dangerous?Why?"

    Relevant Pages

    • Re: Is this a 3-Leg Perimeter scenario?
      ... Disabled the ISA firewall client on the LAN client by opening the configure ... server, and leave LAN clients as 'normal'? ... From the network diagram, to access the FTP server from the LAN client, ...
      (microsoft.public.windows.server.sbs)
    • Re: Is this a 3-Leg Perimeter scenario?
      ... Disabled the ISA firewall client on the LAN client by opening the configure ... server, and leave LAN clients as 'normal'? ... From the network diagram, to access the FTP server from the LAN client, ...
      (microsoft.public.windows.server.sbs)
    • Re: ISA 2004 blocking FTP Scanner on the Network
      ... The copier uses FTP to do this job. ... Does SBS 2003 R2 Premium have FTP enabled by default? ... configure the networking settings for a SBS server. ... creates the ISA rules for internet access and site publishing. ...
      (microsoft.public.windows.server.sbs)
    • Re: ports
      ... SSL is garbage in any direction to ISA if it doesn't terminate the SSL session. ... The reason "clear-text" FTP works in either direction for ISA is because ISA can "see" the conversation happening within the FTP ... >Connected to ***.81.243.250:21, Waiting for Server ...
      (microsoft.public.isa.configuration)
    • RE: ISA 2004 blocking FTP Scanner on the Network
      ... creates the ISA rules for internet access and site publishing. ... Ensure the configuration of SBS Protected Networks Access Rule ... FTP", then uncheck the Read Only checkbox. ... 'Microsoft Firewall' service. ...
      (microsoft.public.windows.server.sbs)