RE: Help me

From: Andrew Shore (andrew.shore_at_holistecs.com)
Date: 02/24/05

  • Next message: Andrew Shore: "RE: What could this icmp mean?"
    Date: Thu, 24 Feb 2005 22:47:02 -0000
    To: "Tran Nguyen Vu" <tran.vunguyen@gmail.com>, <security-basics@securityfocus.com>
    
    

    Is your ISA server just logging www & ftp access?

    By default ISA will only log what it is proxying not what is passing
    through.

    Don't forget mail access.

    The missing 40 gig would account for our mail traffic.

    Also are you allowing p2p?

    HTH

    Andy

    -----Original Message-----
    From: Tran Nguyen Vu [mailto:tran.vunguyen@gmail.com]
    Sent: 21 February 2005 11:20
    To: security-basics@securityfocus.com
    Subject: Help me

    Dear all,
    I have a problem and i dont know how to explain.
    Last month, my ISP give our company a report about the capacity download
    and upload, It was about 47GB.
    The problem is my isa server has logged at about 7GB data down/upload.
    When I asked them explain this great unequal capacity they said that
    although My isa firewall prevented almost requests from the untrust
    network (so this request was not included in capacity logfile and only
    7GB was allowed),their server logged all requests to my router and
    firewall from the other local Loop . It mean, there are 40GB data of
    requests that not except (attack, scan ping ...) in a month.
    So I make some caculation, every second, there are 16035 byte attack (I
    call "attack" because I was not allowed.
    Everybody help me explain this situation. I know, A request does not
    have big capacity and my ISA server was not logged any attack!

    Please help me. (sorry because of my english!)
    Thanks in advance.


  • Next message: Andrew Shore: "RE: What could this icmp mean?"

    Relevant Pages

    • Re: Help me
      ... A request does not have ... > big capacity and my ISA server was not logged any attack! ...
      (Security-Basics)
    • Configure Proxy to forward to internal Proxy?!
      ... the following problem: Outgoing proxy requests from internal clients should be forwarded to an internal proxy: ... An internal client requests an address to the isa server, which is located in the internal network. ... I used all 3 possibilities in ISA Server routing rule. ...
      (microsoft.public.isa.configuration)
    • Cant Access application config file with APPSETTINGS through fire
      ... We have a client with an ISA Server 2000 configured in cache only mode, ... Integrated authentication is required for requests. ... We can replicate the problem with an ISA Server 2000 configured in integrated ...
      (microsoft.public.dotnet.framework)
    • Re: Problem disabling all web logging except for 1 Web Publishing
      ... > After you turn off logging for a Web publishing rule, ... >> Version: ISA Server 2004 STD. ... >> dont want anything stored in this log file except requests made to WPR2 ...
      (microsoft.public.isa)
    • Re: Disable Logging System Policies
      ... For me, I just don't wanna log part of denied requests, for example, ... It seems that I have set up some rules based on those broadcast in order to ... ISA Server Product Team ... I still want logging of firewall events but only ...
      (microsoft.public.isaserver)