Re: routing and remote access don't generate firewall connection logs ?!?

From: zwetan (nospam_at_nospam.com)
Date: 11/23/03


Date: Sun, 23 Nov 2003 18:09:45 +0100


> RRAS features packet filtering for the purpose of reducing the load on
> routing engine and network interfaces - it was never intended for firewall
> use, doesn't feature logs, stateful inspection/spoofing protection, and
many
> other things often found in firewalls. This is why we have ICF (which will
> improve in the next service pack, AFAIK) and all other software to choose
> from.
>

the problem is you can't have RRAS and ICF in the same time

so for now I'm stuck using NAT/firewall from RRAS but without logs
or
use ICS/ICF with logs but without the optimization of RRAS with packet
filtering etc...

hoope that situation will improve in next service pack....

zwetan



Relevant Pages

  • Re: ISA 2004 & SBS 2003
    ... I assume that ISA 2004 also has a Firewall Client. ... > NAT is configured through RRAS. ... > would know the wizards worked again if everything was configured correctly ...
    (microsoft.public.windows.server.sbs)
  • Re: RRAS - Works on internal network, not past DMZ
    ... > VPN Users would connect directly to the Public interface of the RRAS box. ... The Firewall would need some additional configuration if you ... On the network connections configuration of the RRAS box, ... but the 'multiple gateway' error message has me spooked. ...
    (microsoft.public.windows.server.networking)
  • Re: Unknown Network Attack
    ... disabled on a server using rras. ... Check your tcp/ip configuration to make ... IP to DHCP or changed the entries in tcp/ip such as IP address, dns server, ... >> firewall configurations for some firewalls. ...
    (microsoft.public.windows.server.networking)
  • RE: Static routes w/o RRAS
    ... Actually, I had already disabled RRAS, run the CEICW, then disabled the ... Windows firewall, re-enabled RRAS, and configured the static routes. ... we still can add static routes in RRAS on SBS 2003 R2 ...
    (microsoft.public.windows.server.sbs)
  • Re: Passive FTP on PPPoE connection
    ... actual IP address the connection was initiated to in the 227 command. ... at this moment the RRAS firewall prevents me from connecting from ... range for passive FTP and open that range in the RRAS firewall. ...
    (microsoft.public.inetserver.iis.ftp)