<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Infrastructure snapshots : ISA</title><link>http://blogs.technet.com/mbaher/archive/tags/ISA/default.aspx</link><description>Tags: ISA</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Final release of the new ISA firewall client</title><link>http://blogs.technet.com/mbaher/archive/2006/12/17/final-release-of-the-new-isa-firewall-client.aspx</link><pubDate>Sun, 17 Dec 2006 21:33:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:560531</guid><dc:creator>mbaher@microsoft.com</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mbaher/comments/560531.aspx</comments><wfw:commentRss>http://blogs.technet.com/mbaher/commentrss.aspx?PostID=560531</wfw:commentRss><description>&lt;P&gt;Vista users, the final release of the ISA firewall client is released. Go and download it &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyId=05C2C932-B15A-4990-B525-66380743DA89&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyId=05C2C932-B15A-4990-B525-66380743DA89&amp;amp;displaylang=en&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Enjoy&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=560531" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mbaher/archive/tags/ISA/default.aspx">ISA</category><category domain="http://blogs.technet.com/mbaher/archive/tags/Misc/default.aspx">Misc</category></item><item><title>Ports required for external trust using ISA 2004/2006</title><link>http://blogs.technet.com/mbaher/archive/2006/12/17/ports-required-for-external-trust-using-isa-2004-2006.aspx</link><pubDate>Sun, 17 Dec 2006 12:17:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:560123</guid><dc:creator>mbaher@microsoft.com</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mbaher/comments/560123.aspx</comments><wfw:commentRss>http://blogs.technet.com/mbaher/commentrss.aspx?PostID=560123</wfw:commentRss><description>&lt;P&gt;&lt;FONT face=Calibri color=#000000 size=3&gt;You want to establish an external trust between two domains where there is an ISA 2004 or ISA 2006 in between.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Establishing trust requires Kerberos, LDAP, DNS, CIFS &amp;amp; the big problem is the RPCs… one idea is to strict the RPC port on the DCs using registry and open this specified range on the ISA which will be not less than 100 port per the recommendations, other idea was to create an IPSEC tunnel between both DCs and open the IPSC ports only on the firewall however the cons of this solution is the complexity &amp;amp; the exposure of both DCs communication between each other. With ISA 2004 &amp;amp; 2006 the RPC filter will help you establish this, the filter listens for the RPC port maper 135 request and depending on the UUID the ISA sees which port is required to be opened for such service and dynamically open the port for the communication till the session ends. So based on this great cool feature only the below ports are only required to be opened on the ISA.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;FONT color=#000000&gt;&lt;FONT face=Calibri&gt;PING (ICMP)&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;FONT color=#000000&gt;&lt;FONT face=Calibri&gt;DNS Query&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Calibri color=#000000 size=3&gt;Kerberos-Sec (UDP)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 88&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;UDP SEND/RECEIVE&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Calibri color=#000000 size=3&gt;LDAP&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;389 UDP SEND/RECEIVE&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Calibri color=#000000 size=3&gt;LDAP (UDP)&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;389 TCP OUTBOUND&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Calibri color=#000000 size=3&gt;Microsoft CIFS (TCP)&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;445 TCP OUTBOUND&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Calibri color=#000000 size=3&gt;RPC (All interfaces)&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;135 TCP OUTBOUND&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Calibri color=#000000 size=3&gt;Note: PING is required and don’t forget to establish a name resolution mechanism, I would recommend DNS conditional forwarding for both domains&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=560123" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mbaher/archive/tags/ISA/default.aspx">ISA</category></item></channel></rss>