Showing posts with label ISA. Show all posts
Showing posts with label ISA. Show all posts

Tuesday, 27 July 2010

SBS – ActiveSync Error 0x80072F0D – Security certificate is invalid

As we go through the current SBS v7 migration we have hit a few different issues.

This SBS is using a GoDaddy certificate where everything is seemingly set up correctly, but ActiveSync does not agree.

Microsoft Exchange

Result:
The security certificate on the server is not valid. Contact your Exchange Server administrator or ISP to install a valid certificate on the server.Support code: 0x80072F0D

So far, we have ran through and verified that the GoDaddy certificate and Intermediate Certificate Authority certificates are installed correctly.

We set up a test e-mail account to help with our troubleshooting using the Microsoft Exchange Remote Connectivity Analyzer.

image

This is the result:

image

When we drill into the Test Details section to come up with the reason we see:

image

Validating certificate trust for Windows Mobile Devices

Certificate trust validation failed.
Additional Details

Missing intermediate certificate in Certificate Chain. Subject = SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US, See KB 927465 for more details.

The process that we went through to make sure that SBS v7 had its certificate hierarchy in place was the following:

  1. Open the Certificates.msc that is found on the desktop.
  2. Open the Certificates folder under Intermediate Certificate Authorities folder.
  3. Delete any GoDaddy certificates in that folder only.
  4. Download the following certificates from GoDaddy’s Repository site:
    1. gd_cross_ntermediate.crt
    2. gd_intermediate.crt
  5. In the Certificates console:
    1. Right click on the Intermediate Certificate Authorities root folder and Import.
    2. Import the gd_cross_ntermediate.crt _first_
    3. Import the gd_intermediate.crt _second_
  6. In the Personal –> Certificates folder
    1. Verify that the needed GoDaddy certificate is properly keyed.
    2. Delete any GoDaddy certificates that are not needed.
  7. IIReset from an elevated command prompt.

Once we cleaned things up our ActiveSync connection test was successful:

image

Note that we are using a test user account that was created just for this task. Once we have all of our troubleshooting issues taken care of we will delete this account.

The KB referenced in the above failed test results:

Note that if ISA/TMG is running in front of the SBS network that the OS ISA runs on top of must also have the intermediate certificates installed according to the above instructions.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Friday, 12 February 2010

Error – FormMaster CCH Instant Update Can’t Connect Behind ISA

One of our client’s proprietary applications called FormMaster has a built-in update feature.

Whenever they ran the update, it refused to connect to the CCH server, or go anywhere beyond the initial connection

In the ISA live query, the following would be seen from the XP Pro client in the log:

  1. XP –> CCH IP –> Destination Port 80 –> HTTP –> Internal –> External
  2. XP –> SBS IP –> Destination Port 1745 –> TCP Unknown –> Internal –> Local Host

Enabling SOCKS proxy settings in the application in any combination would not work.

A call into CCH support ended up getting us the setting we needed to make things work:

image

Make sure the correct customer number, postal code, and phone number are in place.

Check the Override Default Server Information and set the port number to 8093. Leave the Server Name field blank.

Click OK, then click the Next button to initiate the connection to the server and we will see:

image

Once the scan for files has finished, we will see:

image

Once the files are downloaded, the original CCH program will need to be closed before the updates can run or the following error will happen:

image

After closing the application and clicking OK, the updates ran as expected.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Thursday, 3 December 2009

SBS 2003 – Determining ISA 2004 Version And Service Pack Level

We needed to figure out what service pack level one of our ISA 2004 on SBS 2003 installations has:

This is the grid from the ISAServer.org site:

image

In our case, our version number is 4.0.2167.907 which indicates that it is Service Pack 3 with at least one update beyond that.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Monday, 23 February 2009

SBS 2008 SharePoint 987 and ISA 2006 Non-Standard SSL Ports

If there comes a time to work with a Web site that uses a nonstandard SSL port for its setup, then ISA will not allow the Web browser on through to the site.

For those of us running ISA 2006 SP1 to protect our now migrated domains to SBS 2008, or to manage our client’s SBS 2008 domains where the Companyweb SharePoint site now uses port 987 for its SSL connections from within our ISA protected network, there will be a need to allow that port through ISA 2006 SP1.

The same need applies for those that need to connect to remote SBS 2008 Companyweb sites via SBS 2003 SP1 and R2 Premium networks protected by ISA 2004 SP3.

To correct this, a utility is needed to modify the allowed SSL ports list in ISA. We use the ISA Tunnel Port Editor (ISAtrpe) utility that can be had from the ISATools.org site: ISATools.org ISA 2004 downloads. The download is about 2/3 of the way down the list.

09-02-23 SBS 2008 and ISA 2006 - SSL Port configuration

ISA Tunnel Port Editor

In the above screenshot, we are looking at a vanilla ISA 2006 SP1 install on Windows Server 2003 R2 Standard.

So, we would do the following to get things happening:

  1. LowPort: 987
  2. HighPort: 987
  3. TunnelPortName: SBSSharePoint
  4. Click the Add Tunnel Range button.
  5. Wait a minute or two.
  6. An “Added SBSSharePoint successful!” message will appear when done. Click the OK button.
  7. The newly added port should be listed in the ports list as shown below.

Note that if the port addition is done via an RDP session, the RDP session may be broken. It should be reestablished close to the end of the procedure.

09-02-23 SBS 2008 and ISA 2006 - SSL Port configuration with SharePoint

ISA Tunnel Port Editor with Port 987 Added

Once the procedure has completed, close the Tunnel Editor.

Direct access, or access via the Remote Web Workplace, to any remote Companyweb SharePoint site will work after this.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac!

Windows Live Writer

Saturday, 17 January 2009

SBS 2003 - ISA and ExchangeDefender IP Subnets

Since our switch to the ExchangeDefender service for our own e-mail is now over 72 hours old, we can be reasonably confident that there are no other e-mail servers out there that are using our old DNS MX records that pointed to our three SBS sites.

Since we purchased SBS 2003 R2 Premium SA for two of our sites, we will be migrating both sites to SBS 2008 and still be eligible to protect those sites with ISA.

In the mean time, our sites are still behind ISA running on SBS 2003 R2 Premium.

Now, the ExchangeDefender Deployment Guide addresses the need to limit the IP subnets to protect the internal Exchange server without getting into too much detail. The recommendation is to limit SMTP traffic at the firewall, but since there are so many firewall products out there, the deployment guide only shows us how to set the IP subnet restrictions into Exchange itself.

Here are the ExchangeDefender IP subnets:

ExchangeDefender IP Subnets

For SBS 2003 R2 Premium with ISA 2004 SP3 installed, and for the time when we migrate to SBS 2008 protected by our Software Assurance benefit of ISA 2006 SP1, the setup is actually quite simple.

In the case of SBS 2003 R2 Premium, we took the default SBS Smtp Server Access Rule that had the External network set as the From/Listener and removed it. We then created the ExchangeDefender Subnets in the Add dialogue on the From tab for the rule. The following screenshot shows the modification:

ISA - SBS Smtp Server Access Rule Properties - From Tab

And, once the edit is complete and the APPLY button in ISA has been clicked on:

Default SBS SMTP Rule modified with the ExchangeDefender subnets

The rule setup will be similar on the standalone ISA 2006 SP1.

Once the 72 hours have passed and legitimate e-mail is flowing solely through the ExchangeDefender network, head into the ISA live Logging feature and delimit the query on the SMTP protocol. It will become readily apparent that there are a lot of illegitimate SMTP connection attempts being made.

ISA blocking SMTP attempts

In this particular screenshot, the IP address is from Kiev (Kyyiv) in the Ukraine.

And this one is from Kuala Lumpur:

ISA blocking SMTP attempts

We certainly hope that as time goes by that the IP address associated with our Exchange server no longer resides on spammer's e-mail server IP address list.

Now that we have seen this, ExchangeDefender makes even more sense to us.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Monday, 8 September 2008

Security and SBS 2008 Webinar with Untangle

I will be a part of the upcoming Webinar presented by Untangle.

You can register here.

Untangle will be presenting on Security in an SBS 2008 World tying in their Untangle firewall security product.

For those looking for alternatives to ISA or SonicWall, Untangle may present one, though we have not had a chance to evaluate their product yet.

We will be diving into the Untangle product along with others as we look for an alternative to SBS 2003 R2 Premium once SBS 2008 SKUs go live. Once we do, we will be sure to share the results here.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Thursday, 28 August 2008

SBS 2008 Premium on Open Value Licensing - ISA considerations

This post is more to generate some creative juices in the old grey matter. ;)

Given the experiences we have had configuring ISA 2004 to work with our SBS 2008 lab setups, there look to be a couple of possible methods to make things work.

The key to it all folks: Take a very close look at your SBS 2003 SP1/R2 Premium setups with ISA 2004 installed and configured properly.

Look at how the SSL setup works and just how the Configure E-mail and Internet Connection Wizard sets the ISA SSL bridging up.

From there, it is possible to see two possible ways of configuring ISA:

  1. Bridging using the SBS self-issued cert for RWW and an internal URL for RWW. ISA will bridge SSL for remote.mysbs2008.com to remote.mysbsdomain.local without the dreaded 500 errors.
  2. Bridging using the split DNS setup built into SBS 2008. ISA bridge Internet remote.mysbsdomain.com calls to remote.mysbsdomain.com on the SBS 2008 box.
We have been using the second method to make everything work so far. The key factor is to make sure to import the third party SSL certificate with the Private Key in it.

But, since the current SBS 2003 SP1/R2 Premium setups with ISA 2004 use method 1, we will experiment with it to see if using the internal URL will break things on SBS 2008 ... a distinct possibility given the wizard's use of a split DNS setup.

We won't be able to do this until our lab setup has the SBS 2008 Win2K3 setup in place with ISA 2006 installed and waiting to be configured for use with the Springers' SBS 2008 network.

If the trial runs at setting up option 1 do not work, we will make sure to let you know...

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Saturday, 2 August 2008

SBS 2K3 Premium - Configuring an SSL Wildcard Cert

Finding information on getting a third party SSL certificate installed on SBS Premium is a struggle.

In our case, we are looking to get away from the SBS self-issued certificate as much as possible. The amount of support related issues around that setup can be eliminated with the addition of a rather inexpensive investment in a third party certificate.

The process for setting up for the certificate is rather straight forward. The Official SBS Blog has a post on the initial part: How to Install a Public 3rd Party SSL Certificate on IIS on SBS 2003.

We create a dummy Web site in IIS, issued the certificate request from there, obtained the certificate from DigiCert, import it into the Intermediate Certification Authorities, and finally imported the certificate via the dummy site's certificate wizard. All of these steps are clearly outlined in the above blog post.

The blog author indicates that a further blog post is forthcoming on installing that certificate into ISA but none appear to be found.

The Configure Email and Internet Connection Wizard (CEICW) does have the ability to import a third party certificate, but it wants a *.cer file that does not seem to work from the many times we tried to get things configured that way.

So, that left us in a quandry: How do we get that certificate tied into ISA.

Having a little understanding as to how the CEICW configures both IIS and ISA together is a really important step to discovering how we need to get that certificate working.

With ISA installed on SBS, the configuration used to keep an end to end SSL tunnel between the user and IIS is called an SSL Bridge (MS TechNet Article).

When the browser requests https://rww.mydomain.com/remote and an SSL tunnel is established, ISA actually decrypts the tunnel to inspect the packets. ISA then re-encrypts the packets by establishing a subsequent SSL tunnel into the local IIS server.

When we look at the SBS ISA and IIS SSL setup from the user's perspective we see:

In this bridging setup, the key to realizing how we need to install the third party certificate can be discovered.

It is the Internet facing site that needs that certificate along with OWA, OMA, and direct SharePoint access.

The process is very simple:
  1. On the SBS server open the ISA manager.
  2. Click on the Firewall Policy item.
  3. Double click on any SBS xxx Publishing Rule that uses the SBS Web Listener.
  4. Click the Listner tab.
  5. Click the Properties button beside "SBS Web Listener".
  6. Click the Preferences tab.
  7. Under SSL: Click the Select button.
  8. The new third party certificate should be one of the available ones, click on it.
  9. OK.
  10. Apply & OK.
  11. Double click on the SBS Windows SharePoint Services Web Publishing Rule.
  12. Listener tab.
  13. Properties button.
  14. Preferences tab.
  15. Select button
  16. Choose the correct certificate as above.
  17. OK.
  18. Apply & OK.
  19. Apply in ISA Manager.
From an external client, connect to the Remote Web Workplace and view the certificate. It should reflect the newly installed third party certificate. Connect directly to the SharePoint Companyweb site: https://rww.mydomain.com:444/ and verify the certificate there.

An important note regarding SSL wildcard certificates: For Outlook 2003/2007 clients using Outlook Anywhere (RPC/HTTPS), the msstd:rww.mydomain.com setting in Outlook needs to be changed to: msstd:*mydomain.com in order to avoid this:


Microsoft Office Outlook

There is a problem with the proxy server's security certificate. The name on the security certificate is invalid or does not match the name of the target site rww.mydomain.com.

Outlook is unable to connect to the proxy server. (Error Code 0)
Some helpful links:
Now that we have discovered the process order and configuration steps, we are migrating all of our clients over to third party certificates.

Managing our client's SSL certification needs is one small service addition we have made to our managed services portfolio.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Friday, 1 August 2008

DigiCert Gets our vote for wildcard SSL certificates

In our search for a wild card SSL certificate (previous blog post), we looked into a large number of SSL providers.

While all providers will provide us with a *.mydomain.com wildcard SSL certificate, only DigiCert gives us the option to tag the certificate with Subject Alternative Names.

What does that mean? That means that we can setup our certificate to look somewhat like this:


  • *.mydomain.com
    • mail.mydomain.com
    • rww.mydomain.com
    • oma.mydomain.com
    • mydomain.com
In the case of Windows Mobile 5 devices, having the actual URL of the HTTPS site OMA will use to access Exchange listed in the SSL certificate guarantees that there will be no compatibility issues.

For those of our clients that have multiple SBS sites, or an SBS site with multiple branch offices, the wildcard SSL certificate will make things like Remote Web Workplace and other SSL secured Internet facing services simpler to access and manage.

Their price includes as many sites and servers needed. There is no price augmentation for additional sites, servers, or reissued certificate requests. The price is the price is the price! ;)

When we placed our order for a wildcard certificate, we heard back from DigiCert by phone within a couple of hours. Some questions needed to be answered to confirm our company's identity before the certificate release would happen.

Finally, their Web management interface is very straight forward to operate when requesting or managing our certificates.

For us SBSers, DigiCert is definitely a company to look at for your wildcard SSL needs.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Tuesday, 1 April 2008

SBS Premium - ISA Client Firewall Icon

Sometimes it can be difficult to communicate just what the ISA Client Firewall Icon looks like when phone based troubleshooting with a client.

ISA Client Firewall Icon on the right

The icon to the left of the ISA icon is the Windows Vista Sync Center icon indicating that it is currently up to date and happy with the UT connected to the workstation.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Monday, 17 March 2008

SBS Premium + ISA = You have received an e-card?!?

On the F-Secure Weblog, we have the following article: From SMTP to HTTP to FTP where Mikko talks about the e-card spam evolution.

What Mikko is indicating to us, is that the spammers now send us to a page that will have a link to the virus file via FTP. Note the file link revealing that it is an executable file on an ftp://... at the bottom left of the Hallmark card:

We all love those Greeting Cards! ;)

So, our Favourite User clicks on the link and voila ... they get?

Well, on a vanilla, out of the box SBS 2003 Premium install with ISA 2000/4 installed and configured via the Configure Email and Internet Connection Wizard (CEICW), the user gets absolutely nothing ... zippo ... nada ... and we get a support call from Favourite User wondering why they cannot get their greeting card. ;)

The FTP protocol through the ISA server is disabled by default. We do not enable FTP unless the client specifically needs it for Web site development access to their site root. In some cases, we have a scheduled time to turn FTP access on for our client's site coders when they will be working directly on their sites. We then disable the Rule when they are done.

It has been a long time since we have had a client request FTP access for something other than Web site coding. So many software sites use HTTP for data transfers now that FTP has become something of a special need in our experience.

This situation is a good example of why we have a 95% install base of SBS 2K3 Premium at our client sites.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Friday, 12 October 2007

SBS Premium - ISA - Creating a Work Hours Internet Site Restriction Policy

Almost all of our clients have an Acceptable Use Policy (AUP). The AUP outlines what one can and cannot do with company equipment and Internet access while in the office or out.

One of the requests we get is to place a restriction on which Internet sites that users would commonly visit during working hours or at all.

In ISA 2004, we would do the following:

  1. Open the ISA Management Console
  2. Right click on Firewall Policy -->New --> Access Rule
  3. We call them Workhours Deny
  4. Rule Action: Deny
  5. Selected Protocols: HTTP, HTTPS, MSN Messenger
  6. Access Rule Sources: Internal & Local Host
  7. Access Rule Destination: Add
    1. New: URL Set
    2. Name: Workhours Deny
    3. Add: http://*.rad.msn.com/*
    4. Some sites at the bottom of this post.
    5. OK
    6. Click on + beside URL Sets and double click on "Workhours Deny"
    7. Close
  8. Next
  9. All Users -->Next
  10. Finish
  11. In the ISA Console, double click on the Rule before clicking Apply in there
  12. Click the Action Tab: Tick "Redirect HTTP requests to this Web page:"
  13. Click the Schedule Tab
  14. New button
  15. Name ClientName Workhours and set the active times.
    • We set 0800 to 1800 for the times as a rule for all 7 days.
  16. Click OK
  17. Click Apply and OK in the Workhours Deny Properties window
  18. Click Apply and OK in the ISA Console.
Once the above is done you will end up with a policy that looks something like this in the ISA console:

During the working hours specified, if the user tries to connect to the Web sites that are listed in the Deny List, they will be greeted with the following:


Here is a partial list of sites that we tend to restrict out of the box as part of the SBS Premium setup:

Any site that would essentially waste a user's time or open the network to possible compromise would normally make the list.

In almost all cases, most people figure it out and there is not a problem. Once in a while a little more is needed, so with the Client Contact's approval, a simple email with a screen shot of an ISA report showing the user name and sites being visited is sent to the problematic user. This usually kills the behaviour immediately.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Thursday, 11 October 2007

SBS Premium - SBS Post Install ISA Rule Must Do for DHCP

The reason that brought us to the aformentioned Mr. Client's location was a complaint that some machines were no longer able to connect to the network.

The possibility of a switch failure drew us to bring an extra Gigabit switch with us as we have seen switch failures before.

It turned out that we needed to create a special rule in ISA for client machines that have lost their IP completely and now had a 169. address.

The rule looks like the following:

Access Rule: DHCP (reply) & (request) via Internal and Local Host

Note that the Listener is set for only the Internal and Local Host interfaces. We don't want the DHCP rule to access the Internet NIC.

To create the rule:
  1. Open ISA Manager
  2. Right Click on Firewall Policy --> New
  3. Click on "Access Rule"
  4. Call it 169 DHCP Access or the like [Next]
  5. Allow [Next]
  6. This rule applies to: Selected Protocols
  7. Add Button
  8. Infrastructure: DHCP (reply) and DHCP (request)
  9. Close and Next
  10. This rule applies to traffic from these sources: Internal and Local Host [Next]
  11. This rule applies to traffic sent to these destinations: [Add Button]
  12. Network Sets: All Networks (and Local Host)
  13. Close and Next
  14. All Users [Next]
  15. Finish
  16. Apply and OK in the ISA Manager
Your now complete rule will look like the above pictured ISA Firewall Policy that is highlighted.

Doing a release and renew will allow the client computer to now connect.

The reasoning as we understand it can be found in a previous post: SBS 2K3 Premium - All Editions, ISA, and DHCP on SBS.

This particular SBS Premium box was installed last year during a run of large installs and apparently we missed this step during setup and the DHCP issue didn't rear its head until now!

The importance of this Firewall Rule being there on Premium boxes is the reason behind this post. :D

UPDATE 2007-10-12: Image of ISA if one tries to add the broadcast address to the Internal Range:


It does not seem to work.

The default ISA Internal does include the full subnet though:


But only for that particular IP range.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

SBS Premium - Rootkit, Backdoor, Trojan ... Panic...

Ever had one of these?

Too many long nights and early mornings were partially to blame for the precipitation of a sense of panic that ensued when the following was seen in ISA's live query:


ISA: Unidentified IP Protocol: Source Port 1175, Destination Port 5571

So, a quick search for the destination port of 5571 turns up: Trojan "Lamer Variant".

The next step was to figure out what the program/service was and where it was.

The inital PortQry using the GUI version turned up (unknown service) for the sending port of 1175. That was not too encouraging.

SysInternals' Process Explorer was also turning up nothing out of the ordinary.

The next step was to run the SysInternals Rootkit Revealer. After 45 minutes of scanning - this particular server has huge arrays - nothing out of the ordinary seemed to be there. The scan kept on going with nothing to show for it.

The Symantec A/V on the server was up to date and running with no indications of any interference.

By now, the panic has set in, and the thoughts swirling around were along the lines of, "Mr. Client, we need to perform a Swing Migration in the next 5 minutes." Not really a bad thing given they have a secondary AD server that also has the arrays mirrored. Or is it? With the possibility of rootkit infection, we may be pulling just the data from backups.

Mr. Client's reaction would probably not be too happy. :(

So, as a final effort before having to consider the above meeting, a full port analysis was needed - just in case.

In the command line PortQryV2 directory the following was done:
  • portqry -local -l serverlog.txt [Enter]
This command runs a full query of absolutely everything on the local machine that is related to ports and services on those ports.

After the serverlog.txt file was created, we opened it in NotePad, and did a find for 1175 to see if anything came up and low and behold:

Process ID: 2476 (javaw.exe) on UDP Port 1175

Bingo. Open the Task Manager and shutdown the javaw.exe service, and the UDP errors in ISA disappeared.

Java is required for the Intel Management software that runs on the server. We had updated it during the last update run last week on that particular SBS box. So, something has changed in the program.

The DNSStuff.com report for the IP:
Reverse DNS for 229.111.112.12
Details:
strul.stupi.se. (an authoritative nameserver for 229.in-addr.arpa., which is in charge of the reverse DNS for 229.111.112.12)
says that there are no PTR records for 229.111.112.12.

A Whois for the mentioned .se server turned up Switzerland with no details. Not sure what Java is up to there.

For now, we will leave Java running, but not allow the UDP communication to pass through ISA to that 229 IP. We may even place a full ISA application restriction against it just in case.

After all of that, a huge sigh of relief and a little Irish kick! We got to smile and say, "Good day" to Mr. Client on our way out. ;)

UPDATE 2007-10-12: One thing that wasn't considered was searching for the actual IP listed. It seems that the IP is drawing people to the blog via search.

A question on Experts Exchange: Possible Hacker 229.111.112.12 mentions that the IP address may be an internal "Multicast" IP for the 229/8 range.

It would possibly explain why the Destination Network in ISA was Internal and the Source was the Local Host. It would also explain why there were no rDNS PTR records for the IP.

From the Internet Assigned Numbers Authority we have the following document: Internet Protocol V4 Address Space that indicates:

229/8 Sep 81 IANA - Multicast
Personally, this is not one of my strong points. So, please feel free to comment on whether this is the right direction or are we barking up the wrong tree?

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Thursday, 4 October 2007

SBS - ISA 2K4 - New ISA Client Edition Available

There is a new version of the ISA Client Firewall that has been released today:

Please make sure to update your technician thumb drives and SBS Premium installations with the new file. This will be especially important for new Vista installs on SBS infrastructure that has or will be RipCurled (previous blog post).

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Wednesday, 26 September 2007

SBS - ISA 2K4 - Publishing a DNS Server behind ISA

When we did our very first SBS 2K to SBS 2K3 Premium upgrade for one of our Internet facing clients who have their own little Web farm and Internet DNS settings, it was a lot of "fun"! :(

This is what we found in the ISA 2004 help file for publishing their DNS servers:
Publishing DNS servers

ISA Server does not translate the IP address of DNS servers. To publish a DNS server, configure a route network relationship between the Local Host network and the network that includes the DNS server. Similarly, ISA Server must know the IP address of the DNS server.
Um, huh?!?

We ended up having to call the Partner Support line and work with the ISA troubleshooting team for hours upon hours spanning days. Eventually, while on the phone with a Microsoft tech, we actually figured it out. And, guess what? The answer was just too simple.

  1. Create a Server Publishing rule
  2. Call it DNS Publishing or the like
  3. Assign the DNS Server's internal IP
  4. Assign the DNS Server protocol

  5. Select the External Network
  6. Click Finish
  7. Click the Apply button in the ISA console
  8. OK
That experience over a very poorly written Help File entry was an incredible amount of frustration for us! It was even more so because we had a number of SBS 2K3 Premium migrations with Web farms behind them waiting on us to do after that.

Truly, it must have been a real pain point because Microsoft actually published a KB article about it: How to publish a DNS server in Internet Security and Acceleration (ISA) Server 2006 or in ISA Server 2004.

When publishing any form of manual for users, it must be "User" tested. It must pass the, "My mom can read and do it" test. The language must be simple and bullet proof. All of the bases need to be covered. If we professionals can't read and understand whatever was written in the manual or Help File in the first place, then we can sure as heck count on the phone to be ringing with our users calling us for clarification.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Wednesday, 5 September 2007

Workbench Update Bandwidth Saver - ISA 2000

A while back, Susan Bradley mentioned a service called AutoPatcher: AUTOPATCHER TOLD TO CLOSE UP.

To be honest, we did not realize that there was even a need for this type of service! Who was to know that in certain parts of the world, bandwidth is paid for on a per bit basis!

With that realization, we can see why AutoPatcher would be totally relevant.

In our case, we have a workbench server setup that mitigates our bandwidth costs by caching updates locally. It is also isolated from our internal network.

The workbench servers used to run on two VIA EPIA miniITX boards crammed into an old Compaq case with a couple of tiny power supplies and a couple of laptop hard drives to provide local storage.

Both machines ran Windows Server 2000. One was DC and one was a domain member with ISA 2000 installed on top. Why ISA 2000? Because, in our experience ISA 2004 (we haven't even bothered with ISA 2006) could not come close to caching the content we wanted cached: Microsoft/Windows Updates via the Microsoft Update site.

So, what exactly does this mean for us and our bandwidth costs? Well, for example, we just finished rebuilding three Toshiba Tecra laptops. They were all XP Professional Service Pack 1 versions. We then needed to install Office 2003 Professional on top of that!

Whenever we deal with a machine that is using older media, we have an unpacked XP Service Pack 2 folder resident on the workbench DC. We then have a shortcut in the root of the share:

\\WorkbenchDC01\Company\Microsoft\XP\SP2Unpacked\i386\update\update.exe /passive /forcerestart /n /f

Once the shortcut is double clicked on the machine that is pre-SP2, the SP runs on its own with the reboot happening automatically at the end.

From there, we go to Microsoft's Update Site and upgrade the system to Microsoft Update right away. A reboot later and we are on to all of the critical and optional updates to download and install.

Any guesses on the volume of data needed to update each of these laptops' Windows install only as of this blog post?

At last count, it was in the neighbourhood of 210MB on the first run of critical and optional updates! Never mind Office 2003 Service Pack 2's additional 102MB. That would be a combined total of close to 1GB for the three machines first run! There were more to come after that.

When we work with situations like this often enough, we hit close to 95% of all updates cached locally in ISA 2000. The subsequent updates, as well as the Office Service Pack are also cached locally. When we have multiple units to run updates on without any updates being run lately, we always let one run through first to catch any new updates into the cache. From there, the rest of the units will pull from cache.

Do them at the same time, and they all will pull from the Web and thus cost us extra bandwidth and time.

In the above situation, all three laptops were running their post download update install routine within a short period of time.

Recently, the workbench VIA EPIA W2K DC had its hard drive blow up. So, we moved everything into a virtual setup on one box.

Here is what we did for hardware:

  • Intel D945GTP Main Board
  • Intel Pentium D 950 3.4 GHz
  • 3GB Kingston DDR2
  • 320GB Seagate RAID 1 (Software)
  • 10/100 Built In NIC
  • Gigabit D-Link DGE-530T
  • Gigabit D-Link DGE-530T
  • Antec Minuet 300
And the software to do it:

  • Windows Server 2003 (Host)
  • Windows Server 2000 Standard x 2 (Guests)
  • ISA 2000 (member server)
Memory for the virtual machines is set to 512MB each. The DC has a dynamic VHD of 72GB and is currently using all of 3.4GB. The member server has 2 VHDs attached: One is a dynamic 72GB for the OS and ISA install and is using 3.0GB while the second is a dynamic 120GB that is using 1.5GB.

ISA 2000 has the following cache settings:


The "Less frequently..." lets the objects sit in the cache longer. Thus, we have those updates staying put instead of being pulled from the Microsoft download site.


There is 75GB available to ISA to cache updates. So far, it is holding about 1.5GB.

The 3 NICS are physically setup in such a way as to isolate the workbench setup as follows:
  • Gb NIC 1: Internal IP for Virtual Server and VM management - No VMs attached.
  • Gb NIC 2: Static IP 192.168.x.x is bogus but plugged into the Workbench Gigabit Switch (File & Printer Sharing off).
  • Mb NIC 3: Static IP 192.168.x.x is bogus as it is plugged into the Internet (File & Printer Sharing off).
The workbench VM DC and ISA box both share NIC 2 for "internal" connectivity to the Gigabit switch that we connect any machines we need to run updates on or keep isolated due to some sort of infection. The ISA 2K VM also has a second virtual NIC that is tied to NIC 3 and pulling an IP from our ISP.

We have had great success with this arrangement as well as the previous VIA based one. Due to that success, other than our endeavouring to get ISA 2004 to do the same thing and failing a few years ago, we are leaving things status quo.

Some of you may have a similar arrangement, or know whether ISA 2004 or 2006 in their current iterations would actually accomplish what we are doing with ISA 2000. Is it possible? If so, please feel free to let us know.

And to our friends in Australia, we do hope that you will be able to utilize this kind of setup to facilitate a huge reduction in your bandwidth overhead. It works for us.

UPDATE: 2007-09-22: A sample update run on multiple HP systems:
  • HP Pavilion a605x with XP Pro 32bit SP2 OLP fresh install
  • Update to MS Update = Reboot
  • Update run 1: 202MB includes Critical+Optional+3 hardware
    • Total download time for 202MB: 8 minutes (keep in mind the age of these machines)
    • Install of 202MB including IE7: 31 minutes
  • Update run 2: 43.2MB includes Critical+Optional+1 hardware
    • Total download time for 43.2MB: 3 minutes
    • Install time: ~10 minutes (keep in mind the large .NET updates)
  • Update run 3: 8.8MB (.NET 1.1 SP1)
    • Total download time: less than a couple of seconds
    • Install time: ~2 minutes
Total time spent on updating all of these machines: ~54 minutes plus a little time for setting them up and taking them off of the bench. Our client's site has the rest of the installs setup to deliver the balance of the needed software via Group Policy Software Install. So, we will let WSUS take care of the balance of updates post domain install.

For Windows Vista Business and Ultimate systems that we have received from our System Builder, they seem to be always up to date. Every time we run Windows Update, upgrade the Windows Update Service to Microsoft Update, there are usually no updates to apply.

We will make a point of visiting them to see just how they do all of that since our OPK/OEM Preinstall requirements and experiences are virtually nil.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Wednesday, 29 August 2007

SBS - SBS Security and a Linux comparison

In all of our conversations with Linux gurus or guru wannabees, we can ask a simple question (keep in mind that we deploy 98.5% SBS Premium): You get your best tools, and we can sit down together and watch them try to work on our SBS Premium box with ISA setup and configured properly. With ISA SP3, we will be seeing a sea of red - that is denies!

ISA is more than a software firewall! Check out isaserver.org for more info. It is one of the best ways to manage data coming in or leaving the SBS network ... period. This is one of the main reasons why we pretty much only deploy Premium Edition of SBS. For a few extra dollars, the client gets an enterprise level of protection and user/software access management.

We have clients with Internet facing SBS Premium servers hosting email and providing HTTP filtering for Server 2003 Web Edition farms that have been running trouble free for years now. We have yet to see a successful attack.

For SBS standard, it is not much different since the built in firewall service is configured by the CEICW to only allow the requisite ports opened for SMTP and Remote Web Workplace access. The built in firewall cannot be as finely tuned as ISA, but it will provide that extra layer of protection over a firewall/router/gateway that should be protecting that SBS Standard box.

One should always use the native Remote Web Workplace connectivity to manage your SBS boxes. This further reduces the server's exposure. It gives you SSL protection for your management access without the risk of opening the 3389 port for Terminal Services.

The principle, as far as Linux is concerned, is having so many services running on one box. This is because of the way Linux operates. Each SBS like component, email like SendMail or QMail, Squid for firewall and proxy, Apache for web based services, SSH for remote management and connectivity, MySQL for databases, PHP for scripting and environments, Samba for sharing data files and folders across the internal network, and more all present an attack vector for someone to try and crack their way into the system.

Just the patch management alone on this kind of Linux setup would be a huge undertaking. Each server application product presents a different Web site or newsgroup that one would have to monitor for updates! Nevermind the conflicts that could arrise with all of these services installed on one box.

Small Business Server is not like that. Microsoft in the guise of the SBS team took a lot of time to make sure that each component of SBS plays nice together. They took the time to make sure that there would be a reduced attack vector by presenting what is essentially one secure and united front for access to the server: Remote Web Workplace. This front has a few facets in that VPN and Outlook Web Access can also be dialed in for access to data and email respectively. But, we are still presented with one way in: Through an SSL secured portal that requires us to authenticate BEFORE we get any further.

That is what a Linux person will not understand without sitting them down in front of the server's console and showing them point by point how things operate on a SBS box. Then we would let them watch the live traffic monitoring feature in ISA to gain an understanding of just how tight things run on SBS.

That in a nutshell, this late at night, is an off the top of the head run down of what is said to the Linux people we come across who protest the SBS configuration.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Wednesday, 15 August 2007

SBS Premium - SBS ISA Rule for Remote Management Needed

For those of us who have SBS Premium internally and manage client SBS servers, the following is an important manually created rule for allowing the 4125 RDP proxy port out:


If one does not create this rule, there is no RDP connectivity allowed out of the internal network to any external SBS server's RWW based RDP session.

For clients, this is no big deal, but for those of us who manage SBS networks, it means not being able to connect to remote SBS and XP Pro/Vista Business desktops via RWW proxied RDP.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

SBS Premium - SBS ISA publishing defaults

Out of the box for SBS 2K3 Premium and SBS 2K3 Premium R2 ISA runs the CEICW when it is installed.

This is a screen shot of the default rules created out of the box by the ISA CEICW:

Sometimes it is good to have a quick reference when mucking about with those settings! :D

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.