Networking Forums

Networking Forums > Computer Networking > Windows Networking > Editing Windows firewall ruleset for 2003 Std ?

Reply
Thread Tools Display Modes

Editing Windows firewall ruleset for 2003 Std ?

 
 
Paulo
Guest
Posts: n/a

 
      08-18-2005, 03:39 PM
I have an application that sends http request packets to a microsoft
loopback adapter on 172.31.1.1 (not 127.0.0.1 ), the response is then
sent out via the main interface on 172.31.1.2. The application is
actually an external loadbalancer doing low level MAC re-writing and
needing the answering machine to accept the IP address of 172.31.1.1.

This works perfectly until I turn on the windows firewall. I've
configured both the loopback and external interface to accept
connections on port 80 and can connect and get responses from both
ports on the command line. I found and used the microsoft netsh tool to
turn on logging for the firewall and found that the response packets
are being dropped on their way back out to the calling IP. So the
loopback is still recieving them and IIS is dealing with them and
sending them out through the external interface. The firewall is then
dropping them, I assume for spoofing.

The message in the firewall log is

DROP TCP 172.31.1.1 123.123.123.123 80 dest etc

So I think the firewall is dropping the outbound packets because they
are pretending to originate from the loopback IP but coming from the
external interface.

My question is how do I set the firewall to allow outbound packets on
ther external interface but from the IP of the loopback. The critical
thing is that I can't add the loopback IP to the external interface
because I need it to not respond to ARP requests while the main IP
should respond to ARP requests. The only way I know of to do this is to
have them on different interfaces.

thanks in advance

Paul
--
PrintWhatYouThink - Slogan tshirts for the individual
http://www.printwhatyouthink.co.uk/

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
FTP Timeout Issue on Windows 2003 SP1 with Windows Firewall Sean Stromberg Windows Networking 0 02-13-2006 07:27 PM
firewall windows server 2003 rudolf Windows Networking 1 09-24-2005 03:33 PM
FTP PASV for Windows Server 2003 SP1 Windows Firewall Yoshihiro Kawabata Windows Networking 0 09-12-2005 06:08 PM
Windows 2003 Firewall Sebas Windows Networking 0 07-12-2005 03:33 PM
Windows Server 2003 SP1 - Windows Firewall / IIS - HTTP Stefan Alkman, Precio AB - Sweden Windows Networking 0 07-06-2005 02:28 PM



1 2 3 4 5 6 7 8 9 10 11