Networking Forums

Networking Forums > Computer Networking > Windows Networking > RRAS outbound filter not working

Reply
Thread Tools Display Modes

RRAS outbound filter not working

 
 
Kenneth Porter
Guest
Posts: n/a

 
      08-19-2006, 09:33 AM
System is Windows Server 2003.

I want to use the RRAS outbound filter to limit web access for selected
clients.

I have two NIC's, one Internet-facing configured in RRAS for NAT and one
LAN-facing. DHCP assigns reserved addresses to all LAN clients based on
MAC. I group "Internet-allowed" clients in one net block and the rest in
another. The internal network in 10.44.0.0/16. Allowed clients are in
10.44.7.0/255.

Outbound filters is set to "Drop all packets except those that meet the
criteria below". I have 3 outbound filter rules:

10.44.1.0/24 to any (allow server access to Internet)
10.44.7.0/24 to any (allow privileged clients access to Internet)
192.168.1.0/24 to any (allow outbound NIC access)

I tried to add a rule to allow other stations access to Microsoft for
Windows Updates but they lose all access, including to MS, when I move
them out of 10.44.7.0/24.

any to 207.46.0.0/16

(I attempt to ping to a known update.microsoft.com address within this
block and I just get a timeout. Telnet to port 80 also times out with no
connection, in case that server ignores pings.)

My feeling is that the RRAS snapin is showing the correct rule, but it's
not getting installed in the actual packet filter. I recall having a
similar problem 2 years ago when I first set this server up and I had to
delete all RRAS settings and recreate it from scratch to add a new filter
rule. Are there known issues "pushing" rules down into the kernel?

My own router is a Linux box and I'm very comfortable with the
flexibility and logging of iptables. I'm regretting chosing Win2003 for
this client as the GUI does not make things easier. It just makes
failures harder to diagnose.
 
Reply With Quote
 
 
 
 
Oliver O'Boyle
Guest
Posts: n/a

 
      08-21-2006, 08:47 PM

> I tried to add a rule to allow other stations access to Microsoft for
> Windows Updates but they lose all access, including to MS, when I move
> them out of 10.44.7.0/24.
>
> any to 207.46.0.0/16


what IP address and mask are you using for "any"

Oliver

>


 
Reply With Quote
 
Kenneth Porter
Guest
Posts: n/a

 
      08-30-2006, 02:08 AM
"Oliver O'Boyle" <(E-Mail Removed)> wrote in
news:(E-Mail Removed):

> what IP address and mask are you using for "any"


The checkbox for that is left unchecked, so the address and mask columns
report "any".
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
RRAS VPN filter Don Hollick Windows Networking 1 07-12-2007 05:14 PM
outbound smtp from web edition not working MarshMan Windows Networking 1 03-09-2007 07:28 PM
RRAS not working SBS 2003 manuellee Windows Networking 0 08-31-2005 08:52 AM
RRas not working SBS 2003 Manuel Windows Networking 0 08-31-2005 02:13 AM
MN-700 MAC Filter not working... Sender Broadband Hardware 2 08-19-2004 06:53 PM



1 2 3 4 5 6 7 8 9 10 11