Networking Forums  

Go Back   Networking Forums > Networking Newsgroups > Windows Server Networking

RRAS outbound filter not working

Reply
 
Thread Tools Display Modes
  #1  
Old 08-19-2006, 10:33 AM
Default RRAS outbound filter not working



System is Windows Server 2003.

I want to use the RRAS outbound filter to limit web access for selected
clients.

I have two NIC's, one Internet-facing configured in RRAS for NAT and one
LAN-facing. DHCP assigns reserved addresses to all LAN clients based on
MAC. I group "Internet-allowed" clients in one net block and the rest in
another. The internal network in 10.44.0.0/16. Allowed clients are in
10.44.7.0/255.

Outbound filters is set to "Drop all packets except those that meet the
criteria below". I have 3 outbound filter rules:

10.44.1.0/24 to any (allow server access to Internet)
10.44.7.0/24 to any (allow privileged clients access to Internet)
192.168.1.0/24 to any (allow outbound NIC access)

I tried to add a rule to allow other stations access to Microsoft for
Windows Updates but they lose all access, including to MS, when I move
them out of 10.44.7.0/24.

any to 207.46.0.0/16

(I attempt to ping to a known update.microsoft.com address within this
block and I just get a timeout. Telnet to port 80 also times out with no
connection, in case that server ignores pings.)

My feeling is that the RRAS snapin is showing the correct rule, but it's
not getting installed in the actual packet filter. I recall having a
similar problem 2 years ago when I first set this server up and I had to
delete all RRAS settings and recreate it from scratch to add a new filter
rule. Are there known issues "pushing" rules down into the kernel?

My own router is a Linux box and I'm very comfortable with the
flexibility and logging of iptables. I'm regretting chosing Win2003 for
this client as the GUI does not make things easier. It just makes
failures harder to diagnose.


Kenneth Porter
Reply With Quote
  #2  
Old 08-21-2006, 09:47 PM
Oliver O'Boyle
Guest
 
Posts: n/a
Default Re: RRAS outbound filter not working


> I tried to add a rule to allow other stations access to Microsoft for
> Windows Updates but they lose all access, including to MS, when I move
> them out of 10.44.7.0/24.
>
> any to 207.46.0.0/16


what IP address and mask are you using for "any"

Oliver

>


Reply With Quote
  #3  
Old 08-30-2006, 03:08 AM
Kenneth Porter
Guest
 
Posts: n/a
Default Re: RRAS outbound filter not working

"Oliver O'Boyle" <(E-Mail Removed)> wrote in
news:(E-Mail Removed):

> what IP address and mask are you using for "any"


The checkbox for that is left unchecked, so the address and mask columns
report "any".
Reply With Quote
Reply

Tags
filter, outbound, rras, working

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 12:05 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.