Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

ISA Server Firewall Chaining Can Cause Problems with FTP Access


View products that this article applies to.

Symptoms

Application filter functions allow the filters to specify the destination IP address for which a packet filter opens a secondary connection. The FTP application filter uses this functionality to open packet filters only for the IP address of the destination FTP server. This works correctly unless you are using firewall chaining. If you are using firewall chaining, packets that are received on the external network adapter of the downstream Internet Security and Acceleration (ISA) Server-based computer have a source IP address that is not of the FTP server, but is of the internal IP address of the upstream ISA Server-based computer. Therefore, ISA Server drops the packets.

↑ Back to the top


Resolution

To resolve this problem, obtain latest service pack for ISA Server 2000. For additional information about the latest service pack, click the article number below to view the article in the Microsoft Knowledge Base:
313139 How to Obtain the Latest Internet Security and Acceleration Server 2000 Service Pack

↑ Back to the top


Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article.

This problem was corrected in ISA Server 2000 SP1.

↑ Back to the top


Article Info
Article ID : 313343
Revision : 3
Created on : 1/1/0001
Published on : 1/1/0001
Exists online : False
Views : 302