Article ID: 283213 - Last Review: October 26, 2007 - Revision: 4.3 Blocking and Logging Traffic on ISA Server Internal InterfacesThis article was previously published under Q283213 IMPORTANT: This article contains information about modifying the registry.
Before you modify the registry, make sure to back it up and make sure that you
understand how to restore the registry if a problem occurs. For information
about how to back up, restore, and edit the registry, click the following
article number to view the article in the Microsoft Knowledge Base: 256986
(http://support.microsoft.com/kb/256986/EN-US/
)
Description of the Microsoft Windows Registry
On This PageSUMMARY By default, Internet Security and Acceleration (ISA) Server
2000 does not apply packet filtering to the internal interfaces (as determined
by the local address table). If you want to filter traffic on those interfaces,
use the methods that are described in the "More Information" section of this
article. Note The hotfix cited in the "Blocking and Logging Internal Traffic Sent to ISA Server" section of this article is also available in ISA Server 2000 Service Pack 1 (SP1) and later. MORE INFORMATIONWARNING: If you use Registry Editor incorrectly, you may cause serious
problems that may require you to reinstall your operating system. Microsoft
cannot guarantee that you can solve problems that result from using Registry
Editor incorrectly. Use Registry Editor at your own risk. Blocking and Logging Internal Traffic Sent to ISA ServerTo unconditionally block and log all traffic that is sent from the internal network to ISA Server, follow these steps:
NOTE: Setting this registry value disables various ISA Server services such as firewall clients, array functionality, Web proxy listeners, authentication to domain controllers, and so on. You can still use ISA Server as a standalone server that is not a part of any domain, and support complete SecureNAT client functionality. Blocking and Logging Outbound ICMP TrafficTo unconditionally block and log all outbound ICMP traffic that is sent from the internal network to the external network, follow these steps:
NOTE: Setting this registry value unconditionally blocks outbound ICMP traffic and overrides any existing ISA Server settings for ICMP. NOTE: If you are saving a hotfix locally, please be sure to refresh it from the Hotfix servers. NOTE: Although the above note should prevent this, you may see that three redundant values were added to the registry. These will have to be fixed for IIS to work properly. For more information, please see the following article in the Microsoft Knowledge Base: 296638
(http://support.microsoft.com/kb/296638/EN-US/
)
Starting Internet Services Manager May Cause Error Message
| Article Translations
|
Back to the top
