Internet Connection Firewall and multi-homed NIC

G

Guest

Hi

I´ve got the following problem

PC running XP Pro with one NIC and two IP-Adresses bound to that NIC. I cannot use just one address due to some non-MS services running on that machine

I enabled the ICF for that NIC and added manual entries to the services tab with different IP-Addresses/DNS-Names for the two IP-Addresses bound to the NIC

eg

193.111.111.1 TCP-Port 111
193.111.111.2 TCP-Port 111

I cannot make any connections to the ports bound to the secondary address. I allowed an ICMP echo. It works on both IP-Addresses

I also tried to bind the needed port to 127.0.0.1. Still no success

Is there any way to configure it like this. I would like to gain the additional security of the ICF, although using another firewall on a seperate machine

J. Rusch
 
C

Curtis Koenig [MSFT]

Hi J.,
Unfortuantly ICF at this time does not allow this functionality. Its either
all or nothing on a card, it is not configurable by bound IP address.
--
Curtis Koenig
Support Engineer
Product Support Services, Security Team
MCSE, MCSES, CISSP

This posting is provided "AS IS" with no warranties and confers no rights.
Please reply to the newsgroup so that others may benefit. Thanks!

--------------------
From: "=?Utf-8?B?SiBSdXNjaA==?=" <[email protected]>
Subject: Internet Connection Firewall and multi-homed NIC
Date: Sun, 25 Jan 2004 05:21:04 -0800

Hi,

I´ve got the following problem:

PC running XP Pro with one NIC and two IP-Adresses bound to that NIC. I
cannot use just one address due to some non-MS services running on that
machine.

I enabled the ICF for that NIC and added manual entries to the services tab
with different IP-Addresses/DNS-Names for the two IP-Addresses bound to the
NIC.

eg.

193.111.111.1 TCP-Port 1111
193.111.111.2 TCP-Port 1111

I cannot make any connections to the ports bound to the secondary address.
I allowed an ICMP echo. It works on both IP-Addresses.

I also tried to bind the needed port to 127.0.0.1. Still no success.

Is there any way to configure it like this. I would like to gain the
additional security of the ICF, although using another firewall on a
seperate machine.

J. Rusch
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top