If the packet filtering options provided by the Small Business Server Internet Connection Wizard did not provide a filtering option required for your network, you must create a new IP packet filter using the ISA Management snap-in. Note that packet filters create a static opening in the firewall, and only allow access to the Small Business Server computer, not to clients on the local network.
To create a custom packet filter
- Open ISA Management. (Click Start, and then click Small Business Server Administrator Console. Double-click Internet Security and Acceleration Server 2000.)
- Double-click Access Policy.
- Right-click IP Packet Filters, and then click New. The New IP Packet Filter Wizard appears.
- On the Welcome page, enter a name for the IP packet filter name field.
- On the Filter Mode page, accept the default of Allow packet transmission if you want to permit the traffic; otherwise select Block packet transmission.
- On the Filter Type page, select a predefined filter from the drop-down list. If a predefined filter is not available, select Custom. If you select Custom, you must then enter the protocol used, communication direction, and any filter-specific information on the Filter Settings page.
- On the Local Computer page, accept the default of Default IP address for each external interface on the ISA Server computer.
- On the Remote Computers page, accept the default of All remote computers; otherwise, select Only this remote computer and enter the remote computer's IP address.
- Click Finish on the Completing the New IP Packet Filter Wizard page.
- Restart the Firewall service.
- In the console tree, under ISA Management, double-click Monitoring, and then select Services.
- In the details pane, restart each of the ISA Server services to which the new filter will be applied. Right-click the service, and then click Stop. Once the service is stopped, right-click the service, and then click Start.