Ask a questionAsk a question
 

AnswerSite to Site VPN not passing traffic on port 80

  • Friday, June 05, 2009 3:48 PMRussSc Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    Hi,


    I currently have configured a site to site VPN to a 3rd party hosting some web servers for us

    Although i have configured ISA to pass all traffic types across the VPN tunnel ISA does not appear to pass traffic on port 80 ( although i can connect to a telnet session on port 80 )

    All other traffic types appear to route correctly ( ie 443 )



    I have followed advice with regards to setting up a 2nd HTTP protocol that does not apply the Web proxy filter and denied the use of the original HTTP protocol for this firewall rule

    Although this does not seem to have had the desired effect


    ISA returns an error 10065 A socket operation was attempted to an unreachable host on monitoring with the additional information below :

    • Client agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10 (.NET CLR 3.5.30729)
    • Object source: Internet (Source is the Internet. Object was added to the cache.)
    • Cache info: 0x0
    • Processing time: 62969 ms
    • MIME type:
    can anyone advise ? .. has anyone seen this in thier environment?

    Kind Regards

Answers

  • Wednesday, June 10, 2009 2:31 PMRussSc Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    Turns out I needed to add both external facing IP addresses of the ISA servers to the remote end of the tunnel and not just the virtual IP address

    Thanks anyway !

All Replies

  • Sunday, June 07, 2009 7:05 AMKeith AlabasterMVP, ModeratorUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    Not totally sure why port 80 would be treated differently to port 443. Are you convinced that the ISP/hosting company is not blocking anything at their end?
  • Wednesday, June 10, 2009 2:31 PMRussSc Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    Turns out I needed to add both external facing IP addresses of the ISA servers to the remote end of the tunnel and not just the virtual IP address

    Thanks anyway !