Forefront Edge Security - Firewall Client ForumA forum for the discussion of issues and ideas regarding the Forefront Threat Management Gateway (TMG) and the ISA Server Firewall clients.© 2009 Microsoft Corporation. All rights reserved.Mon, 23 Nov 2009 02:10:07 Zec4bef36-0ff8-43bc-b7f1-8c04da36ee96http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/5aab1d34-c034-432e-9c7c-440fa8d26d35http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/5aab1d34-c034-432e-9c7c-440fa8d26d35Pablo Moyohttp://social.technet.microsoft.com/Profile/en-US/?user=Pablo%20MoyoIsa 2006 FW client strange issue with internal web sitesHi, i got an isa 2006 ent with 2 nic, internal 10.x and external with public IP. <br/>All the clients have the Firewall client installed. <br/>I've a DMZ (192.x) but is not directly connected to the ISA machine; the firewall client is configured, with LAT file, to bypass ISA for that range. <br/>All the clients are 99% the same (ghost image, wsus forced update, GPO configuration). <br/><br/><br/>I got a very strange issue with that.... <br/><br/>On some machines all works fine. <br/>On other random machines, i'm not able to browse internal (10.x site) and dmz (192.x) due to time out. <br/><br/>On those machines, if i disable the firewall client service or if i manually configure Internet Explorer (and or Firefox) to use a proxy and putting the exclusion for those sites, all works. <br/><br/>Unistalling and reinstalling the firewall clients on those bizarre machines didn't fix the problem. <br/><br/>Any suggestion/idea ? <br/>Thanks in advance.Thu, 23 Jul 2009 13:38:56 Z2009-11-19T19:31:07Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/33874dba-db3e-467c-8681-efcabb642e51http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/33874dba-db3e-467c-8681-efcabb642e51IT RWBhttp://social.technet.microsoft.com/Profile/en-US/?user=IT%20RWBWindows 7 Forefront InstallationHey,<br/><br/>there is a problem, if I would like to install Forefront on Windows 7. We install forefront with WSUS and a GPO. Windows Server and all Windows XP Clients install the client automatically. If I check the gpresult, I could see the right GPO. But Windows 7 don't install Forefront.<br/><br/>Could anybody help me ?<br/><br/>Mon, 16 Nov 2009 11:47:53 Z2009-11-23T02:10:07Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/ede81bc9-3d27-4536-b7dc-d8b8109b9bb3http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/ede81bc9-3d27-4536-b7dc-d8b8109b9bb3Reza-Shttp://social.technet.microsoft.com/Profile/en-US/?user=Reza-SConfigure ADSL modem in ISA 2004Hi,<br/>I installed ISA and made access roule.I have a ADSL modem and i want to configure PPPOE in ISA.When i go to <br/>preference Dialup ,i dont have any PPPOE connection.So i cant configure it for connectivity to internt.<br/>Thanks,<br/>RezaThu, 05 Nov 2009 20:22:38 Z2009-11-12T08:34:29Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/10317389-b5a2-4637-946f-3d70a074e9dahttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/10317389-b5a2-4637-946f-3d70a074e9dajames2k8http://social.technet.microsoft.com/Profile/en-US/?user=james2k8SVPN not working on ISA 2006 when firewall client is enabledHi,<br/> <br/> I'm trying to get SVPN (Sabre) to work with firewall client on ISA 2006.  Where do I start?Thu, 29 Oct 2009 01:00:51 Z2009-10-30T05:12:11Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/6d3a167d-8ce9-497f-8e1f-fc04c6e4d1a7http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/6d3a167d-8ce9-497f-8e1f-fc04c6e4d1a7Dave502http://social.technet.microsoft.com/Profile/en-US/?user=Dave502MP3 Rocket connectionI am trying to connect to MP3 Rocket to download some more music, but the past 2 days it will not connect. &nbsp;The program says its connecting, but beside the connection progress there is a icon that says firewall detected. &nbsp;I tried to turn off the firewall, but had no luck. &nbsp;If anyone can help me, I would greatly appreciate it. &nbsp;ThanksWed, 14 Oct 2009 15:39:11 Z2009-10-26T02:00:42Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/160791df-f178-4125-825f-05afabac0705http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/160791df-f178-4125-825f-05afabac0705RolanBoyhttp://social.technet.microsoft.com/Profile/en-US/?user=RolanBoyIsa Server 2000 Configuration<p>Hellow guys,</p> <p>&nbsp;&nbsp;&nbsp; I have a problem regarding my Isa server 2000, my setup is like this<br />&nbsp;&nbsp;&nbsp; -&nbsp; I have DC server with DNS and DHCP (domain name is gbdistinc.local) Ip Add &nbsp;192.168.11.245; 255.255.255.0 no Gateway<br />&nbsp;&nbsp;&nbsp; -&nbsp; I have separate server for ISA Server with replicate DNS from main server Ip Add &nbsp;192.168.11.244;255.255.255.0 no gateway primary dns is 192.168.11.245</p> <p>&nbsp;&nbsp;&nbsp; -&nbsp; MY internal IP is 192.168.11.244 and my External is dynamic DSL dial up using PPPOE<br />Problem no1<br />&nbsp;&nbsp; Before ISA server was installed my nslookup to external IP was ok, but when ISA installed this is the result</p> <p>C:\nslookup <a href="http://www.google.com.ph">www.google.com.ph</a><br />Server:&nbsp; gbmainserver.gbdistinc.local<br />Address:&nbsp; 192.168.11.245</p> <p>DNS request timed out.<br />&nbsp;&nbsp;&nbsp; timeout was 2 seconds.<br />*** Request to gbmainserver.gbdistinc.local timed-out<br />&nbsp;&nbsp;&nbsp; <br />Problem No2 <br />&nbsp;when im in Isa Server i can ping external IP, but when i try it to my workstation it doesnt work</p> <p>Problem no3<br />&nbsp;I try to use IP Filters and enable the IP Routing and PPTP, adding new Rule for ICMP to work ping on client.&nbsp; It works but the problem is my pop3 and smtp configuration on Outlook was unable to send and receive email.&nbsp; This problem occur when IP routing was enabled.&nbsp; We have a VPN connection outside the netowrk thats why i need to enable IP Routing and PPTP to work. <br />&nbsp;When IP Routing Enabled and PPTP<br />&nbsp;&nbsp;VPN and Ping work but my outlook did not<br />&nbsp;When IP Routing Disabled<br />&nbsp;&nbsp;Outlook works fine but VPN and Ping did not.</p> <p>Can anyone help my problem.&nbsp; I am new in ISA but i want to use and learn more about it.&nbsp; Is there any problem with my configuration.&nbsp; Thanks</p> <p>&nbsp;</p>Tue, 13 Oct 2009 05:28:16 Z2009-10-13T22:19:23Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/381797ab-998b-4ed3-a4fd-c3ff48cb5809http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/381797ab-998b-4ed3-a4fd-c3ff48cb5809mgranhttp://social.technet.microsoft.com/Profile/en-US/?user=mgranSlowness on opening Office files when Firewall Client installed<p align=left><font face=Arial size=2>Hi, I have a laptop (HP nx7000) with Windows XP SP2 and Office 2003. All the Office aplications work fine, but when I install the Microsoft Firewall Client 2004 and you try to open Word, Excel... or double click on a file it takes around 20 seconds to open it. Once it is open and you do File --&gt; Open it opens the file OK.</font></p> <p align=left>If I uninstall the Firewall Client everything works fine and fast again.</p> <p align=left> </p> <p align=left>Anybody knows how can I fix this? I've searched the internet but couldn't find a solution. This problem is driving me crazy.</p> <p align=left> </p> <p align=left>Thanks in advance.</p>Tue, 11 Mar 2008 10:06:49 Z2009-09-27T10:29:47Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/ba6807a2-3cc7-4041-82a8-0baedb6c321chttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/ba6807a2-3cc7-4041-82a8-0baedb6c321cAmjad_211http://social.technet.microsoft.com/Profile/en-US/?user=Amjad_211Clear Old Data on repor from ISA?<p>Hi<br/><br/>I want to clear old data that appears on the report of the ISA 2006 server- not cache- and the report must appears as tha ISA just satrted. Is this possible??<br/>&amp; If so how can I do that???<br/><br/>Thanx<br/></p>Sat, 28 Mar 2009 12:23:51 Z2009-11-14T20:08:09Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/bb439423-75fb-410a-b618-783fb93256afhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/bb439423-75fb-410a-b618-783fb93256afShahinhttp://social.technet.microsoft.com/Profile/en-US/?user=Shahincertificate questionHi,<br/><br/>we did setup a new domain that called mydomain.local, and has a registerd domain that called mydomain.com.<br/>This domain has an exchange 2007 and ISA 2006, we are going to use the Ex2007 as pop3 server and also for OWA for the mydomain.com (we did add mydomain.com as a accepted domain to the exchange 207), now we have to buy a certificate for use with OWA and ISA 2006.<br/>here is my question,<br/><br/>I went to versian website and there I can get a certificate for 21 days trail, so first they asked I should create a SCR for the Webserver, does this means the IIS of the Exchange 2007? I did try to create an SCR for the exchange 2007 IIS, but as I said before this server has an .local domain, then when I did create the SCR I had to copy the genrated SCR and send it to versain, but when I send it to them I get this error that they can not issue a certificate for intranet (or .local domain I  think!), so what does this live me with? or my internal domain have to be the same as my external domain?<br/><br/>Thanks,<br/><br/>SHahin<hr class="sig">ShahinWed, 16 Sep 2009 13:48:56 Z2009-09-17T07:46:03Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/b0d01993-4eb8-4294-b717-5204f22847fehttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/b0d01993-4eb8-4294-b717-5204f22847feEd Mansfieldhttp://social.technet.microsoft.com/Profile/en-US/?user=Ed%20Mansfieldisa 2006 and blocking web access to port 8443<p align=left><font face=Arial size=2>cannot get past web proxy rule to allow port 8443 as alternate port for ssl.</font></p> <p align=left>Add access rule and web proxy rule still blocks.</p> <p align=left>How to extend ssl to include 443 and 8443?</p>Mon, 12 Nov 2007 23:38:08 Z2009-09-09T03:45:32Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/296f54e5-3f66-4063-9374-86895aa3ef60http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/296f54e5-3f66-4063-9374-86895aa3ef60Amjad_211http://social.technet.microsoft.com/Profile/en-US/?user=Amjad_211Log Write Time excessive on ISA 2006?Hi<br/><br/>I have a warning event appears everyday on my ISA 2006 server says the log write time took approximately 15 seceonds.........!<br/>I tried what said on this article:<br/><a href="http://support.microsoft.com/default.aspx/kb/960925">http://support.microsoft.com/default.aspx/kb/960925</a><br/><br/>But it still happening!!!!!!<br/>Any idea please?<br/><br/>Sat, 11 Jul 2009 07:05:37 Z2009-08-15T01:24:41Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/ed439cde-efd8-4715-b78d-a257ba424fc9http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/ed439cde-efd8-4715-b78d-a257ba424fc9bestqueenaouhttp://social.technet.microsoft.com/Profile/en-US/?user=bestqueenaouQuestion About ISA server 2006I hope every one have a good day <br/><br/>I have question <br/><br/>can  I conect two DC (Domain Controller ) to one ISA server?<br/>Note:<br/>Each DC has different pollicy from another .For example,<br/>I have two DC for two servers first DC for first server and second DC for second server <br/>first one emploee DC for first server ,and LAB DC for second server<br/>becouse, I want to make some pollicy to employee dc differ from LAB dc .like : I want to allow to all employee to see all sites <br/>but I do not want to allow to users in LAB (computer lab) to see all sites from internet <br/><br/>that is right?or can I do it?<br/><br/><br/>thanx Thu, 16 Jul 2009 22:38:59 Z2009-07-23T16:54:04Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/f9ec1cc2-330a-4463-aac3-bd6589db907chttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/f9ec1cc2-330a-4463-aac3-bd6589db907cPronichkinhttp://social.technet.microsoft.com/Profile/en-US/?user=PronichkinWindows Automatic Update client and Proxy Authentication<p>Automaic Updates (AU) is client-side service used by Windows Update, Microsoft Update and Windows Server Update Services (WSUS). It runs in svchost.exe process in Local System context. Obviously, it requires Internet access in many scenarios. My quiestion is: how do I enable proxy authentication for this service?<br/><br/>As far as I know it is neither possible nor supported. The only working way to provide AU client with Internet access is the followintg:</p> <ol> <li>Turn off mandatory proxy authentication (go to Networks -&gt; Internal -&gt; Properties -&gt; Web Proxy -&gt; Authentication -&gt; <strong>uncheck &quot;Require all users to authenticate&quot;</strong>).</li> <li>Create a Firewall rule that allows HTTP and HTTPS traffic from AU client computers to your update services <strong>for &quot;All Users&quot;</strong>.</li> <li>(Optional) Use &quot;Authenticated Users&quot; or even more restrictive groups for all other Firewall rules if you want authenticate as many connections as possible.</li> </ol> <p>I am pretty sure this is the only possible solution though I'm not very happy with it. But recently I found some very confusing information.</p> <ul> <li><a href="http://www.freelists.org/post/isalist/Automatic-Updates,24">This</a> <a href="http://www.freelists.org/post/isalist/Automatic-Updates,18">thread</a> in a mail list archive. Some users there reported their AU clients actually authenticated as domain computer accounts (DOMAIN\Computer$).</li> <li>A couple of my friends (also very experienced ISA administrators) confurmed they have AU clients successfully authenticating and they performed no special manual configuration steps for it. They said it is native functionality of Firewall Client.</li> </ul> <p>But as far as I know, FWC purpose is to authenticate user currently logged on to workstation, but not system services running in Local System context. So this sounds very confusing to me and I'd love to find some clarifications.<br/><br/>Thanks in advance</p>Sun, 28 Jun 2009 10:38:50 Z2009-07-01T17:47:42Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/dd524a66-6bcd-40c6-b847-ecca33e83b26http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/dd524a66-6bcd-40c6-b847-ecca33e83b26andrewcrystalhttp://social.technet.microsoft.com/Profile/en-US/?user=andrewcrystalISA 2000 Filter questionHi all, <br/> <br/> We have had our SBS server in for many years now and it is all running very smoothly. <br/> <br/> However, we recently installed some new Health and Safety software that does automatic updates, to do this we installed a database server on our server then a liveupdate programs on one of the client machines.  The update program uses port 2069 so I did what I thought would open the port correct to let the program access the net. <br/> <br/> Custom Filter <br/> Direction: Inbound <br/> Local Port Fixed <br/> Port Number: 2069 <br/> Remote Port: All Ports <br/> <br/> This wouldnt work but we thought it was perhaps that the program wasnt setup to use the proxy server so we added that in and it appears to be using that.  However, whatever we do I cannot get the update program to access the internet and the developers say they do not know enough about ISA to understand why it is not working. <br/> <br/> Any help would be greatly appreciated as I have tried everything I can think of (including altering the filter settings above to other options - possibly not the right ones mind! lol). <span class=info> </span> <div></div> <table border=0 cellspacing=1 cellpadding=1 width="100%"> <tbody> <tr> <td> </td> <td align=right></td> </tr> </tbody> </table>Tue, 16 Jun 2009 10:01:13 Z2009-06-17T18:02:02Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/00d0eec8-1272-4e79-a064-ad4b862dfddfhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/00d0eec8-1272-4e79-a064-ad4b862dfddfJim Harrison IsaDewdhttp://social.technet.microsoft.com/Profile/en-US/?user=Jim%20Harrison%20IsaDewdNetwork Monitor 3 Gets a Parser for the Firewall Client!<a href="http://blogs.technet.com/isablog/archive/2009/06/04/fwc-parser-for-netmon-3-3-on-codeplex.aspx">http://blogs.technet.com/isablog/archive/2009/06/04/fwc-parser-for-netmon-3-3-on-codeplex.aspx</a><br/><br/>Go Get Some!<br/><hr class="sig">Jim Harrison Forefront Edge CSTue, 09 Jun 2009 20:49:12 Z2009-07-01T18:09:07Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/e0d1fa1e-23a1-4b12-852c-8a295fa27963http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/e0d1fa1e-23a1-4b12-852c-8a295fa27963Michael C. Neelhttp://social.technet.microsoft.com/Profile/en-US/?user=Michael%20C.%20NeelRunning a Windows Service behind ISA FirewallI'm not sure this is the correct forum, but hopefully I can get pointed in the right direction.<br><br>I have a custom windows service (.Net 3.5) that FTPs files out to some servers across the internet.  The server hosting my service (Windows 2003) is behind an ISA firewall, and I need to connect through this proxy to transfer the files.<br><br>I had installed the ISA Firewall Client and all seemed well.  The service (which runs under it's own domain level account) was able to FTP out okay.  I even logged out of the server and started the custom service remotely to make sure there wasn't anything special about me being logged in that made everything work (my Infrastructure team tells me the server is okay to use the ISA proxy, and it's not account based).<br><br>Only there was.<br><br>It seems the ISA client cached me being logged into the server and allowed the service to FTP without issue for about a hour or so before it started getting denied.<br><br>I've been searching the net and docs trying to find guidance on how to configure ISA Server and Client to allow a Windows Service to use the ISA Firewall Client while no one is logged in, but so far nothing.  Any help or guidance is greatly appreciated - even if it's &quot;idiot, you use X for this&quot; cause I'm having to make this stuff up as I go!<br><br>Thanks,<br>Mike  <br>Tue, 17 Mar 2009 19:54:11 Z2009-06-06T17:30:56Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/1d19cbb8-b38c-4931-a933-cfc09203dd1fhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/1d19cbb8-b38c-4931-a933-cfc09203dd1fNetSecurityhttp://social.technet.microsoft.com/Profile/en-US/?user=NetSecurityfirewall client for mac ? hello.<br><br>Is there any firewall client for MAC computers ?<br><br>Fri, 26 Sep 2008 11:45:00 Z2009-03-28T07:19:49Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/654d06f3-b86b-486c-82f2-ef14fd1d35ebhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/654d06f3-b86b-486c-82f2-ef14fd1d35ebAmjad_211http://social.technet.microsoft.com/Profile/en-US/?user=Amjad_211ISA 2006 & Special NATHi <br><br>I want to setup a special NAT on ISA server 2006 standard that allows a dedicated client to go out with IP address that is not the external IP address of the ISA. Is this possible??????<br><br><br>Wed, 25 Mar 2009 15:11:20 Z2009-03-26T11:47:53Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/94b96840-5d67-4e5b-b0d8-3e3ae71ffa94http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/94b96840-5d67-4e5b-b0d8-3e3ae71ffa94dickchanhttp://social.technet.microsoft.com/Profile/en-US/?user=dickchanHow to automatically configuring the ISA 206 Firewall client when use GPO to deploy?We want to use DHCP WPAD and AD GPO to deploy ISA 2006 Firewall Client software to over 100 computers.<br>And we need more additional task like automatically configuring the Firewall client and automatically hiding the Firewall client symbol from clients.<br>I can install the softwar by GPO, but i need to config it at client computer one by one.<br>I am new to GPO and ISA 2006. Any idea how can i do it? Many thanks.<br>Sun, 15 Mar 2009 17:30:01 Z2009-06-17T18:02:59Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/99e7271f-a524-4423-bb7e-21d415c20f6ahttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/99e7271f-a524-4423-bb7e-21d415c20f6aWINNETPROhttp://social.technet.microsoft.com/Profile/en-US/?user=WINNETPROWindows Update using Web Proxy Clients  <p style="margin:0in 0in 0pt"><span style="font-size:9pt;font-family:Verdana">Hello Everyone, <br><br>I wanted to confirm if this is issue still an issue with ISA 2006. We have two ISA Server 2006 Std (Member Server) in a production environment. All Clients are running Windows XP Pro. All Users access internet using ISA Firewall Client.  With Firewall Client <strong>&quot;Windows Update&quot;</strong> won't work.  If we use Web Proxy Client, <strong>&quot;Windows Update&quot;</strong> works fine.  Even on Servers, it won't work without Web proxy clients.  I have gone through the following KB and made exact configuration for ISA Server 2006.</span></p> <p style="margin:0in 0in 0pt"><span style="font-size:10pt;font-family:Arial"><a href="http://support.microsoft.com/?id=885819"><span style="font-family:'Times New Roman'"><font color="#800080">http://support.microsoft.com/?id=885819</font></span></a><br><br>any recommendation is much appreciated.</span> </p><span style="font-size:10pt;font-family:Arial"><br><br><br></span>Thu, 08 Jan 2009 05:11:05 Z2009-06-01T21:41:45Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/ec683581-8794-4ede-8111-fee2e266ae27http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/ec683581-8794-4ede-8111-fee2e266ae27follettrichardhttp://social.technet.microsoft.com/Profile/en-US/?user=follettrichardISA 2000 Help <p class=MsoNormal>Hello Guys,</p> <p class=MsoNormal> </p> <p class=MsoNormal>I have a problem with setting up remote printing using ISA 2000.<br> Basically the setup is as follows</p> <p class=MsoNormal> </p> <p class=MsoNormal>1x Router (Not Natting) into 1x firewall (Not Natting) into ISA 2000 which is Natting.</p> <p class=MsoNormal> </p> <p class=MsoNormal>The local address of the server is<span style="">        </span>10.0.0.2</p> <p class=MsoNormal>The External address of the server is<span style="">  </span>65.65.65.2</p> <p class=MsoNormal>The local address of the router is<span style="">        </span>65.65.65.1</p> <p class=MsoNormal>The Local address of the firewall is<span style="">    </span>65.65.65.3<br> the external address is<span style="">             </span><span style="">            </span>65.65.65.65 (for Example)</p> <p class=MsoNormal>The local address of the printer is <span style="">      </span>10.0.0.150</p> <p class=MsoNormal>The Gateway of the printer is <span style="">                        </span>10.0.0.2</p> <p class=MsoNormal> </p> <p class=MsoNormal>I have opened the ports in the firewall to allow port 9100 which is Ok; I have also set up a publishing rule for remote printing within the ISA 2000.</p> <p class=MsoNormal>I have set my directjet port to 65.65.65.2 on the remote machine for printing</p> <p class=MsoNormal>How ever I can still not print. </p> <p class=MsoNormal> </p> <p class=MsoNormal>I have been to websites that test you ports and they all say port 9100 is open! I can also telnet into them ports from an external site.</p> <p class=MsoNormal> </p> <p class=MsoNormal>I am not very familiar with ISA 2000 and am sure the error is all mine, if anyone could advise me in some way I would highly appreciate it</p> Fri, 20 Feb 2009 14:18:07 Z2009-06-02T08:43:54Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/67dec794-be85-4211-b1a3-3d81fb94a367http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/67dec794-be85-4211-b1a3-3d81fb94a367TrojanMan78http://social.technet.microsoft.com/Profile/en-US/?user=TrojanMan78ISA firewall client, Vista, and BITS I was setting up a new Vista Business 64 bit machine the other day and all the updates before loading the ISA firewall client. After installing the firewall client BITS no longer will start. Has anyone else seen this problem before? If you uninstall the firewall client and reboot BITS will start back up. This has never been an issue before. I have loaded the firewall client previously in Vista 64 bit without any problems. That was pre SP1. So the only thing i can think of is either one of the updates prior to installing the firewall client messed it up, or something about SP1. The media I used has SP1 already on it.<br><br>Any ideas? In the XP machines the firewall client is a must for auto-updates to work but that doesnt seem to be the case in Vista.<br><br>ThanksThu, 15 Jan 2009 00:17:40 Z2009-06-02T08:47:07Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/6d208f6d-c1f4-4a95-b5b0-dd9a23d5e7dfhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/6d208f6d-c1f4-4a95-b5b0-dd9a23d5e7dfBrian Deckerhttp://social.technet.microsoft.com/Profile/en-US/?user=Brian%20DeckerWhere to install the ISA firewall clientI am wondering if the firewall client should be installed on servers as well as workstations.<br><br>What server roles should the ISA Firewall client be installed on in the enterprise?  Domain Controllers, ISA Servers, Exchange Servers, etc?   Should the ForeFront Client be installed on every server or only on workstations?<br><br>Does the firewall client run as a service or does it only run interactively when a user is logged on?<br><br>Thanks,<br><br>BrianFri, 10 Oct 2008 21:36:27 Z2009-01-05T08:29:46Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/90240b41-d934-45a1-a236-869372d8adf3http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/90240b41-d934-45a1-a236-869372d8adf3kabibonokahttp://social.technet.microsoft.com/Profile/en-US/?user=kabibonokaFWCCreds.exe credentials Hi, everybody!<br><br>Can anyone tell me, whether it is possible to access credentials, saved by admin using FWCCreds tool, under the non-admin account? <br><br>I've tried to do this but always the 'Error: Unexpected error (0x80070005)' appears. As I know, this is the 'Access denied' error, but I couldn't find the files or registry keys that must be opened.<br><br>All I found, is that under non-admin user the 'lsass.exe' process can not (not with error message, just does not) go further than 'HKLM\SECURITY\Policy\' and 'HKLM\SECURITY\Policy\SecDesc', though the credentials are saved in 'HKLM\SECURITY\Policy\Secrets\MS_MSP_WSP_AppCredentials&lt;app_name&gt;'.<br><br>Also I know, that there were no such problems with the FWC for ISA 2000. And if I find and istall it, will it work with ISA 2006?<br><br>Thank you!<br><br>FWC version is 4.0.3442.654.Wed, 11 Jun 2008 10:16:58 Z2009-06-17T18:01:29Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/ff409064-f1f4-4e8b-ab92-a25d30c9cc4ehttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/ff409064-f1f4-4e8b-ab92-a25d30c9cc4eWINNETPROhttp://social.technet.microsoft.com/Profile/en-US/?user=WINNETPROWPAD Entry For DNS and DHCP <font face=Arial> Hi, <br><br>I have two ISA Server deployed. One in main office and 2nd one in <br>Branch Office <br><br>Main Office and Branch Office is connected via private WAN. Users in Main office access internet through Main Office ISA.  Branch Office Users access through Branch Office ISA.  I have created DHCP WPAD 252 entry and DNS CNAME for Main Office ISA and DHCP clients works fine when I select automatic detect settings, it’s able to find Main Office ISA.  <br><br>I have also created DHCP WPAD 252 entry for Branch Office, but when I select automatic detect settings in any of my Branch Office ISA Server it can't find Branch Office ISA, it finds Main Office ISA.  I noticed there is only 1 entry in DNS called wpad.abc.com.  When I tried to create DNS CNAME for Branch Office ISA Server it wants to replace the name for Main Office ISA Server. <br><br>What's the best way to have my Branch Office Servers to get automatic detect settings working?</font>Mon, 22 Dec 2008 00:22:36 Z2009-06-17T18:03:19Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/f2017ed6-3efc-4488-b83e-3557c5436d1ahttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/f2017ed6-3efc-4488-b83e-3557c5436d1akingstevehttp://social.technet.microsoft.com/Profile/en-US/?user=kingsteveISA 04 IDSI've been working on my firewall trying to get it back up to where it used to be before a hard drive failure and no backup... i've only been working at this place for 3 months, so i didnt even know we had no backups. Anyway, i have been looking at my security logs in event viewer and i keep seeing failed logon attempts, and some successful attempts by anonymous logon from IPs i dont recognize. I just recently put my ISA server on the domain for backup purposes and thats when i stated noticing this. Is it normal to see these in my logs? I had an idea that it might be people logging in to their webmail from off campus(im net admin at a college). Would my isa server pick those up if theyre trying to get webmail? <br><br>Thanks,<br>Steve<br> Fri, 21 Nov 2008 13:54:40 Z2009-06-02T08:40:53Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/8b22aa3c-ee26-4300-a976-df3c3dc62cdchttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/8b22aa3c-ee26-4300-a976-df3c3dc62cdcgregaricanhttp://social.technet.microsoft.com/Profile/en-US/?user=gregaricanISA 2004 VPN and Internet Access?Here's my quandary. I think this pertains to a known issue with ISA 2004 (<a href="http://support.microsoft.com/default.aspx/kb/891195">http://support.microsoft.com/default.aspx/kb/891195</a>) so perhaps I'm at an impasse.<br><br>Our CEO travels between several of our remote sites. Our headquarters has ISA 2004 and his laptop uses the Microsoft Firewall Client for web proxy access and whatnot. This ISA 2004 box has site VPN's defined to connect to the remote sites, which have a mix of Cisco ASA and PIX devices on the other end.<br><br>When he visits these remote sites he is still being pointed to the HQ ISA 2004 box for web browsing access. Due to the known issue with ISA 2004 this won't work because he's piping in from a site VPN endpoint. So I have set him up with a couple of batch files he has to manually launch. When he's at a remote site he has to launch one that removes all of the WPAD registry entries from his system so Internet Explorer won't automatically detect the HQ web proxy. Then when he's back at HQ he launches the other batch file that puts these WPAD entries back into effect.<br><br>Is there any more elegant way of handling this behind the scenes? I don't want to install a separate caching web proxy at the remote sites since all of the other users don't see or care about the HQ ISA 2004 box. They all just go directly out of their Cisco devices for unrestricted Internet access. If I could do something programatically that would save me face, since batch files are rather crude to ask my CEO to remember each and every visit around :-)Wed, 19 Nov 2008 14:07:18 Z2008-12-29T10:41:05Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/cda609f7-d98a-4edd-aeeb-d907fbde45c3http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/cda609f7-d98a-4edd-aeeb-d907fbde45c3DavidGWhttp://social.technet.microsoft.com/Profile/en-US/?user=DavidGWHow to control dynamic ports used by Winsock app with ISA 2006 Firewall Client Is there any way to restrict which ports a winsock application uses to connect to the ISA server when using the Firewall Client to make connections out to the Internet? For example for sending outbound SMTP - I need to use the Firewall Client on an Exchange 2007 Hub Transport server as I can't use SecureNAT as the Default Gateway will not route Internet bound traffic to the ISA Server. The complication however is that there is a Cisco Firewall module in between the Exchange Server and the ISA Server. As far as I can see when the Exchange Server wants to send SMTP it will make a connection to a randomish high port on the ISA Server e.g. 41266, 42596, 42598 etc. I need to be able to specify a sensible port or small range of ports to the Cisco Firewall admins (in addition to the Firewall Client's use of 1745 of course) on which the Exchange Server can connect to the ISA Server in order to send the SMTP. <br><br>So is there any way to control which port(s) the Exchange Server will connect to ISA on when it needs to make a port 25 connection to a server on the Internet? Is there anywhere the Firewall Client's use of high port above 40000 is even documented? <br><br>Regards <br>David WilsonThu, 30 Oct 2008 18:46:51 Z2008-11-04T12:05:53Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/99c2dd3d-d3a6-4a31-a35b-4de687c3969ehttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/99c2dd3d-d3a6-4a31-a35b-4de687c3969eDouglas Nakamotohttp://social.technet.microsoft.com/Profile/en-US/?user=Douglas%20NakamotoISA 2006 SP1 server -> RADIUS servers - authentication problem  <p style="margin:0in 0in 0pt"><font face=Calibri>On my ISA 2006 SP1 server (ISA-MLB), I can run the ISA Best Practices Analyzer Tool (IsaBPA).  It checks, amongst other things, access to the RADIUS server(s).</font></p> <p style="margin:0in 0in 0pt"><font face=Calibri> </font></p> <p style="margin:0in 0in 0pt"><font face=Calibri>The RADIUS servers for ISA-MLB are DC1-MED-MLB and DC2-MED-MLB.</font></p> <p style="margin:0in 0in 0pt"><font face=Calibri> </font></p> <p style="margin:0in 0in 0pt"><font face=Calibri>The IsaBPA is showing a problem accessing both RADIUS servers.</font></p> <p style="margin:0in 0in 0pt"><font face=Calibri> </font></p> <p style="margin:0in 0in 0pt"><font face=Calibri>When I visit these servers, both are showing this error:</font></p> <p style="margin:0in 0in 0pt"><font face=Calibri> </font></p> <p style="margin:0in 0in 0pt"><i><span style="color:red"><font face=Calibri>Event Type:         Error</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:red"><font face=Calibri>Event Source:     IAS</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:red"><font face=Calibri>Event Category: None</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:red"><font face=Calibri>Event ID:              17</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:red"><font face=Calibri>Date:                    10/2/2008</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:red"><font face=Calibri>Time:                    2:10:10 PM</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:red"><font face=Calibri>User:                    N/A</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:red"><font face=Calibri>Computer:           DC1-MED-MLB</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:red"><font face=Calibri>Description:</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:red"><font face=Calibri>An Access-Request message was received from RADIUS client isa-mlb.atex.com without a message authenticator attribute when a message authenticator attribute is required. Verify the configuration of the RADIUS client in the Internet Authentication Service snap-in (the &quot;Client must always send the message authenticator attribute in the request&quot; checkbox) and the configuration of the network access server.</font></span></i></p> <p style="margin:0in 0in 0pt"><font face=Calibri> </font></p> <p style="margin:0in 0in 0pt"><font face=Calibri>However, the settings on ISA-MLB, DC1-MED-MLB, and DC2-MED-MLB are all correctly set to use the message authenticator attribute.  I’ve double-checked this and the shared secret as well.</font></p> <p style="margin:0in 0in 0pt"><font face=Calibri> </font></p> <p style="margin:0in 0in 0pt"><font face=Calibri>So, to make sure that there wasn’t some other problem, I temporarily <u>removed</u> all settings to use the message authenticator attribute.  Then, during an IsaBPA test, ISA-MLB was able to successfully connect to both RADIUS servers (the authentication failed, but that is to be expected from this test) as shown below:</font></p> <p style="margin:0in 0in 0pt"><font face=Calibri> </font></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri>Event Type:         Warning</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri>Event Source:     IAS</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri>Event Category: None</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri>Event ID:              2</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri>Date:                    10/2/2008</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri>Time:                    2:05:12 PM</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri>User:                    N/A</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri>Computer:           DC1-MED-MLB</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri>Description:</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri>User USER was denied access.</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> Fully-Qualified-User-Name = MEDIACOMMAND\USER</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> NAS-IP-Address = 134.128.43.42</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> NAS-Identifier = &lt;not present&gt; </font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> Called-Station-Identifier = &lt;not present&gt; </font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> Calling-Station-Identifier = &lt;not present&gt; </font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> Client-Friendly-Name = isa-mlb.atex.com</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> Client-IP-Address = 134.128.43.42</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> NAS-Port-Type = &lt;not present&gt; </font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> NAS-Port = 254214144</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> Proxy-Policy-Name = Use Windows authentication for all users</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> Authentication-Provider = Windows </font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> Authentication-Server = &lt;undetermined&gt; </font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> Policy-Name = &lt;undetermined&gt; </font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> Authentication-Type = PAP</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> EAP-Type = &lt;undetermined&gt; </font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> Reason-Code = 16</font></span></i></p> <p style="margin:0in 0in 0pt"><i><span style="color:#c0504d"><font face=Calibri> Reason = Authentication was not successful because an unknown user name or incorrect password was used. </font></span></i></p> <p style="margin:0in 0in 0pt"><span><font face=Calibri> </font></span></p> <p style="margin:0in 0in 0pt"><font face=Calibri>After this, I <u>reinstated</u> all settings to use the message authenticator attribute.  Then, during an new IsaBPA test, ISA-MLB was again no longer able to connect to either RADIUS server.<br><br>So, any ideas as to what might be the problem here?<br><br>Regards,<br><br>Douglas Nakamoto</font></p>Thu, 02 Oct 2008 19:38:05 Z2009-05-27T19:28:06Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/f0591e52-62a1-4e39-8698-6a673a7558c7http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/f0591e52-62a1-4e39-8698-6a673a7558c7Darfoxhttp://social.technet.microsoft.com/Profile/en-US/?user=DarfoxISA 2004 Browsing by IPHi,<br><br>I have a problem with my new isa configuration.<br>I can't browse any website if my url is an IP.<br><br>The error : Error Code: 502 Proxy Error. The ISA Server denied the specified Uniform Resource Locator (URL). (12202)<br><br>For exemple, if i enter <a href="http://www.google.fr">http://www.google.fr</a>, it work. but if i enter an ip which belong to this domain, i have an error.<br><br>Many thanks.Mon, 29 Sep 2008 08:41:29 Z2008-10-03T11:52:11Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/14238ef7-bb00-4aff-bdcd-8fec7e42cf14http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/14238ef7-bb00-4aff-bdcd-8fec7e42cf14Adidibauhttp://social.technet.microsoft.com/Profile/en-US/?user=AdidibauProxy OverrideHi <br><br>I have a problem with the Isa firewall Client. We use proxy override setting in registry to get some homepages to go around  Isa server.<br>The reason why we do this is that we use a site that we cannot access through ISA even with it as direct access (www.myedos.com).<br>I uses a header that is not supportet by ISA. before i upgraded and installed ISA firewall client there were no problem because we just put the sites into proxy override settings in the registry and it would access site through.<br>The problem is not the web browser automatic configuration thtat one is disabled.<br>When the firewall client is active it just skips the proxy override settings in registry.<br>If i disable firewall client it work again.<br>Anyone know if its possible to get the firewall client to accept the proxy override list in registry.<br><br><br>Thu, 02 Oct 2008 05:59:44 Z2009-06-02T08:00:26Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/9ce11bb0-3d77-4c36-a85c-2a483a9b9b8fhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/9ce11bb0-3d77-4c36-a85c-2a483a9b9b8fJoes12http://social.technet.microsoft.com/Profile/en-US/?user=Joes122004 Firewall Client slowHi. <p style="margin:0in 0in 0pt"><font face=Calibri><br>We have isa 2004 sp3 </font></p> <p style="margin:0in 0in 0pt"><font face=Calibri> </font></p> <p style="margin:0in 0in 0pt"><font face=Calibri>When browsing through the firewall client is very slow… when we browse with the proxy the speed is fine</font></p> <p style="margin:0in 0in 0pt"><font face=Calibri> </font></p><span style="font-size:11pt;font-family:'Calibri','sans-serif'">Any help is greatly appreciated.</span>Mon, 11 Aug 2008 14:11:53 Z2008-09-29T18:49:23Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/b5757931-0c8b-4e04-88ba-d5d3f01bf77dhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/b5757931-0c8b-4e04-88ba-d5d3f01bf77dNathan Bigmanhttp://social.technet.microsoft.com/Profile/en-US/?user=Nathan%20BigmanWelcome to the Forefront Edge Security Firewall Client Forum!<p class=MsoNormal style="margin:0in 0in 10pt"><font face=Calibri>Welcome to the Forefront Edge Security Firewall Client Forum!</font></p> <p class=MsoNormal style="margin:0in 0in 10pt"><font face=Calibri>In this space you can post ideas, questions, or issues that you encounter regarding the ISA Server Firewall client. </font></p> <p class=MsoNormal style="margin:0in 0in 10pt"><font face=Calibri>A broad range of IT professionals, Microsoft employees, and MVPs will take part in these discussions, which we expect to be interesting and helpful. We look forward to your participation.</font></p>Sun, 18 Mar 2007 09:33:52 Z2009-06-07T07:51:16Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/a58132de-2371-4b36-9286-1b89cd391fd3http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/a58132de-2371-4b36-9286-1b89cd391fd3svm_nhttp://social.technet.microsoft.com/Profile/en-US/?user=svm_nDomain becomes unavailable after installing firewall client.Alright, instead of ripping my hair out, I decided to post somewhere where I could get some opinions from people who know what they're talking about. Google searches have returned nothing, it's quite frustrating.<br><br>But anyway, I've been having problems with ISA Firewall Client 2006 on a few machines. It works fine, until I reboot the computer. Then, it tells me that the &quot;user cannot logon because domain X is unavailable&quot; when I try logging in with a regular user. It won't allow me to rejoin the domain either.<br><br>It lets me log in, no problems, with domain administrator accounts, but gives me trouble when I use a regular user account. If I uninstall the firewall client, all is well again. <br><br>I didn't notice any odd behavior other than this, except that the firewall client can't detect the ISA server automatically (but appears to connect to it manually). So I pinged the server by its name and by the IP, and it replied, no problem. <br><br>Here's the kicker - this one computer lab of several in the building that we have to install the firewall client on. All labs work fine except this one, and the machines are identical to probably 80% of the rest of the computers in the building (the client is fully functional on those computers). This lead me to thinking that it's these particular computers themselves causing the problem and not the server. Correct me if I'm wrong in thinking that.<br><br><br>Software issue, perhaps? What kind of software would conflict? VNC is installed, that's the only thing that sets these computers apart from the rest. I haven't yet tried uninstalling it as I ran short on time, but I would like to know if it's a possibility before I go and do it?<br><br>Thanks in advance for any help you can provide. The computers are running Windows XP Pro SP2 and are Dell..something or others. I'm sorry for the sketchy details, I'm not in front of the machines at the moment :P<br><br>side notes:<br><br>-one out of 24 computers (#12) works correctly with the client installed. I cannot, for the life of me, figure out the difference between #12 and the rest. They are all the same image. <br>-they did, at one point in time, have an older version of microsoft firewall client on them. We uninstalled it because the server died &amp; we had to replace it<br><br>come to think of it, I vaguely remember #12 still having the old client installed when I went to install the new one. After uninstalling &amp; rebooting the machine, I installed '06.<br><br>I apologize for thinking to myself, but I suppose the more info I can give, the more I'll get back. Thanks again.<br> Sat, 31 May 2008 04:12:31 Z2008-08-20T09:23:36Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/0c9a53e3-e266-45b3-bb21-49aef508bf52http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/0c9a53e3-e266-45b3-bb21-49aef508bf52Derar1http://social.technet.microsoft.com/Profile/en-US/?user=Derar1ISA ProblemDear All,<br><br>I installed ISA2006 Enterprise Edition SP1 on window server 2003 sp2 ,actually this server work just 3-5 min then it cant continue  and stoped.then i tried to restart the server then he connect to the internet and allow all other users to connect.after 4 min its stopped. and doesn't allow  the users to connect again.<br><br><br>Any usefull help <br>please Advice<br><br><br>Derar<br><br><br>Mon, 07 Jul 2008 06:07:48 Z2009-06-01T18:59:33Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/e70ac02e-de79-413e-96d5-39395a6d204dhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/e70ac02e-de79-413e-96d5-39395a6d204dStudent1http://social.technet.microsoft.com/Profile/en-US/?user=Student1What is the function of ISA firewall client? I just wanted to ask this question that what is the function of ISA firewall client?<br><br>Is it only used to connect the computer to the ISA Server ?<br><br>Mon, 18 Aug 2008 21:13:27 Z2008-08-18T22:38:37Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/1039a09f-2ccb-4dbd-af01-e4e3721aa093http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/1039a09f-2ccb-4dbd-af01-e4e3721aa093garyqzohttp://social.technet.microsoft.com/Profile/en-US/?user=garyqzoQuestion: When to use Firewall client instead of enterprise policy I am running isaserver enterprise 2006 and have always wanted a simple explanation regarding what the difference is between the Enterprise policy and firewall policy.   How and when does one decide to use one over the other?   What are the most common uses for creating a firewall policy and installing the client to a user's system?<br><br>Much thanks in advance to anyone who can explain this without going off into several paragraphs.<br><br>Keep it simple.Sun, 29 Jun 2008 20:42:40 Z2009-06-01T18:57:13Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/af3be61d-d75e-455c-b4ec-1f5df18d7661http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/af3be61d-d75e-455c-b4ec-1f5df18d7661Edie Hawkhttp://social.technet.microsoft.com/Profile/en-US/?user=Edie%20HawkISA Server FireWall Client<p align=left><font face=Arial size=2></font> </p> <p>hi all </p> <p align=left> </p> <p align=left>I have a Windows Server 2003 Updated to SP3</p> <p align=left>Client: Windows Xp Sp2 </p> <p> </p> <p align=left>i do install the the ISA 2006 Standard edition </p> <p align=left>and i do select the network adaptor and ip ranges</p> <p align=left>and i install the ISA 2006 Client on the client PC </p> <p align=left> </p> <p align=left>my problem is that once i install the above the ISA client, the ISA client do not detect the ISA server </p> <p align=left>and i even try to look for the server at the workgroup computers but it s not shown there  </p>Thu, 08 May 2008 04:49:35 Z2009-06-01T18:55:26Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/6aab3a16-9b25-43a2-92ff-ec1e9936dcc7http://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/6aab3a16-9b25-43a2-92ff-ec1e9936dcc7Heath Bowlinhttp://social.technet.microsoft.com/Profile/en-US/?user=Heath%20BowlinCannot Uninstall Microsoft Firewall Client from Windows 2003 x64 serverRecently, Microsoft Firewall Client version 4.0.3442 was installed on our Exchange 2007 servers due to an incorrectly configured GPO. During our last maintenance window, I tried to uninstall it via Add/Remove Programs, but keep receiving the following error<br><br>Firewall Client cannont be installed on computers running a 64-bit Windows Operating System<br><br>I downloaded this version of the firewall client from the microsoft site and it says it supports 64-bit. Anyone have any ideas?<br><br>- Heath Bowlin<br>Wed, 16 Apr 2008 02:00:04 Z2008-06-19T00:15:52Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/191de0ac-b203-4d19-98eb-71038a20f94ahttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgefirewall/thread/191de0ac-b203-4d19-98eb-71038a20f94ahappy_20_y2khttp://social.technet.microsoft.com/Profile/en-US/?user=happy_20_y2kClient Name shown as username (?)Hi<br><br>When I check the logging it shows client name along with (?) for example Sam (?) or anonymous<br><br>Any help would be appreciated.<br><br><br><br>Harpreet<br>Wed, 05 Dec 2007 11:46:38 Z2009-06-01T18:54:44Z