Forefront Edge Security - General ForumA forum for the discussion of general issues and ideas regarding Forefront Edge Security (ISA Server)© 2009 Microsoft Corporation. All rights reserved.Mon, 30 Nov 2009 03:05:11 Z118ced35-7414-4c6a-a524-563341908cbfhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/f629ee1c-6e15-4550-be14-a024877f73d1http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/f629ee1c-6e15-4550-be14-a024877f73d1TechFanhttp://social.technet.microsoft.com/Profile/en-US/?user=TechFanMagicJack. . .ISA 2004 blocking VOIP access somehow??<font face=Arial size=2> <p>I just got a MagicJack and was hoping to test it on our network, but I can't get it to work behind our ISA 2004 firewall.  The tech support says that our network is blocking ports 5060-5070 somehow.</p> <p> </p> <p>I checked with our ISP's and they are not blocking those ports.</p> <p> </p> <p>We have a dual wan router outside our ISA.  When I connect a machine directly to that subnetwork, the magicjack works fine, so it has to be something with our ISA firewall setup.</p> <p> </p> <p>I created an outgoing rule to allow ALL from a specific host (where testing the Magicjack), but it still doesn't work.  I even tried disabling ALL (incoming/outgoing) other rules.  Still nothing.</p> <p> </p> <p>What can be blocking this from working when I am specifically allowing access?</p></font>Tue, 20 May 2008 05:59:23 Z2009-11-30T01:40:55Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/4fbba78c-7571-4a46-9ed6-a2bfdf9b39e8http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/4fbba78c-7571-4a46-9ed6-a2bfdf9b39e8m.r.wallishttp://social.technet.microsoft.com/Profile/en-US/?user=m.r.wallisISA NTLM Default Domain in Credential DialogWhen ISA 2006 SP1 is asking a user to authenticate to a published site using NTLM in Internet Explorer (and IE pops up a username password prompt) is it possible to make ISA assume a particular domain name if the user just types &quot;username&quot; instead of &quot;domain\username&quot;?<br/><br/>I understand the default - which may be the clients behaviour - is to assume the name of the site, eg &quot;sharepoint.blah.com\username&quot; and that if this then falls back to &quot;Basic Auth&quot; I can set this in the web listeners properties - however this setting does not affect NTLM auth. I need NTLM for domain joined machines and users, so they get logged in automatically.<br/><br/>These problematic client machines are not in the domain, so I cannot just get Integrated Auth(Kerberos/NTLM) to sign them in without prompting at all.Thu, 26 Nov 2009 14:00:50 Z2009-11-26T14:00:51Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/b461815c-2c88-4b31-95a6-e802dbbebe8bhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/b461815c-2c88-4b31-95a6-e802dbbebe8bdavemoretonhttp://social.technet.microsoft.com/Profile/en-US/?user=davemoreton412 Precondition Error with ISA ServerHi <br/><br/>We are running ISA 2006 through an external firewall and having a problem getting to one website (www.funkyhampers.com)<br/><br/>If anyone going through the proxy server browsing to funky hampers they get an 412 Precondition error however if I plug my laptop directly into the external firewall I can browse to the site no problems.<br/>Even the ISA server itself is getting this message, I have checked the HTTP config and firewalls but can't figure this one out.<br/><br/>Can anyone shine a light on this?<br/><br/>Thanks<br/>DaveWed, 25 Nov 2009 16:30:22 Z2009-11-26T07:08:18Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/936a0f3d-a5e4-47ee-b54b-a1b33d771d67http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/936a0f3d-a5e4-47ee-b54b-a1b33d771d67Rob K Jrhttp://social.technet.microsoft.com/Profile/en-US/?user=Rob%20K%20JrAccess internal website via external namesI have a 2006 ISA server with 3 NICs, one internal, one external and one not used.  A week ago the external NIC died so I switched the external network over to the &quot;spare&quot; NIC and all was well or so I thought.  Prior to this issue I was able to access websites hosted internally with their external names.  <a href="http://www.mysite.com">http://www.mysite.com</a> worked both internally and externally.  Since the NIC change this no longer works.  <br/><br/>Yes the websites work with internal IPs/names and yes they work from outside the network with external names.  And yes I know I can setup internal names in my local DNS but I'd rather not have to do this twice one for inside and once for outside.  <br/><br/>Anyone have any idea why this no longer works or how to get this working again?<br/><br/>TIA<br/>Rob<br/> Mon, 23 Nov 2009 14:49:48 Z2009-11-25T15:58:43Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/1aad3714-51a9-448e-a2bb-624f9fc62454http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/1aad3714-51a9-448e-a2bb-624f9fc62454Jack Hachttp://social.technet.microsoft.com/Profile/en-US/?user=Jack%20HacISA 2004 - Different subnets on one WAN NIC?<p>Finally nail down the issue with the Ping issue, here comes another problem:</p> <p>When we were with old ISP, the WAN IPs are in the subnet, so there is no problem to add them onto on WAN nic, with the new ISP, the IPs they give to us are on different subnets - how can I put them onto one WAN NIC?</p> <p>Here is the information provided to us:</p> <p>IP: 64.201.56.97 - this should be our WAN IP.<br/>Default Gateway: 64.201.56.96, Subnet Mask: 255.255.255.254</p> <p>Routed Block: 64.201.56.104/29<br/>Useable addresses 64.201.56.105-110 - this is the IPs we want to assign to the Servers, Subnet Mask 255.255.255.248</p> <p>If we put 64.201.56.97 AND 64.201.56.105 onto the same WAN NIC, it won't work because they're on different subnets.</p> <p>Please advise!<br/>Thanks a lot</p>Tue, 24 Nov 2009 14:31:37 Z2009-11-24T21:24:53Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/1c3ced70-f980-4af3-966d-d3888cb757c4http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/1c3ced70-f980-4af3-966d-d3888cb757c4Jack Hachttp://social.technet.microsoft.com/Profile/en-US/?user=Jack%20HacISA 2004 - can't ping second external IP on the ISA server from outside<p>There are two NICs on our ISA Server 2004 - one external, one internal.<br/><br/>We used to have one external IP, and everything is working fine, I can ping the external IP address from outside.<br/><br/>Now we added the second external IP on the same NIC, and I still can pint the first IP, but can NOT ping the new one - I have restarted the ISA server box.  And I created a second web listener using the new IP for publishing another webserver, but it's not working either, it's probably relate to the Ping issue.<br/><br/>Any advise?</p>Thu, 19 Nov 2009 15:03:15 Z2009-11-23T20:29:37Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/57e34a04-23c2-407e-9963-3c478b6f2702http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/57e34a04-23c2-407e-9963-3c478b6f2702merlion-stevehttp://social.technet.microsoft.com/Profile/en-US/?user=merlion-steveapplication filter on non-standard porte.g i am using a non standard port 1000 for http traffic<br/> <br/> firewall rule - public ip:1000 map to private ip:1000<br/> <br/> will this connection be subject to http application layer filter ?<br/> if not how to made the application filter applied ?Sun, 22 Nov 2009 18:34:28 Z2009-11-30T03:05:11Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/8dffe4e6-5bba-4f62-b7a7-586135bcdb99http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/8dffe4e6-5bba-4f62-b7a7-586135bcdb99Corey Rileyhttp://social.technet.microsoft.com/Profile/en-US/?user=Corey%20RileyLoad Balance Inbound POP/IMAP/SMTP connections to Exchange 2007 with ISA 2006?We have an ISA 2006 Cluster handling inbound traffic to our Exchange 2007 CAS servers.  It handles load balancing for web traffic nicely, but it seems to be absent for the POP/IMAP/SMTP connections.  Is there a way to acheive this with 2006 or Forefront Edge Security?  It just seems silly when ISA can load balance front end web servers, but it can't do the same for client mail traffic. Thu, 19 Nov 2009 14:44:50 Z2009-11-25T08:45:16Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/8230a5ea-03a5-4b1a-a0c7-366f115df4e5http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/8230a5ea-03a5-4b1a-a0c7-366f115df4e5Larakiahttp://social.technet.microsoft.com/Profile/en-US/?user=LarakiaForefront TMG 2010 (ISA) Enterprise Vs Standard featuresHi all<br/>Where can I find a list of the difference between Forefront TMG 2010 (ISA) Enterprise Vs Standard features.<br/><br/>I have manage a network that is global and have 60+ gateways. We are currentlly using another product for HTTP filtering.<br/><br/>I do not require Load balancing or an Array setup, but I would like to manage the 60+ System from one console ie (Forefront Server Security Management Console)<br/><br/>Senario 1<br/>I have URL Filtering enable to stop users accessing a gambling site but management require access to the Lotto Results and I am asked to unblock http://thelottoresults.com<br/>I would like to add the url and the overide rule is then replicated to all servers<br/><br/>Can I manage the multple std TGM 2010 servers from one console <br/><br/>Thanks Jeff<br/><br/>Thu, 19 Nov 2009 05:59:15 Z2009-11-26T02:43:26Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/c2eb3829-d097-43d3-92eb-92953cdac318http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/c2eb3829-d097-43d3-92eb-92953cdac318LoboFXhttp://social.technet.microsoft.com/Profile/en-US/?user=LoboFXConfiguring ISA Server to allow SIP softphone traffic Hello there people.<br><br>We have here a Windows Server 2003 R2 Service Pack 2, connected to the internet through ADSL, and ISA Server 2004 (version 4.0.2161.50) installed on it.<br><br>We are now using a third-party VoIP solution to communicate with our customers (it's a service called PABX Virtual, from a brazilian company named Locaweb), and we use a softphone called eyeBeam, from CounterPath.<br><br>We are using the service for some months now, and it works great most of the time. But, sometimes we have some problems, especially with a new PSTN number we've just contracted with our SIP provider Locaweb. The two most common problems are:<br><br> <ul> <li>We hear the caller voice but the caller can't hear us.</li> <li>The caller dials our PSTN number, then he/she reaches the virtual PBX recording, dials the wanted option and then the call is lost.</li></ul> <p><br>After some tests, our provider said that we are probably blocking some port here on our network. They told us to allow access specially to the range 10.000-20.000 UDP. However, since the beginning we did configured ISA server to allow these and other ports:</p> <ul> <li>Ports 5060-5061 TCP</li> <li>Ports 5060-5061 UDP</li> <li>Ports 10000-20000 UDP</li></ul> <p><br>But we've never been 100% sure if the way we did it is correct. We've tried a lot of combinations, but the actual configuration is something link this:<br><br></p> <p> - We've created two new user-defined protocols:<br><br><strong> 1. CounterPath eyeBeam (in)</strong>:</p> <ul> <li>5060-5061, <strong>TCP</strong>, Direction: <strong>Inbound</strong></li> <li>10000-20000, <strong>UDP</strong>, Direction: <strong>Receive Send</strong></li> <li>5060-5061, <strong>UDP</strong>, Direction: <strong>Receive Send</strong></li></ul> <p><br> <strong>2. CounterPath eyeBeam (out)</strong>:</p> <ul> <li>5060-5061, <strong>TCP</strong>, Direction: <strong>Outbound</strong></li> <li>10000-20000, <strong>UDP</strong>, Direction: <strong>Send Receive</strong></li> <li>5060-5061, <strong>UDP</strong>, Direction: <strong>Send Receive</strong></li></ul> <p><br> - Then we've created an Access Rule like that:</p> <ul> <li>Action: <strong>Allow</strong></li> <li>Protocols: <strong>CounterPath eyeBeam (in) and (out)</strong></li> <li>From: <strong>All Networks (and Local Host)</strong></li> <li>To: <strong>All Networks (and Local Host)</strong></li> <li>Users: <strong>All Users</strong></li> <li>Schedule: <strong>Always</strong></li> <li>Content Types: <strong>All</strong></li></ul> <p><br>We did tried with more appropriate sources and destinations (<strong>From</strong> and <strong>To</strong> fields), but at that time we ended trying a more &quot;wide&quot; and desperate approach.<br><br>Do you have any clue what should be the correct configuration for using our VoIP solution behind ISA Server? Thanks in advance for any help.<br><br>Best regards,<br>Pedro.</p>Thu, 06 Nov 2008 20:00:20 Z2009-11-19T13:51:21Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/6c6cb81c-10bd-4028-94ba-9ca770c2b9dehttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/6c6cb81c-10bd-4028-94ba-9ca770c2b9deimprisehttp://social.technet.microsoft.com/Profile/en-US/?user=impriseSecureNAT entries in Sessions section...Hi all; <br/> <br/> In my network all of the clients are Web Proxy without the Gateway address. Now, when I check the Sessions tab of the Monitoring section, I can see several clients are SecureNAT? Why this happens? <br/> <br/> <br/> ThanksTue, 17 Nov 2009 12:12:01 Z2009-11-19T09:36:56Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/86e2642e-bd17-4076-828d-a1217ee573dfhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/86e2642e-bd17-4076-828d-a1217ee573dfip-robhttp://social.technet.microsoft.com/Profile/en-US/?user=ip-robTrouble joining TMG EE to arrayI have a machine I'm trying to join to an existing EE array. It always fails with the message: <br/><br/>Error: 0xc0040431 <br/>Forefront TMG services failed to start after a array join or an array disjoin. Check alerts, fix the configuration, and attempt to restart the services. <br/><br/>It seems like it isn't waiting long enough for a particular service to start. Just wondering if anyone else had this issue and a potential workaround? <br/><hr class="sig">RobFri, 06 Nov 2009 14:35:57 Z2009-11-18T22:59:53Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/7372bb7e-a3b6-4b78-81ee-2ec3a22e9f53http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/7372bb7e-a3b6-4b78-81ee-2ec3a22e9f53Jim Harrison IsaDewdhttp://social.technet.microsoft.com/Profile/en-US/?user=Jim%20Harrison%20IsaDewdTMG 2010 Ships!<a href="http://blogs.technet.com/isablog/archive/2009/11/17/forefront-threat-management-gateway-2010-release.aspx">http://blogs.technet.com/isablog/archive/2009/11/17/forefront-threat-management-gateway-2010-release.aspx</a><hr class="sig">Jim Harrison Forefront Edge CSTue, 17 Nov 2009 23:12:31 Z2009-11-17T23:12:31Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/62f7f19c-3110-4ea7-a330-c4638fd08a05http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/62f7f19c-3110-4ea7-a330-c4638fd08a05imprisehttp://social.technet.microsoft.com/Profile/en-US/?user=impriseWeird problem while I connect to my network by Remote DesktopI use ISA Server 2006 with latest Service Pack and patch. I configured VPN on my ISA Server and connect to my network by using Remote Desktop connection. <br/> <br/> I use this configuration for several months. But for several week I have a weird problem. When I create the VPN session everything works well but when I execute the Remote Desktop Connection, the connection establishes but I can only see a black screen. In this situation, if I create a second RDP connection everything works well. <br/> <br/> At first I thought this is the problem of the server that I want to connect, but I have this problem on my all of the servers. Then I thought maybe the problem relates to the RDP application on my client, but I can connect to my another VPN server on another network. So, I think this is the problem of the ISA server... <br/> <br/> Any idea? <br/> <br/> Thanks <br/> <br/> -RezaMon, 16 Nov 2009 19:28:01 Z2009-11-17T12:09:43Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/2e61f309-5fe8-4a72-8687-f9a68a803653http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/2e61f309-5fe8-4a72-8687-f9a68a803653cmleehttp://social.technet.microsoft.com/Profile/en-US/?user=cmleeISA 2006 AD Group Filtering Causes 403 Forbidden Error for OWA with RSA SecurID<p class=MsoNormal style="line-height:normal;margin:0in 0in 12pt"><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">I have an ISA 2006 server within the DMZ, so it is a single-homed server acting only as a reverse proxy for our internal OWA website.  The ISA server is a member of the internal domain, and the ports for AD communication have been opened on the intranet firewall so that the ISA server can communicate with the internal domain controllers and internal DNS.  RSA SecurID tokens are required for users to have two-factor authentication.<br/><br/>When the OWA publishing rule is set to allow the predefined ISA user group for &quot;All Authenticated Users&quot;, there is no problem accessing the internal OWA site.  When the OWA publishing rule is modified to contain only a specific AD user account or contain the AD group for remote users, the logon fails with the error &quot;403 Forbidden.  The server denied the specified Uniform Resource Locator (URL),  Contact the server administrator. (12202)&quot;.  After the credentials are entered, the page indicating that the session is being redirected appears right before the error is displayed.<br/><br/>In the ISA logs, the following error is received, generated by the &quot;Default Rule&quot; rather than the OWA publishing rule:</span></p> <p class=MsoNormal style="line-height:normal;margin:0in 0in 0pt"><strong><span style="font-family:'Verdana', 'sans-serif';color:red;font-size:8pt"><span> </span>Denied Connection<span>                              </span></span></strong><strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">ISASERVER 11/13/2009 9:30:12 AM</span></strong></p> <p class=MsoNormal style="line-height:normal;margin:0in 0in 0pt"><strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">Log type: </span></strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">Web Proxy (Reverse)<strong></strong></span></p> <p class=MsoNormal style="line-height:normal;margin:0in 0in 0pt"><strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">Status: </span></strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">12202 The ISA Server denied the specified Uniform Resource Locator (URL).</span></p> <p class=MsoNormal style="line-height:normal;margin:0in 0in 0pt"><strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">Rule: </span></strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">Default rule</span></p> <p class=MsoNormal style="line-height:normal;margin:0in 0in 0pt"><strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">Source: </span></strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">Internal (&lt;Client_IP&gt;)</span></p> <p class=MsoNormal style="line-height:normal;margin:0in 0in 0pt"><strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">Destination: </span></strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">(&lt;ISA_IP&gt;:443)</span></p> <p class=MsoNormal style="line-height:normal;margin:0in 0in 0pt"><strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">Request: </span></strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">GET <a href="http://webmail.domain.com/"><span style="color:blue">http://webmail.domain.com/</span></a></span></p> <p class=MsoNormal style="line-height:normal;margin:0in 0in 0pt"><strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">Filter information: </span></strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">Req ID: 02a41bfb; Compression: client=Yes, server=No, compress rate=0% decompress rate=0% ; FBA cookie: exists=yes, valid=yes, updated=no, logged off=no, client type=public, user activity=yes</span></p> <p class=MsoNormal style="line-height:normal;margin:0in 0in 0pt"><strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">Protocol: </span></strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">https</span></p> <p class=MsoNormal style="line-height:normal;margin:0in 0in 0pt"><strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">User: </span></strong><span style="font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">(SecurID)&lt;username&gt;</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><strong><span style="line-height:115%;font-family:'Verdana', 'sans-serif';font-size:8pt">Client agent: </span></strong><span style="line-height:115%;font-family:'Verdana', 'sans-serif';font-size:8pt">Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><strong><span style="line-height:115%;font-family:'Verdana', 'sans-serif';font-size:8pt">Object source: </span></strong><span style="line-height:115%;font-family:'Verdana', 'sans-serif';font-size:8pt">(No source information is available.)</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><strong><span style="line-height:115%;font-family:'Verdana', 'sans-serif';font-size:8pt">Cache info: </span></strong><span style="line-height:115%;font-family:'Verdana', 'sans-serif';font-size:8pt">0x0</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><strong><span style="line-height:115%;font-family:'Verdana', 'sans-serif';font-size:8pt">Processing time: </span></strong><span style="line-height:115%;font-family:'Verdana', 'sans-serif';font-size:8pt">1 ms</span></p> <p class=MsoNormal style="line-height:normal;margin:0in 0in 0pt"><span style="font-family:'Verdana', 'sans-serif';font-size:8pt"><strong>MIME type:<br/><br/></strong>One thing I have noticed during testing is that if I remove the RSA authentication from the Web Listener that the OWA Publishing Rule uses, and instead just use the AD forms based authentication, users are able to log in when only a specific AD group is defined in the publishing rule.  When RSA authentication is enabled, the RSA credentials are validated as the page displays the redirection page, which then fails with the 403 Forbidden error.  Is there additional security or configuration that is required for the RSA authenticaiton redirection page to work?</span></p>Fri, 13 Nov 2009 14:46:19 Z2009-11-23T02:06:45Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/149d39d7-c6e0-43de-a002-37f78fffacc0http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/149d39d7-c6e0-43de-a002-37f78fffacc0Anshu10http://social.technet.microsoft.com/Profile/en-US/?user=Anshu10NLB error in ISA 2006 Hi,<br><br>We want to use ISA 2006 with NLB for publishing Exchange 2007 environment.<br><br>Server ISA001 is installed both as a CSS and ISA server. Single network adapter template is applied to the network.<br><br>The second node ISA002 gets added to the array. The problem starts when we configure NLB for the servers.<br><br>The intra-array communication fails. CSS server is not able to obtain membersip status from ISA002.<br><br>We are using CISCO 4948 switch.<br><br>I had earlier posted this problem at Exchange server forum. They had advised me to come here.<br><br>Please help.<br><br>Anshu<hr size="1" align="left" width="25%">AnshuFri, 19 Sep 2008 10:51:29 Z2009-11-12T15:50:48Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/3e617592-160b-4ab9-93bd-c66e11aa03d2http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/3e617592-160b-4ab9-93bd-c66e11aa03d2AZIThttp://social.technet.microsoft.com/Profile/en-US/?user=AZITreplacing hardware load balancer by ISA 2006 EE array<p>Hi,<br/>Office Communication Server 2007 R2 enterprise edition servers within a pool do require a hardware loadbalancer. Internal clients connect to the pool. Now, would it be possible to use an ISA 2006 array instead of a hwardware loadbalancer infrastrcuture ? (I guess ISA Firewall client has to be installed on clients as well). The requirements for hardware loadbalancer are: <a href="http://technet.microsoft.com/en-us/library/bb870398.aspx">http://technet.microsoft.com/en-us/library/bb870398.aspx</a> (or at the bottom) - Is ISA 2006 able to fulfill these requirements ? Support for that ?<br/><br/>Thanks <br/><br/>Load Balancer Requirements for Office Communications Server 2007 Enterprise Pools<br/>This topic lists requirements for a hardware load balancer deployed in an Office Communications Server 2007, Enterprise pool.</p> <p>  Prerequisites for a Load Balancer Connecting to a Pool <br/>Before a hardware load balancer can connect to the Office Communications Server Enterprise pool, you must configure the following:</p> <p>A static IP address for servers within your pool.<br/>Using a load balancer in SNAT (source network address translation) mode is recommended for ease of deployment, however be aware each SNAT IP address on the load balancer limits the maximum number of simultaneous connections to 65,000. If you deploy load balancer in SNAT mode, ensure you configure a minimum of one SNAT IP address for each group of 65,000 users. (The open number of connections generally corresponds to the number of active users.) For example, in a deployment supporting 100,000 users, you would configure two SNAT IP addresses.<br/>If you use a DNAT (destination network address translation) load balancer for your Enterprise pools, the following is required:<br/>Each pool must reside in a distinct IP subnet from other pools, because the Front End Servers in each pool must reside in this distinct IP subnet. <br/>For a pool in the expanded configuration, only the Front End Servers must be placed in this distinct IP subnet. All other roles – the Web Conferencing, A/V Conferencing and Web Component Servers – must reside outside the distinct IP subnet for the Front End Servers. There is no additional restriction on how these other roles can be placed on the network.<br/>A VIP address and associated DNS record for the load balancer. See the DNS (Domain Name Service) section for more information.<br/>Important:  <br/>The following requirements apply to all load balancers that are deployed in an Office Communications Server 2007, Enterprise pool. For information about configuring and deploying a particular brand and model of hardware load balancer, see the documentation that is included with the product of your choice.<br/><br/>A load balancer for an Office Communications Server 2007, Enterprise Pool must meet the following requirements:<br/>Expose a VIP Address through ARP (Address Resolution Protocol). The VIP must have a single DNS entry, called the pool FQDN and must be a static IP address.<br/>Allow multiple ports to be opened on the same VIP. The following ports are required.<br/>Table 77 Hardware load balancer ports that are required for Office Communications Server 2007<br/>Port Required  Virtual IP  Port Use  <br/>5060<br/> Load balancer VIP used by the Front End Servers<br/> Client to server SIP communication over TCP<br/> <br/>5061<br/> Load balancer VIP used by the Front End Servers<br/> Client to Front End Server SIP communication over TLS</p> <p>SIP Communication between Front End Servers over MTLS<br/> <br/>135<br/> Load balancer VIP used by the Front End Servers<br/> To move users and perform other &quot;pool&quot; level WMI operations over DCOM <br/> <br/>444<br/> Load balancer VIP used by the Front End Servers<br/> Communication between the internal components that manage conferencing and the conferencing servers<br/> <br/>443<br/> Load balancer VIP used by the Web Components Server<br/> HTTPS traffic to the pool URLs<br/>Provide TCP-level affinity. This means that the load balancer must ensure that TCP connections can be established with one Office Communications Server in the pool and all traffic on that connection will be destined for that same Office Communications Server.</p> <p>Each Front End Server must have an IP address that is directly routable within the internal network (specifically to allow communications between Front End Servers across different pools).</p> <p>The load balancer must provide a configurable TCP idle-timeout interval with its value set to 20 minutes or greater. This value must be 20 minutes or higher because it should be above the following values:</p> <p>Maximum SIP connection idle timeout of 20 minutes (this is the major determining value).</p> <p>SIP Keep-alive interval 5 minutes.</p> <p>Maximum REGISTER refresh interval of 15 minutes in absence of keep-alive checks.</p> <p>Enable TCP resets on idle timeout; also disable TCP resets when servers are detected to be down.</p> <p>Front Ends within a pool behind a load balancer must be capable of routing to each other. There can be no NAT device in this path of communication. Any such device will prevent successful RPC between Front End Servers within a pool.</p> <p>Front Ends behind a load balancer must have access to the Active Directory environment.</p> <p>Front Ends must have static IP addresses that can be used to configure them in the load balancer. In addition, these IP addresses must have DNS registrations (referred to as Front End FQDN).</p> <p>Any computer running Office Communications Server 2007 administrative tools must be able to route through the load balancer to both the Pool FQDN as well as the Front End FQDN of every Front End in the pool(s) to be managed. In addition, there can be no NAT device in the path of communication to the Front Ends to be managed. Again, this is a restriction enforced by the usage of the RPC protocol by DCOM.</p> <p>The load balancer should support a least-connections-based Load balancing mechanism. This means that the load balancer will rank all Office Communications Server servers based on the number of outstanding connections to each of them. This rank will then be used to pick the Office Communications Server to be used for the next connection request.</p> <p>The load balancer must allow for adding and removing servers to the pool without shutting down.</p> <p>The load balancer should be capable of monitoring server availability by connecting to a configurable port for each server.<br/>Important:  <br/>The monitor for ports 135 and 444 should open TCP connections to port 5060 or 5061 for determining server availability. Attempting to monitor ports 135 and 444 on the servers will cause the load balancer to incorrectly detect these servers to be available because these ports are open even though Office Communications Server is not running.</p>Wed, 11 Nov 2009 10:59:47 Z2009-11-12T10:58:33Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/ed352f4d-33b4-4df2-96e6-b3eb754d8f92http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/ed352f4d-33b4-4df2-96e6-b3eb754d8f92imprisehttp://social.technet.microsoft.com/Profile/en-US/?user=impriseWhy not assign Gateway address in ISA server's Internal Adapter?Hi all;<br/> <br/> Why not assign Gateway address in ISA server's Internal Adapter?<br/> <br/> Thanks<br/> <br/> -RezaWed, 11 Nov 2009 21:26:27 Z2009-11-11T22:36:33Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/47482802-7555-4b3d-ae13-21a18ddb28b3http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/47482802-7555-4b3d-ae13-21a18ddb28b3tnsudhihttp://social.technet.microsoft.com/Profile/en-US/?user=tnsudhiDns server issueDear All, We have 2 AD intergrated DNs servers.And in DNS server we have put forwarders to resolve the the external queries.This dns servers are used by ISA 2006 EE to name resolving.It was working fine. Recently we have some issue with ISP link.So when ISP link goes down and coming up like Variation is there.So once this happens suddenly our DNS server not able to resolve external queries.It is able to resolve internal queries.Then if i restart the dns service also it is not resolving.SO the only thing is to restart then only it will work fine. Thanks Sudhir Mon, 02 Nov 2009 14:17:06 Z2009-11-10T07:55:56Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/483c6e44-abbd-46c6-a901-d50b62474af2http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/483c6e44-abbd-46c6-a901-d50b62474af2JasonTheBoyWonderhttp://social.technet.microsoft.com/Profile/en-US/?user=JasonTheBoyWonderInstalling ISA 2006 CSS on a Windows 2003 Domain Controller with DNSIs there a trick to installing the ISA 2006 CSS on a Windows 2003 Domain Controller with DNS? We keep getting a failure at the creation of the ADAM instance, and I see that it is a supported configuration. The best practices analyzer even says it is supported, so why would it have a problem?<br/><br/>Have done all the suggested things, (running the CD from hard drive, all updates applied, etc.) but no luck.<br/><br/>Error: Setup failed to install ADAM (0x80070002)<br/><br/>ISA 2006 EE<br/>Windows 2003 R2 EE (with all updates)<br/>VM with Windows 2003 DC &amp; DNS<br/>PDC for ISA domain<br/>single processor<br/>single NIC<br/>plenty of RAM and HD space<br/><br/>Any suggestions?Mon, 09 Nov 2009 16:17:01 Z2009-11-10T02:50:56Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/dbe5ed65-7779-4149-8528-64db24f5dd83http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/dbe5ed65-7779-4149-8528-64db24f5dd83ip-robhttp://social.technet.microsoft.com/Profile/en-US/?user=ip-robCan't get NAT Address setting to change trafficI have a TMG RC running on Server 2008 R2.  One NIC for public connection, one for private.  I have 3 IP's assigned to the public NIC, two of which are NLB clusters.  Everything works fine EXCEPT getting the NAT Address Selection to actually impact data.<br/><br/>I've set up a network rule that anything coming from the mail server uses NAT address .3 (3rd IP assigned to public NIC, it is an NLB cluster).  The traffic in the log still shows everything going out on the default IP of the TMG gateway.<br/><br/>Am I missing something simple?  Does this work in the RC?<br/><hr class="sig">RobThu, 05 Nov 2009 20:03:19 Z2009-11-06T14:33:54Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/e03f5b7c-7fcb-42f3-91e0-2aa55ec108f1http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/e03f5b7c-7fcb-42f3-91e0-2aa55ec108f1Rayhaanhttp://social.technet.microsoft.com/Profile/en-US/?user=RayhaanRDP to W2K8 R2 through ISA 2004 VPNHi Folks<br/> <br/> I have an ISA 2004 VPN connection and can successfully RDP to my Windows 2003 Servers. However I cannot RDP or ping any Windows 2008 R2 Servers from VPN connection. This have me puzzled as I can successfully RDP and ping all servers (Win03, Win08) when on LAN.<br/> <br/> Does this issues have to do with ISA 2004 or some settings of Windows 2008 R2? I was told to post this issue on the ISA forum to narrow/determine nature of issue.<br/> <br/> <br/> Rayhaan.Thu, 05 Nov 2009 05:36:19 Z2009-11-06T05:00:16Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/5eedd59c-69e1-48fc-9c0d-8e3d6e29d9c5http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/5eedd59c-69e1-48fc-9c0d-8e3d6e29d9c5Carpadumhttp://social.technet.microsoft.com/Profile/en-US/?user=CarpadumStrange HTTP Redirect / DMZ IISWe have a fairly large new IIS server (win 2008 x64) that hosts a number of websites (replacing 2003 box behind pix). We have a BUNCH of &quot;http redirects&quot; setup at the IIS level and also some in META code. We just moved this server behind an ISA 2006 firewall (in DMZ) and now none of the redirects work. For instance if I hit a site <a href="http://www.domaina.com/">www.domainA.com</a> which has an HTTP Redirect to <a href="http://www.domainb.com/">www.DomainB.com</a> and both of these sites are on the same server then a few thousand requests start looping for DomainA.com. We think this behavior is related to host headers not passing around properly. <br/>ISA shows a HTTP Status Code of 304 Not Modified and error info 0x580 <br/>I also see the following entries related to cache. <br/>0x40801012 (Request includes the IF-MODIFIED-SINCE header. Request includes the VIA header. Request includes the IF-NONE-MATCH header. Response includes the LAST-MODIFIED header. Response should not be cached.) <br/>There are no deny actions reported in the log just thousands of &quot;allow connection&quot; over and over again. <br/>The browser received this message from the ISA server. <br/>Error Code: 500 Internal Server Error. The number of HTTP requests per minute exceeded the configured limit. Contact the server administrator. (12219) <br/>We need to know how to fix this. I know I could create a rule to deny <a href="http://www.domaina.com/">www.domainA.com</a> and then send the request to <a href="http://www.domainb.com/">www.domainB.com</a> however we need to do this at the server for many reasons. It was never an issues when we used a pix firewall and windows 2003. Detailed help would be great. Thanks Tue, 20 Oct 2009 14:57:50 Z2009-11-03T00:15:45Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/a68f8885-1da2-4637-9d0c-7a1e62e0be65http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/a68f8885-1da2-4637-9d0c-7a1e62e0be65Vahid Rashmanihttp://social.technet.microsoft.com/Profile/en-US/?user=Vahid%20Rashmaninew version ISAhi<br/> what is the new version of ISA?<br/>Mon, 02 Nov 2009 15:27:38 Z2009-11-07T14:34:31Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/4bb2aa4a-aa2b-42e2-8d4c-009708ef32dbhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/4bb2aa4a-aa2b-42e2-8d4c-009708ef32dbwsg2http://social.technet.microsoft.com/Profile/en-US/?user=wsg2ISA Server cannot load the property page<span class=value>In System Policies, under Remote Management | Ping and Diagnostic Services | ICMP, all of the networks have disappeared in the To and From tabs respectively. I get the error message &quot;ISA Server cannot load the property page. Error: 0x80070002. The system cannot find the file specified.&quot;<br/> <br/> When I try to add a network such as Internal and save, I get &quot;The changes cannot be saved. Error: 0xc0040357&quot; and &quot;The Network referenced by Policy Rule Allow ICMP (PING) requests from selected computers to ISA Server does not exist.&quot;<br/> <br/> I am running Microsoft ISA Server 2006 Version: 5.0.5723.493 on Win2003 Server EE SP2.<br/> <br/> I have tried recreating the mmc to no avail...<br/> <br/> Any thoughts?</span>Tue, 27 Oct 2009 21:25:56 Z2009-10-31T13:16:22Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/4cdac057-43aa-4b34-b563-8517343e7ffehttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/4cdac057-43aa-4b34-b563-8517343e7ffeV. Prakash Choudharyhttp://social.technet.microsoft.com/Profile/en-US/?user=V.%20Prakash%20ChoudharyISA LOAD BALANCINGGuys,<br/><br/>We have some performance issue going on ISA servers, its two nodes configuration running as load balancing, the version is ISA 2004 enterprises sp3, <br/><br/>What would be the best way to stop this load balancing manually so that we could make one node down and do the windows fragmentation as suggested by microsoft for our performance issue.<br/><br/>Do we need to stop service manually in ISA console? what would be the best practise?<br/><br/>any suggestion on this?Fri, 23 Oct 2009 07:12:35 Z2009-10-30T15:32:43Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/84eebac2-9af1-4a81-9652-c6f47a17b7fbhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/84eebac2-9af1-4a81-9652-c6f47a17b7fbjames2k8http://social.technet.microsoft.com/Profile/en-US/?user=james2k8http redirector????Hi,<br/> <br/> I need to enable http redirector filter for ISA 2006 as our clients are not being filtered by websense when using firewall client.  I can't find this filter anywhere.  Please help.<br/> <br/> Many thanksWed, 28 Oct 2009 07:56:45 Z2009-11-04T08:13:41Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/a48f62eb-19a9-411b-bd86-20c2ebf27deehttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/a48f62eb-19a9-411b-bd86-20c2ebf27deejames2k8http://social.technet.microsoft.com/Profile/en-US/?user=james2k8FTP denied access and ISA 2006<span class=value>Hi,<br/> <br/> I've created a rule that allows FTP traffic from internal to external for everyone under firewall policy.  Now FTP access works in IE but I'm trying to access this through one of the FTP client software called Core FTP (free).  I've specified proxy details but still am not getting through ISA.<br/> <br/> Looking at monitoring in ISA, I get 59 An unexpected network error occurred. Source is from client and destination is ISA.  So I'm not even getting through ISA.  Also user is anonymous.  Looks like user is not being authenticated either?<br/> <br/> Please advise.</span>Thu, 22 Oct 2009 05:16:54 Z2009-10-29T06:56:13Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/43a60987-134b-4334-8ea7-3b45ea6ffe5bhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/43a60987-134b-4334-8ea7-3b45ea6ffe5bMohammad Nasirihttp://social.technet.microsoft.com/Profile/en-US/?user=Mohammad%20NasiriCan ISA server filter traffic that are not coming to its NIC ?hi:<br/><br/>I want to know if ISA can filter traffic on the network that are not directly connected to the ISA Server !!!<br/>I dont know how to exactly explain it !!!<br/><br/>I have a network that i want to filter traffic to some servers , I have connected ISA server to one of the switch ports , And i want to know that , Can isa Server filter traffic that are not comming to its NIC ? or no ?<br/>Thank you.<br/> <hr class=sig> Network is my LOVEMon, 26 Oct 2009 11:01:02 Z2009-11-03T01:34:41Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/332760a4-90ce-41ca-8010-e523c3aa8fdahttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/332760a4-90ce-41ca-8010-e523c3aa8fdaGiuseppe Mercatantehttp://social.technet.microsoft.com/Profile/en-US/?user=Giuseppe%20MercatanteWake on Lan trough ISA 2006 SP1hi to all,<div>i need to enable WOL trough ISA. </div><div>I Have created a rule to allow the UDP 9 from source to destination, but the packet is discarded with the following code:</div><div><br></div><div>FWX_E_BROADCAST_PACKET_DROPPED<br></div><div><br></div><div>Thank a lot for the help.</div>Mon, 05 Jan 2009 16:38:43 Z2009-10-24T09:34:51Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/829b6386-76a2-42c8-9c33-5f09551816f2http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/829b6386-76a2-42c8-9c33-5f09551816f2james2k8http://social.technet.microsoft.com/Profile/en-US/?user=james2k8ISA 2006 + AD groups SyncHi,<br/> <br/> For some reason when I make changes to AD groups, ISA 2006 does not replicate the changes down.  Is it possible?Sat, 24 Oct 2009 07:11:47 Z2009-10-30T02:58:29Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/c5bb8ec3-537d-42f9-87db-a2d32ccf1f8ahttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/c5bb8ec3-537d-42f9-87db-a2d32ccf1f8aksnbhttp://social.technet.microsoft.com/Profile/en-US/?user=ksnbpublish exchange2007 owa, activesync, pop AND imap with single nic configuration?We have isa 2006 sp1 deployed on server 2003 fully patched. ISA is currently a single nic configuration. We use it for proxy for a few servers. We will be transitioning to exchange 2007 next month. I have a test deployment of ex2007 up, with separate CAS/hub box, separate mailbox server and a separate w2003 domain controller which also has ex2003 mailboxes.  I have successfully published  OWA and activesync using our production isa box with its single nic configuration.<br/>I need to be able to also publish pop and imap (both over ssl). I don't have much isa server experience, as you can tell by now. <br/>I know I read somewhere that if I installed an exchange 2007 publishing wizard, I could use it for pop, imap, owa and activesync but find that not to be the case.<br/>It seems I have to have a dual nic config in isa to be able to publish the pop and imap?Fri, 23 Oct 2009 20:47:29 Z2009-10-23T22:51:26Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/da435f84-4790-4281-9a3c-3392440477bchttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/da435f84-4790-4281-9a3c-3392440477bcFabio Firsthttp://social.technet.microsoft.com/Profile/en-US/?user=Fabio%20FirstNLB ISA EE 2006Hi people!<br/> <br/> I have big problem in my environment.<br/> <br/> 2 ISA with NLB.<br/> <br/> 1 NIC Internal<br/> 2 External (DMZ)<br/> 3 Intra-array<br/> <br/> <br/> My problem occours replication communication beetween nodes of NLB.<br/> <br/> The NLB use NIC internal for communications and my lan network starts to drop packets, because the <br/> <div dir=ltr>communication occurs by internal lan.<br/> <br/> I need configure communications beetween by NIC dedicated intra-array..<br/> <br/> Help me... I need shutdown a Isa server, because user's don't worked!</div>Tue, 29 Sep 2009 12:32:41 Z2009-10-23T07:01:37Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/38609a86-9e7f-4f0e-9ca4-3b40f2560865http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/38609a86-9e7f-4f0e-9ca4-3b40f2560865Jose Osorio R.http://social.technet.microsoft.com/Profile/en-US/?user=Jose%20Osorio%20R.publish internal crm 4 (port:5555) by isa 2006<p>Hi All,<br/><br/>I´m Trying to publish my crm 4.0 by isa 2006, so i read this post <a href="http://blogs.technet.com/isablog/archive/2008/07/23/publishing-microsoft-crm-4-0-through-isa-server-2006.aspx">http://blogs.technet.com/isablog/archive/2008/07/23/publishing-microsoft-crm-4-0-through-isa-server-2006.aspx</a>.<br/><br/>Internally i access to crm by port 5555 (<a href="http://srvcrm:5555">http://srvcrm:5555</a>) and i want to publish crm by port 443. It means isa receive request to port 443 and redirect to port 5555.<br/><br/>what would be the <span><strong>IFD Configuration </strong>for me?<br/></span><br/>Authentication Strategy : IFD + on Premise<br/><br/>IFD Internal Network Address and Subnet Mask : x.x.x.x - 255.255.255.0<br/><br/>IFD Domain Scheme :  HTTPS<br/>IFD App Root Domain : externaldomain.com:433<br/>IFD SDk Root Domain : externaldomain.com:433<br/><br/>AD Domain Scheme : HTTP<br/>AD App Root Domain : srvcrm:5555<br/>AD SDK Root Domain : srvcrm:5555<br/><br/>Is this ok?<br/><br/>Thanks.<br/><br/><br/></p>Wed, 21 Oct 2009 15:04:52 Z2009-10-29T06:54:56Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/55c5e3a1-4cd4-41f9-8158-addb524ea4a3http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/55c5e3a1-4cd4-41f9-8158-addb524ea4a3bsnyder-bscaleshttp://social.technet.microsoft.com/Profile/en-US/?user=bsnyder-bscalesISA 06, Exchange 07 OWA & Win2k8I have a problem when I try to access OWA it doesn't let me in. But if i ping my exchange server then try OWA it works fine. It's the strangest thing. If I try to log the traffic on the ISA server I don't see traffic until I ping the server first. <br /> <br /> After about 3-5 minutes of an idle connect to reverts back to not working then I have to ping it again.<br /> <br /> Ideas?<br /> <br /> Thanks<br /> -BFri, 09 Oct 2009 15:40:18 Z2009-10-19T07:33:27Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/2abe7f9e-1867-45cc-b80d-b11ecedb9b7ehttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/2abe7f9e-1867-45cc-b80d-b11ecedb9b7ejames2k8http://social.technet.microsoft.com/Profile/en-US/?user=james2k8Help with latest version of ISAHi,<br /> <br /> I've been doing a bit of a research on the latest version of ISA and i'm a little confused on the product line.&nbsp; From what I can understand MS forefront TMG is the next version of ISA and it only runs on windows 64-bit version.&nbsp; My problem is that I can only see MS forefront TMG for medium size business on the volume licensing service center website.&nbsp; Our business has more than 400 users so this version wouldn't be suitable for us.&nbsp; I need to a product that will accommodate our needs.&nbsp; I basically need to run latest version of ISA with windows 2008, preferably 32-bit platform.&nbsp; Please help?<br /> <br /> Thanks,<br /> JamesWed, 14 Oct 2009 00:00:50 Z2009-10-19T07:30:14Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/994ca637-d318-49d8-8f6f-1bd1a79aec3fhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/994ca637-d318-49d8-8f6f-1bd1a79aec3fRupandhttp://social.technet.microsoft.com/Profile/en-US/?user=RupandISA server 2006 - FTP server problemsHi<br /><br />I have a problem with ISA server 2006, Windows Server 2003 R2 and&nbsp;FTP session.<br /><br />A FTP server is published through&nbsp;the ISA server. When the FTP client uploads lots of small files&nbsp;the session halts after around 30 secs. When uploading large files (200 mb) everything&nbsp;is going fine.<br />&nbsp;<br />I have ran some different test and the result seems to be that the ISA server is the problem.<br /><br />Anyone who have experienced this problem ?<br />Tue, 06 Oct 2009 13:27:52 Z2009-10-19T01:43:05Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/da8a0087-22ee-4cb3-a1db-23e14dab671dhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/da8a0087-22ee-4cb3-a1db-23e14dab671dJim Harrison IsaDewdhttp://social.technet.microsoft.com/Profile/en-US/?user=Jim%20Harrison%20IsaDewdForefront TMG 2010 Release Cadidate Has Hit The Web!<div style="MARGIN: 0px"><span style="FONT-FAMILY: Calibri, sans-serif; FONT-SIZE: x-small"><span style="FONT-SIZE: 11pt">Hi All, </span></span></div> <div style="MARGIN: 0px"><span style="FONT-FAMILY: Calibri, sans-serif; FONT-SIZE: x-small"><span style="FONT-SIZE: 11pt">&nbsp;</span></span></div> <div style="MARGIN: 0px"><span style="FONT-FAMILY: Calibri, sans-serif; FONT-SIZE: x-small"><span style="FONT-SIZE: 11pt">I&rsquo;m happy to share with you that the Forefront TMG 2010 RC is available for download. Please see the following <a title="ISABlog post" href="http://blogs.technet.com/isablog/archive/2009/10/11/forefront-threat-management-gateway-2010-release-candidate-now-available.aspx">blog post</a> for more information about the RC content. The actual download location is <a title="TMG RC Download link" href="http://www.microsoft.com/DOWNLOADS/details.aspx?FamilyID=e05aecbc-d0eb-4e0f-a5db-8f236995bccd">here</a>.</span></span></div> <div style="MARGIN: 0px"><span style="FONT-FAMILY: Calibri, sans-serif; FONT-SIZE: x-small"><span style="FONT-SIZE: 11pt">&nbsp;</span></span></div> <div style="MARGIN: 0px"><span style="FONT-FAMILY: Calibri, sans-serif; FONT-SIZE: x-small"><span style="FONT-SIZE: 11pt">We are also in the process of updating our Connect web site with German and Japanese versions of TMG RC. If you speak either of these languages, we would be very happy to hear your feedback about them.</span></span></div> <div style="MARGIN: 0px"><span style="FONT-FAMILY: Calibri, sans-serif; FONT-SIZE: x-small"><span style="FONT-SIZE: 11pt">&nbsp;</span></span></div> <div style="MARGIN: 0px"><span style="FONT-FAMILY: Calibri, sans-serif; FONT-SIZE: x-small"><span style="FONT-SIZE: 11pt">As always, thank you for your continued support.</span></span></div> <hr class="sig" /> Jim Harrison Forefront Edge CSSun, 11 Oct 2009 15:14:11 Z2009-10-13T17:58:01Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/34f35fac-b92c-4a1e-958b-6a75cc551e0chttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/34f35fac-b92c-4a1e-958b-6a75cc551e0csalman gilanihttp://social.technet.microsoft.com/Profile/en-US/?user=salman%20gilaniISA 2006 BEHIND ASA FIREWALL AND DNS MESS<p>I have configured ISA 2006 as edge firewall behind ASA , right now i have configured ISA to use internal and external dns through network cards, which has created a big mess , internal users are not able to access websites, often they have click refresh button and then they can access, since ISA does not know which is internal dns query and which is external , i around 10 sites and routing is done through CISCO router , i have configured persitant routes in ISA to handle traffic , i unchecked IP ROUTING feature from ISA , my DOMAIN controllers are in same network as ISA server , but domain controler points to cisco routers as gateway , so in return , when i remove external dns to forward external dns traffic from internal users to outside it does not work, in past if we were to forward dns trafic from DC to external dns , you would need to define ISA as default gateway.<br/>From ASA all traffic is allowed, but i still feel UDP 53 PORT should be opened exceptionally for dns forwarding traffic , for some reason i cannot get name resolution done through AD.<br/><br/>I have configured NAT Rule on ISA From internal to external and both adapters are using private IP adresses , if we use route then some traffic like pop 3 does not work.<br/><br/>Microsoft Input is required on this.<br/><br/>Regards,<br/><br/>Salman Gilani</p>Thu, 17 Sep 2009 17:51:18 Z2009-10-13T17:28:38Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/eef95617-f684-442a-a7c2-893507bcd9bfhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/eef95617-f684-442a-a7c2-893507bcd9bfMerrick59http://social.technet.microsoft.com/Profile/en-US/?user=Merrick59Redirecting client to a specific homepage with ISA or similar tools.<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><a name="OLE_LINK2"></a><a name="OLE_LINK1"><span style="mso-bookmark: OLE_LINK2;"><span style="font-family: Calibri; font-size: small;">There is a network on a public library which client can access to the internet via wireless connection. The problem is we want them to see a specific homepage when they try to access the internet to show them the rules they have to consider while using internet via our servers. Is there any where in ISA or any other similar program that provide this service?</span></span></a></p> <p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-bookmark: OLE_LINK1;"><span style="mso-bookmark: OLE_LINK2;"><span style="font-family: Calibri; font-size: small;">Thank you in advance.</span></span></span></p>Tue, 13 Oct 2009 16:21:22 Z2009-10-14T06:55:34Z