RE: Client can't tracert public address

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: John [MSFT] (jhawkins_at_online.microsoft.com)
Date: 07/26/04


Date: Mon, 26 Jul 2004 22:15:14 GMT

OK so something is not configured right. Tell me if this works or not. If
you stop the Microsoft ISA Server Control Service (which stops all ISA
Services) and then do this tracert from the ISA Server itself does it work?
If not the you do not have an ISA issue some on the external side of ISA
has a problem with tracert traffic.

If it does not work the turn the service back on and go to the following
site:

www.isatools.org

Download the ISAinfo.exe and run it on your ISA Server. Please send the
attached file back to me directly. Just remove the "online" out of my email
address you see.

Thank you,

John Hawkins
Security Support
Microsoft Corporation

This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
>From: "ricky chan" <chan-r@marubeni.com>
>Subject: RE: Client can't tracert public address
>Date: Fri, 23 Jul 2004 15:32:15 -0400
>Lines: 52
>X-Priority: 3
>X-MSMail-Priority: Normal
>X-Newsreader: Microsoft Outlook Express 6.00.2800.1437
>X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1441
>Message-ID: <e#0jIvOcEHA.1356@TK2MSFTNGP09.phx.gbl>
>Newsgroups: microsoft.public.isa.configuration
>NNTP-Posting-Host: pool-162-83-213-210.ny5030.east.verizon.net
162.83.213.210
>Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
>Xref: cpmsftngxa06.phx.gbl microsoft.public.isa.configuration:7655
>X-Tomcat-NG: microsoft.public.isa.configuration
>
>Hi John,
>
>Thanks for your reply. However, when I tried tracert cnn.com, yahoo.com
>.....etc. They all have the same response as hotmail.com...
>
>
>C:\Documents and Settings\Administrator>tracert www.yahoo.com
>
>Tracing route to www.yahoo.com [216.109.127.28]
>over a maximum of 30 hops:
>
> 1 <1 ms <1 ms <1 ms x.x.x.x <------This will be default gateway
>of external nic.
> 2 * * * Request timed out.
> 3 * * * Request timed out.
> 4 * * * Request timed out.
>
>When I tried to ping yahoo.com, cnn.com...etc. I got "Request timed out."..
>
>
>What's wrong? I didn't touch all the default packet filter that created in
>my isa server, except disable the "ICMP ping response (in)"
>
>I only created one packet filter for the DNS according from
>http://www.isaserver.org/articles/snatdns.html.
>
>IP protocol: TCP
>
>Direction: Outbound
>
>Local Port: All ports
>
>Remote port: Fixed port 53
>
>
>
>This packet is going to use for support the use of TCP port 53 for DNS
>queries.
>
>
>
>I also configure this ISA server as web proxy, it's working fine.
>
>
>
>Please let me know.
>
>
>Thanks
>Ricky
>
>
>



Relevant Pages

  • Re: Microsoft SBS 2000 Internet Permissions Problem
    ... The web site logon page is access via HTTPS port 85: ... If Microsoft Internet Explorer is configured to reference a server that is ... ISA Server 2000 Standard Edition, ...
    (microsoft.public.windows.server.sbs)
  • Re: SMTP email with ISA Server - Securing
    ... Think I'll remove the packet filter I created for port 25 and re-run the ... just in case I've created the packet filter ... >> internet, just letting ISA server handle our firewall needs. ... >> what I need to do to securely allow email to come in through ISA server. ...
    (microsoft.public.backoffice.smallbiz2000)
  • port forwarding (rerouting) with isa server.
    ... I have a question about port forwarding with isa server. ... external nic connected to the router and one internal nic ...
    (microsoft.public.isa)
  • Re: Trying to understand this behavior, Ports in IIS
    ... That tells me the ISA server was accepting the connections. ... assign port 8080. ... In the border router and in the PIX firewall (both devices are "in front of" ...
    (microsoft.public.inetserver.iis.security)
  • Re: Adding Rules for Blackberry ES to ISA 2000 - SOLVED
    ... I found that their connection actually initiated a connection on port ... any lan machine to any outside host:: allow host to ... Note that in order to get outbound bes to work on an isa server (when ...
    (microsoft.public.isaserver)