ISA2004 SP2: EventID 14148



Hi,

I've used a webserver quite a long time using one NIC and a hardware router,
IIS 6.0 and host headers. My router broke down, I upgraded to SDSL with a
Cisco 828. I added a second NIC that has a public IP and connects to the
Cisco, e.g. NIC=218.188.188.188 and the GW/Cisco=218.188.188.187. No
firewall is active on the Cisco and all ports are passed through.

I created a rule so LAN users can access the internet through the ISA 2004
server/proxy. This works fine. However, if I create a web server publishing
rule, I'mnot able to access the websites from the internet. A-records are
correctly setup by the provider.

The firewall reports the following error when starting:
The Web Proxy filter failed to bind its socket to 218.188.188.188 port 80.
This may have been caused by another service that is already using the same
port or by a network adapter that is not functional. To resolve this issue,
restart the Microsoft Firewall service. The error code specified in the data
area of the event properties indicates the cause of the failure.

MS Knowledge Base says it has something to do wih ports that are bind by
another service. Most likely it is IIS. But why doesn't this work well. I
checked all settings and rules from reference SBS2003SP1 server and there
are no thing different for web server publishing (HTTP only) and IIS.



Jeroen


.



Relevant Pages

  • Re: IIS / Web Services Security threats
    ... > believe the weblogic designated ports are open in firewall. ... > Sec configuration may make the network little secure. ... >>> My security team thinks allowing communication between the two IIS ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: Very good break in
    ... IIS is not running on this machine. ... netBIOS ports are blocked at the edge. ... of course there are no iis logs. ... just installing patches is not enough to secure a computer... ...
    (microsoft.public.win2000.security)
  • Re: Finally, a secure computer
    ... paranoia in the security aspects of IIS administration. ... security at the IBM website is compromised, ... I ran a port check on 10,000 plus ports (I ... > trouble downloading updates [I'm not sure about AVG pro, ...
    (microsoft.public.inetserver.iis.security)
  • Re: Windows 2003 remote admin access
    ... access done in context of the authenticated browsing account (i.e. ... be limited to areas defined as vdirs in IIS and/or FTP. ... particular ports inbound so access on any other ports shouldn't be ... The user does have HTTP and FTP web authoring access but this ...
    (microsoft.public.security)
  • Re: FTP on IIS6.0 Not Working
    ... have you try ftp.exe command line util to login from remote machine? ... This was already set up before the upgrade to IIS 6.0 and was ... but I wouldn't guarantee the higher ports for that. ... you configure passiveportrange in IIS 6.0. ...
    (microsoft.public.inetserver.iis.ftp)