ISA 2006 and Listeners Part 2!



Hello All

I just tried publishing my website by using a listener that was bound
to a second IP address on my external interface of my ISA 2006 box, and
for the life of me I cannot get this working. I was doing this because
I am using FBA for OWA and the OWA listener can't be used for
publishing other websites.

Looking at the logging I can see that connections get denied by the
default rule and the client receieves a 403 - The server denied the
specified reource locator.

The weird thing here is that the destination IP address for the denied
packet is for the primary IP address on the same NIC as opposed to the
websites IP address that is detailed in the web publishing rule.

The listener is set up to listen on the secondary address and all looks
good to me. Anyone have any ideas what is going on here.

My ISA firewall is configured in a three legged configuration and is
the primary firewall control.

External - DMZ and Internal Networks

Any help greatly appreciated!!!

Thanks

AJ

.



Relevant Pages

  • ISA 2004 & Link Translation
    ... I'm using ISA 2004 and publishing a couple of websites. ... Am I doing something wrong or am I expecting too much? ...
    (microsoft.public.isa)
  • Re: Web listener question
    ... >> I have a webserver that sits alone in the perimeter network. ... When I try to use web publishing rule and a web ... >> listener I keep getting blocked by the ENTERPRISE Default policy. ... As far as ISA is concerned, ...
    (microsoft.public.isa)
  • Re: ISA 2004 Publishing OWA/Mobile/ActiveSynch on SBS 2003
    ... You're stuck on the idea that only ISA has listeners. ... access rules are not relevant to this problem. ... I have a HTTPS listener for SSL traffic to OWA etc. ... The Web Proxy filter failed to bind its socket to 192.168.10.1 port 443. ...
    (microsoft.public.isa.publishing)
  • Re: Wind Mobile Pushservice verweigerte Verbindung
    ... sobald du mit ihm auf den isa listener zugreifst wird der sogenannte user-agent-string ausgewertet. ... sobald der isa feststellt, das es sich hierbei nicht um einen browser handelt versucht er dir nicht die fba sondern die standardauthentifizierung anzubieten. ... das fba mit ldap funzt beweist dein owa. ... Client over SSL zu ISA - stop - ISA over SSL zu XMS vorher noch per LDAP gucken, ...
    (microsoft.public.de.german.isaserver)
  • Re: Wind Mobile Pushservice verweigerte Verbindung
    ... sobald du mit ihm auf den isa listener zugreifst wird der sogenannte user-agent-string ausgewertet. ... sobald der isa feststellt, das es sich hierbei nicht um einen browser handelt versucht er dir nicht die fba sondern die standardauthentifizierung anzubieten. ... das fba mit ldap funzt beweist dein owa. ... Client over SSL zu ISA - stop - ISA over SSL zu XMS vorher noch per LDAP gucken, ...
    (microsoft.public.de.german.isaserver)

Loading