RE: Load Balance Error Message
- From: Shijaz <Shijaz@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Thu, 3 Aug 2006 05:11:02 -0700
Under Configuration --> Networks --> Network Rules, did u create a "Route"
relationship between Internal and External networks?
Firstly, creating a "Route" between external and internal networks is a
not-so-good idea.
Secondly, if you can't live without the "Route", then you need to load
balance your external network. If you can't loadbalance your external
network, then you have to live with the error :).
For ISA networking best practices, see:
http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/bp_networks.mspx
--
Shijaz
MCSE:Security, CCNA
www.shijaz.com/isaserver
"Henri" wrote:
Hello,.
i have problems in my ISA Array, below my config.
ISA Server 2006 Ent (previously ISA server 2004, same error message did
appear (listed below).
Multi Server Array (2 Servers)
Internal 172.16.1.0/24
DMZ 10.10.10.0/24
Array communication 192.168.249.0/24
External 195.35.xxx.xxx (ISA #1) / 82.92.xxx.xxx (ISA #2)
Internal network is load balanced
DMZ network is also load balanced,
External network is NOT Load balanced because this are 2 different DSL lines
Network rules:
- Route rule between Perimeter and internal
- Nat rule beteen external and internal/perimeter
Everything works fine, but i want to get rid of this annoying message below,
anyone ideas?
If i read the error message, it looks like the problem is related that i
load balance my internal and not my external network?
Error Message:
i have an reoccuring error message in the application log, the error is also
logged in the alers section of the dashboard.
Event ID 21215:
An inconsistency in the Network Load Balancing (NLB) configuration may
result in inconsistent handling of traffic between the Internal network
and the External network. When a network rule specifying a route
relationship is defined between two networks, NLB must be enabled (or
disabled)
on both networks. To enable NLB for IPsec remote site networks, enable NLB
on the network containing the local tunnel endpoint.
To enable NLB for VPN site-to-site and VPN client networks, enable NLB on
the selected access networks.
Alternatively, for the VPN Client network, you can designate a router for
routing traffic according to the static address pool.
Regards Henri
- Follow-Ups:
- Re: Load Balance Error Message
- From: Henri
- Re: Load Balance Error Message
- References:
- Load Balance Error Message
- From: Henri
- Load Balance Error Message
- Prev by Date: Load Balance Error Message
- Next by Date: Re: Load Balance Error Message
- Previous by thread: Load Balance Error Message
- Next by thread: Re: Load Balance Error Message
- Index(es):
Relevant Pages
|