Re: Clients get wrong IP for ISA server

From: J.C. Hornbeck [MSFT] (jchornbe_at_online.microsoft.com)
Date: 03/16/04


Date: Tue, 16 Mar 2004 09:10:17 -0600

Tony is absolutely right. When you do this also check to make sure that the
external interface is not dynamically registering that address in your DNS
as well, otherwise it may come right back. The checkbox for this is within
the properties of the network connection -> properties of TCP/IP ->
Advanced -> DNS tab.

-- 
J.C. Hornbeck, MCSE
Microsoft Product Support
NOTE: Please reply to the newsgroup and not directly to me. This allows
others to add to and benefit from these threads and also helps to ensure a
more timely response. Thank you!
This posting is provided "AS IS" without warranty either expressed or
implied, including, but not limited to, the implied warranties of
merchantability or fitness for a particular purpose.
"Tony Su" <anonymous@discussions.microsoft.com> wrote in message
news:c2e601c408a5$8a9149e0$a501280a@phx.gbl...
> Absolutely yes,
> But most people just say they don't know why they can't
> access the Internet, congrats on determining perhaps the
> number one problem for FW and Web proxy client failure.
>
> This should make sense to you...
> - The Web and FW clients by default are configured to
> connect to the ISA server by machine name
> - ISA boxes usually are multi-homed
> - Particularly if DNS is running on ISA, <by default MS
> DNS will create an A record for every IP address on the
> box>.
>
> So, put all that together you are looking at least two IP
> addresses which are bound to most ISA boxes (WAN and LAN
> addresses) and if you add additional addresses for various
> reasons (multiple websites? multiple SMTP servers?) you'll
> exacerbate the problem... because at the least the
> outbound Web Listener will be bound only to the LAN
> interface and may even be bound to only one address on the
> LAN interface.
>
> So, the solution should be to remove all unnecessary A
> records in your DNS to force client resolution <only> to
> the primary LAN address.
>
> Tony Su
>
>
>
>
>
>
> >-----Original Message-----
> >Hi,
> >
> >Occasionally, proxy clients in my lan incorrectly
> resolved IP address for
> >ISA server so they could not go out to internet.  I
> pinged the ISA server
> >and got replied from an IP that was designated for VPN
> clients connecting
> >from internet to the ISA server.  Our DNS did not record
> the VPN IP.  I had
> >to bounce the ISA server and nbtstat workstations.
> Sometimes it works right
> >away.  At others, it took like 15 mins.  Has anyone seen
> this problem?
> >
> >My config:
> >Win2k sp4
> >ISA2k sp1 and hotfix
> >All workstations are win2k pro
> >
> >TIA,
> >
> >Cal
> >
> >
> >.
> >


Relevant Pages

  • Re: ISA Server and Domain Controller
    ... how can I resolve external DNS ... > If this is correct you'll need to join the ISA server computer to the AD ... >> Ayon kay Jens Baier: ... >>> legitimate access for your clients. ...
    (microsoft.public.isaserver)
  • ISA Installed, but DNS problem. HELP!!! Please ;-)
    ... enabled) on a Win Sever 2003 Computer with two NIC´s (one for the LAN ... Controller of my Domain and last but not least, the DNS server of the ... the proxy and then to the Internet and my internal message software ... but I don't have any Idea on how to configure this for the ISA Server ...
    (microsoft.public.isaserver)
  • Re: Allow Remote Subnet to Authenticate
    ... LAN router doesn't have the ISA servers as it's gateway. ... The ISA server internal nic is in the 10.0 subnet and C/TS on that subnet ... DNS I don't see as being even relevant to this,...but the details of the ...
    (microsoft.public.isa.configuration)
  • Re: CEICW fails - several errors
    ... On the WAN NIC of your server the DNS has to point to the LAN IP. ... Ethernet adapter Internet Connection: ... I immediately checked and ISA Server ... Management said that Web Proxy, Firewall and ...
    (microsoft.public.windows.server.sbs)
  • Re: CEICW fails - several errors
    ... On the WAN NIC of your server the DNS has to point to the LAN IP. ... Make those changes and try the CEICW ... Ethernet adapter Internet Connection: ... I immediately checked and ISA Server ...
    (microsoft.public.windows.server.sbs)