Re: ISA time out, no ACK received

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: n00mis (noomis_slack(remove_this)_at_go2.pl)
Date: 03/30/04


Date: Tue, 30 Mar 2004 09:30:34 +0200

Hmm...

I sniffed traffic by external box and this is what I've got:

On ISA box:
telnet 80.72.33.39 80

On external box with tcpdump:
09:10:28.831360 my.isa.box.56281 > 80.72.33.39.http: S [tcp sum ok]
3765883928:3765883928(0) win 16384 <mss 1460,nop,nop,sackOK> (DF) (ttl 128,
id 42348, len 48)
09:10:31.772709 my.isa.box.56281 > 80.72.33.39.http: S [tcp sum ok]
3765883928:3765883928(0) win 16384 <mss 1460,nop,nop,sackOK> (DF) (ttl 128,
id 42427, len 48)
09:10:37.788305 my.isa.box.56281 > 80.72.33.39.http: S [tcp sum ok]
3765883928:3765883928(0) win 16384 <mss 1460,nop,nop,sackOK> (DF) (ttl 128,
id 42581, len 48)

As you can see ISA box is sending SYN packets but there is no any response
from Akamai host.
The strange thing is that other machine on the same external ip address
works good.

I have no idea what's going on here...

Is that possible that ISA's SYN pocket is corrupted?

n00mis

"Jim Harrison [MSFT]" <jmharr@online.microsoft.com> wrote in message
news:e$EUgGAFEHA.2524@TK2MSFTNGP09.phx.gbl...
> Akamai seems to be causing many problems for folks lately:
>
> nslookup download.microsoft.com
>
> Non-authoritative answer:
> Name: a767.ms.akamai.net
> Addresses: 80.67.66.63, 80.67.66.57, 80.67.66.55, 80.67.66.54
> Aliases: download.microsoft.com, dl-geodir.microsoft.akadns.net
> loadsplit-dom-dl.microsoft.akadns.net,
download.microsoft.com.d4p.net
>
> You could try restarting the web proxy service.
> If that works, you should reduce the DNS cache TTL for the web proxy
service.
> See
http://isaserver.org/tutorials/ISA_Clients__Part_1__General_ISA_Server_Configuration.html
for details.
>
> --
> Jim Harrison [ISASE]
> Read the help, books and articles!
>
> This posting is provided "AS IS" with no warranties, and confers no
rights.
>
>
> "n00mis" <noomis_slack(remove_this)@go2.pl> wrote in message
news:%23T%238Sg8EEHA.1456@TK2MSFTNGP09.phx.gbl...
>
> Hi!
> I have a problem with downloading anything from download.microsoft.com
> site.
>
> ISA Server reports "10060 - Connection timeout" error message.
>
> I tried to bypass ISA and it works.
>
> Next, I tried to 'telnet download.microsoft.com 80' from ISA box and
capture
> network traffic by Network Monitor. It shows that ISA sends packet with
SYN
> flag three times and gives up because no SYN-ACK response was received.
>
> Connecting to other sites works good.
> I don't have any visible rules that could this traffic. Also I don't have
> any idea how many sites is blocked in the same way (download.microsoft.com
> is
> the only one I've noticed).
>
> Can anyone help me with this problem? Thanks.
>
> n00mis
> ---------------------------------------
> Details:
> ISA Server 2000 SP1 FP1 (Version: 3.0.1200.235 SP1 FP1)
> Windows 2003 Server - as a domain member
>
> PS: Excuse me for this mess in previous post.
>
>
>
>
>



Relevant Pages

  • Re: MS Access cannot connect to external site via FTP
    ... Jim Harrison (ISA SE) ... Each workstation on this network has the firewall client installed. ... BTW, pardon my ignorance, but what is the difference between a web proxy ... Destination for "direct access" concerning the web proxy service. ...
    (microsoft.public.isa)
  • Re: ISA server 2004 and Bluecoat proxy
    ... i want to ask about event 14130 that related to web proxy chain fauilire. ... If you were able to work around the upstream proxy server, ... upstream ISA Server, you might want to change it back. ... SecureNAT,Firewall clients) and you can disable it. ...
    (microsoft.public.isa.configuration)
  • Re: ISA server 2004 and Bluecoat proxy
    ... second as i told you ((http web proxy filter)) is designed for ( ... SecureNAT,Firewall clients) and you can disable it. ... the only problem that i have that many erros appear in ISA state that WEb ... server that is configured as firewall server. ...
    (microsoft.public.isa.configuration)
  • Re: Figuring out my socks firewall and web proxy
    ... There is no "Socks Service" with ISA. ... For things that aren't provided by the Web Proxy Service you must use the ... The Mac does this by either using ISA as it's Default ...
    (microsoft.public.win2000.networking)
  • RE: ISA 2000 Problem - SBS2003
    ... identification" option after you gather the ISA info? ... please click the Settings button ... Stop the Web Proxy service. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)