Intermittent ISA 2004 SP2 Time Outs on port forward - Any assistance would be greatly appreciated!



Hello all,

I have installed an application that has a single ISA 2004 SP2 in front of it.

This application requires HTTP, HTTPS and another port (3102) open to function.

The custom port forward works intermittently from the Internet. I can connect using Telnet to port 3102 successfully repeatedly at certain times and then it will time out randomly at other times. This can range from complete denial of connections to allowing connections a portion of the time. This has been tested from a variety of external ISPs.

SSL and HTTP publishing can connect 100% of the time

When it times out, the connection does not get to the application server after sniffing the traffic.

Connecting directly from ISA to the application server on the custom port, it never times out.

The ISA 2004 SP2 box has 2 NICS in it with a public IP address on one NIC and access through the DMZ to the application server through the other NIC.

As this application is of a real time nature, we need to have as near to 100% connection rate as possible.

Any assistance you can provide would be greatly appreciated as we are being pressured to replace ISA with an alternative solution to attempt to resolve the issue immediately.

Please remove *nospam* to reply via email.

Thanks!

Jay
.



Relevant Pages

  • Re: HTTPS Using Web Proxy
    ... The ISA log displays the following on the error. ... HTTP Method = ... I created a HTPPS 444 protocol set to TCP port 444 and assigned it to my ... At first I was getting a error code: 502 Proxy Error and fixed that by ...
    (microsoft.public.isa)
  • Re: Isa and Mdaemon
    ... ill go through the article and install ISA and Mdaemon. ... > outbound connections over dialup is a bit tricky, ... > Direction: Outbound ... > Local port: All ports ...
    (microsoft.public.isa)
  • Re: Determine HTTP traffic on port other than 80
    ... Then the only thing ISA knows is target IP ... ... HTTP is still HTTP regaurdless of the port. ... Do I have to specify HTTP filter? ...
    (microsoft.public.isa)
  • Re: Publishing services in a dual FW environment
    ... I need port 80 mainly for OWA not for web site hosting. ... That said, my first thought would be remove the NAT router, configure the external nic to connect directly to your cablemodem/dslmodem etc. ... Then re-run the CEICW and allow the necessary services through under the firewall section, this will configure ISA for you. ... The only difference between those services is that SMTP and POP3 have the external interface as "listener" whereas, HTTP and HTTPS have the web proxy listener. ...
    (microsoft.public.windows.server.sbs)
  • Re: Setting up an access rule
    ... I've set up ISA Monitor to watch for failed connections, ... and destination port = 2409 and nothing is showing up. ... HTTP from ISA to Computer2 ...
    (microsoft.public.isa.configuration)