RE: 504 Proxy timeout only with SSL traffic



Ok, a few questions:

Is the Internal and DMZ network separated within ISA with two different
network objects? or are they both internal?

What are the network rules between the two networks? NAT/Route?

Does your ISA Server have 3x NICs? ie: one for external, one for DMZ and one
for Internal?


--
David Maskell - BUI
MCSE:Security,Messaging, CISSP.
http://www.bui.co.za


"Always remember to rate the posts!"


"bluenetadmin" wrote:

Hi,

Here is a little more detail on the problem. The webserver sits wihtin our
DMZ and externally anyone can hit the website and all pages whether normal or
secure come up properly. It is only from within the inside that we are
encountering a problem getting to the secure (SSL) Pages.

We have two ISA 2004 Servers both at same level of service packs which is
SP3 for ISA Server 2004 and SP1 for Windows 2003 server.

One thought I had is perhaps it is seeing it on the same network but they
are clearly on different networks. The internal is using a 192 scheme and
the DMZ is using a 10. scheme

This problem only came about after applying service pack 2 for iSA 2004 and
then in thinking that it was a bug I proceeded to apply sp3 to the same
server for ISA 2004.

Thanks for your help

David


"David Maskell - BUI" wrote:

Hi,

This sounds like a very strange problem, its a bit unusual that you can
access the HTTP but not HTTPS pages, can you access the HTTPS pages directly
on the server? Have you checked the IIS Settings?

If the web server works on itself, ie browsing to the localhost, then it may
have something to do with how the proxy is set up, although, in my honest
opinion, it seems to be more the web server than ISA.

Can you access HTTPS pages locally on the webserver is what we need to look
at first?

--
David Maskell - BUI
MCSE:Security,Messaging, CISSP.
http://www.bui.co.za


"Always remember to rate the posts!"


"bluenetadmin" wrote:

Hi I am hoping that someone can help me. We have been running ISA Server
2004 for sometime and then we had a problem with email so I decided to go to
service pack 2 for ISA 2004 server and I started to get this error mentioned
below. I figured perhaps if I went to the next service pack which is SP3 it
might go away and it has not resolved it yet. I am trying to access https
pages on a webserver that is located on our DMZ. I am able to reach the
webserver pages that are not secure pages but once I try to go to the secure
pages it results in this error mentioned below. I have searched all over the
web for a possible fix and I have not been able to figure this out. Any help
would be appreciated. Thanks

Network Access Message: The page cannot be displayed

Technical Information (for Support personnel)
Error Code: 504 Proxy Timeout. The connection timed out. For more
information about this event, see ISA Server Help. (10060)
IP Address: xxx.xxx.xxx
Date: 9/17/2007 5:36:34 PM
Server: server.at.work
Source: proxy


.



Relevant Pages

  • Re: ISA 2006 configuration question - multiple VLANs and domains
    ... very familiar with network segments vs. domains et. al. ... multihomed ISA 2006 server forward a DHCP request to the proper VLAN ... ISA is a Firewall Product designed to protect a network from the Internet. ...
    (microsoft.public.isa.configuration)
  • RE: Firewall service and remoteaccess service shut down frequently
    ... Do you have run the CEICW after installing the ISA components? ... please open SBS server management console, ... Click the Add Adapter button, and add your internal network adapter ... Meanwhile, from the subject, you said you the firewall service and RRAS ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN breaks after installing patches
    ... I have just received your email due to some network traffic problems. ... access the network shares was denied by ISA Server. ... Open the Server management console, navigate to "Internet and E-mail", ...
    (microsoft.public.windows.server.sbs)
  • Re: Connect the SBS to a remote IIS for Internet Printing
    ... the server can access the Internet with no problems at all. ... Checking network connection, and after a few seconds it says The ... the problem is cause by the configuration of ISA. ...
    (microsoft.public.windows.server.sbs)
  • Re: Where do I put Exchange Server?
    ... I'm not sure of OWA can be front-ended by a lone IIS server; again, the DMZ ... isn't the right place for it with ISA 2000. ... > its internal network only. ...
    (microsoft.public.isa.configuration)