Proxy chain loop errors

Tech-Archive recommends: Fix windows errors by optimizing your registry



I am getting these errors from my ISA2004 server.

ISA Server detected a proxy chain loop. There is a problem with the
configuration of the ISA Server routing policy.

I have one ISA Server on a small network. The error is happening because I
have 2 external network cards that both have gateway settings. One is a
cable ISP and one is DSL. I'm not trying to do load balancing or have some
users go out through the cable modem and others through the DSL modem or
anything like that. It's just redundancy/availability. I have a mail
server published and I have the DNS (outside service) setup with 2 MX
records. One for the cable IP and one for the DSL IP, this way if one goes
down the other should be available. Also my network can still access the
internet if one of the ISPs goes down. It doesn't need to be automatic, I
can go and disable the NIC for the ISP that's down if necessary. But I
think dead gateway detection should make everything work without me doing
anything. The second external NIC must have a gateway assigned or outside
mail servers will not be able to make SMTP connections to that IP. It's not
like I can setup a route for every mail server out there.

A lot of what I've been reading has been saying that windows doesn't support
multiple gateways so ISA doesn't either. But that's not entirely true.
Windows does support multiple gateways and does dead gateway detection.
What windows won't do is know if a packet should go out on gateway A or
gateway B. What windows will do is send all packets out on the default
gateway (the one on the NIC listed first in network advanced setting
(adapters and bindings). If that gateway is down it will try the next
gateway in the list which has a default entry in the routing table. That
will now be the new default gateway until something happens to that gateway.
I'm not trying to control which gateway they go out on. I don't really care
which NIC the internet packets go out on as long as they go out.

I think I have everything setup correctly. Everything works fine, but after
a couple days I started getting these warnings sporadically. Looking at the
ISA server logs, the times of the warnings correspond to http requests
(antivirus updating itself) that are going out on NIC B instead of NIC A. I
don't know why this would happen unless the cable modem lost its connection,
but again, it doesn't really matter since both NICs send the packets out.

In my case, can I ignore these warnings?

Sorry for the long post, I thought the details were important.

Thanks in advance,
jim


.



Relevant Pages

  • Re: ISA 2K4 dropping Internet Gateway
    ... The only way I've been able to get the gateway back when it drops is either ... I have my ISA ... I have tried other nics as well that I know are good, ... >> How to Set up an ISA Server with a Cable Modem Connection. ...
    (microsoft.public.isa)
  • Re: Alert Configuration Error, please explain.
    ... in the gateway, sounds like sloppy work or that the gateway makes some assumptions ... Microsoft Internet Security & Acceleration Server: Partners ... Microsoft ISA Server Partners: Partner Hardware Solutions ...
    (microsoft.public.isa)
  • Re: ISA 2004 Access Denied Error
    ... You do not need a default gateway on the internal NIC. ... Make sure your Internal address range (under Network objects in the ... toolbox) correctly reflects the 10.x.x.x range of your lab internal net. ... > The internal NIC on the ISA server is configured with an IP address on ...
    (microsoft.public.isaserver)
  • Re: Eventid 15108... spoof address ????
    ... the ISA server identifies the spoof attacking according to the ... > the internal network object). ... > server could receive some spoof attacks from the internet. ... > to the same internal default gateway address as the ISA Server computer. ...
    (microsoft.public.windows.server.sbs)
  • Re: Internal network cannot get internet access
    ... I have done as you suggested but no progress and the ISA server now cannot ... Mask 255.255.255.0 ... Gateway left blank ... Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa.configuration)