Re: 0xc0040017 FWX E TCP NOT SYN PACKET DROPPED
From: penrose.l (anonymous_at_discussions.microsoft.com)
Date: 08/30/04
- Next message: penrose.l: "Re: 0xc0040017 FWX E TCP NOT SYN PACKET DROPPED"
- Previous message: anonymous_at_discussions.microsoft.com: "Re: Access to a website on a different port"
- In reply to: Jim Harrison [MSFT]: "Re: 0xc0040017 FWX E TCP NOT SYN PACKET DROPPED"
- Next in thread: penrose.l: "Re: 0xc0040017 FWX E TCP NOT SYN PACKET DROPPED"
- Messages sorted by: [ date ] [ thread ]
Date: Mon, 30 Aug 2004 09:49:31 -0700
Hi Jim ,
In reaction to your posting :
We are providing the ISA server and all the cisco routers
in our network. All cisco's are ( to our best knowledge )
properly configured , and the Microsoft network we have is
entirely based on the MSA infrastructure.
In short the problem can be brought down to this :
client - ISA server - Fileserver ( 2003 enterprise )
when the client copies a file to the fileserver , we get
lots and lots of SYN blocks on the ISA firewall and the
file is cancelled ( the remote network location doesn't
exist anymore or something the client gets ).
Now , we have lots of fileservers ( with different
hardware ) and lots of clients with different hardware ,
and these SYN drops are occuring on all our network
segments connected by our ISA , which lets us believe the
problem is in the ISA.
Is there a way to disable bad SYN packet dropping on the
ISA server as a means of testing ?
We have tried so far :
Disable SYNAttackprotect everywhere ( also ISA ) Disable
Offline files
Disable Caching on harddrives
Disable LargeSystemCache registry hack
Disable DisablePagingExec
We have made rules Allow All
We have upgraded all drivers
We have installed all patches
This is our ISA hardware :
Dell PowerEdge 1550 with Quad Nic Intel Pro1000 / MT
any advice ?
Lex P
- Next message: penrose.l: "Re: 0xc0040017 FWX E TCP NOT SYN PACKET DROPPED"
- Previous message: anonymous_at_discussions.microsoft.com: "Re: Access to a website on a different port"
- In reply to: Jim Harrison [MSFT]: "Re: 0xc0040017 FWX E TCP NOT SYN PACKET DROPPED"
- Next in thread: penrose.l: "Re: 0xc0040017 FWX E TCP NOT SYN PACKET DROPPED"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|