REPOST - Rules failing in ISA

From: Jamie Turner (jamieturner_at_fernhillsolutions.net)
Date: 03/10/05


Date: Thu, 10 Mar 2005 14:19:35 -0000

Apologies for the repost but this is a real problem for us - if anyone from
MS is watching some help would be greatly appreciated!

JT.

We have a website which is hosted on 2 2003 web servers, load balanced with
a multicast NLB cluster (class c affinity). This is published to the world
through 2 ISA rules - one for HTTP and one for HTTPS. We don't use web
publishing because it's important for the web servers to see the user's IP
address - instead we have 2 server publishing rules to achieve this. We're
using ISA 2000 (non caching) on W2K.

Several times a day, external clients get connection refused errors in their
browsers. If you telnet on port 80 to the servers externally, you also get
connection refused. From the clean side of the firewall, you can browse and
telnet to the the NLB cluster and each host servers fine - I don't think
it's anything to do with IIS or NLB. What's weird is that while the site
appears stalled for about 5-10 seconds, you can connect externally on
HTTPS/443 without a problem. It seems to be specific to the rule.

There are no items in the event log or ISA logs that indicate a problem. I
can't see any weird network errors, IIS or NLB problems - it looks like ISA
is losing the server publishing rule.

Can anyone help? This is causing us real problems.

Thanks in advance.

JT.



Relevant Pages

  • Re: REPOST - Rules failing in ISA
    ... server's running SP2 in ISA and SP4 for Win2k. ... > You don't say what patch level your ISA is at. ... > a multicast NLB cluster. ... > publishing because it's important for the web servers to see the user's IP ...
    (microsoft.public.isaserver)
  • Re: REPOST - Rules failing in ISA
    ... You don't say what patch level your ISA is at. ... a multicast NLB cluster. ... publishing because it's important for the web servers to see the user's IP ... address - instead we have 2 server publishing rules to achieve this. ...
    (microsoft.public.isaserver)
  • Rule fails every few minutes
    ... through 2 ISA rules - one for HTTP and one for HTTPS. ... publishing because it's important for the web servers to see the user's IP ... address - instead we have 2 server publishing rules to achieve this. ...
    (microsoft.public.isaserver)
  • Re: 70-291 test - unfair
    ... and looked through the objectives to see if I had sat the correct exam! ... If I knew that ISA servers ...
    (microsoft.public.cert.exam.mcsa)
  • Re: POP3 E-mail Issue After Swing Migration
    ... only be using POP3 and SMTP servers under corporate control. ... changing it in the ISA Server Management Console, Server, Configuration, ... how in the heck do I fix this?! ...
    (microsoft.public.windows.server.sbs)