Re: ISA SERVER NOT STARTING

From: JACK39 (JACK39_at_discussions.microsoft.com)
Date: 09/15/04


Date: Tue, 14 Sep 2004 20:27:13 -0700

I delete the nat/basic firewall and stop and started the RRAS an tried to
start the firewall but would not start. Today the new hd came an intialize it
and when i stop the rras and delete the nat/basic firewall out of RRAS the
outside email started to come in for the last 3 days. This whole issue
started with the backup exc. failure on Firday when i reboothed the server
when the backup would stuck on the backup job.Below is the Performane report;
on Firday morning after the backup job failed
.
Critical Errors in Application Log

Source Event ID Last Occurrence Total Occurrences
  Backup Exec 34113 9/9/2004 9:03 PM 1
Backup Exec Alert: Job Failed (Server: "BTSERVER1") (Job: "Backup 0014")
Backup 0014 -- The job failed with the following error: The semaphore timeout
period has expired. For more information, click the following link:
http://eventlookup.veritas.com/eventlookup/EventLookup.jhtml
 

Source Event ID Last Occurrence Total Occurrences
  Backup Exec 33152 9/9/2004 9:02 PM 2 *
Adamm Mover Error: Read Not Ready Failure! Error = ERROR_IO_DEVICE Drive =
"EXABYTE 1" {A1C142D8-ED17-4A73-A091-AD966FA290AE} Media = "A0000002"
{012C7F2F-1B9A-4A1E-AA8A-100531A62539} Read Mode: SingleBlock(0), ScsiPass(0)
Write Mode: SingleBlock(1), ScsiPass(1)
 

Source Event ID Last Occurrence Total Occurrences
  Backup Exec 57665 9/9/2004 9:02 PM 1
Storage device "EXABYTE 1" reported an error on a request to read data from
media. Error reported: The semaphore timeout period has expired. . For more
information, click the following link:
http://eventlookup.veritas.com/eventlookup/EventLookup.jhtml
 

Source Event ID Last Occurrence Total Occurrences
  Active Server Pages 5 9/9/2004 2:20 PM 1
Error: The Template Persistent Cache initialization failed for Application
Pool 'DefaultAppPool' because of the following error: Could not create a Disk
Cache Sub-directory for the Application Pool. The data may have additional
error codes..
 

* The text shown is for the most recent occurrence of this event. For more
information, see the Event log.

Critical Errors in Directory Service Log

There were no critical events in the Directory Service Log in the last 24
hours.

Critical Errors in DNS Server Log

There were no critical events in the DNS Server Log in the last 24 hours.

Critical Errors in File Replication Service Log

There were no critical events in the File Replication Service Log in the
last 24 hours.

Critical Errors in Security Log

Source Event ID Last Occurrence Total Occurrences
  Security 537 9/10/2004 5:46 AM 11 *
Logon Failure:
  Reason: An error occurred during logon
  User Name:
  Domain:
  Logon Type: 3
  Logon Process: Kerberos
  Authentication Package: Kerberos
  Workstation Name: -
  Status code: 0xC0000133
  Substatus code: 0x0
  Caller User Name: -
  Caller Domain: -
  Caller Logon ID: -
  Caller Process ID: -
  Transited Services: -
  Source Network Address: 192.168.1.100
  Source Port: 0
 

Source Event ID Last Occurrence Total Occurrences
  Security 546 9/9/2004 10:30 AM 1
IKE security association establishment failed because peer sent invalid
proposal. Mode: Key Exchange Mode (Main Mode) Filter: Source IP Address
66.184.230.138 Source IP Address Mask 255.255.255.255 Destination IP Address
203.196.141.227 Destination IP Address Mask 255.255.255.255 Protocol 0 Source
Port 0 Destination Port 0 IKE Local Addr 66.184.230.138 IKE Peer Addr
203.196.141.227 IKE Source Port 500 IKE Destination Port 500 Peer Private
Addr Attribute: Authentication Method Expected value: RSA Signature with
Certificates Received value: Kerberos (GSSAPI)
 

* The text shown is for the most recent occurrence of this event. For more
information, see the Event log.

Critical Errors in System Log

Source Event ID Last Occurrence Total Occurrences
  adpu160m 9 9/9/2004 9:02 PM 2 *
The device, \Device\Scsi\adpu160m1, did not respond within the timeout
period.
 

Source Event ID Last Occurrence Total Occurrences
  W32Time 29 9/9/2004 7:51 PM 1
The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible. No
attempt to contact a source will be made for 960 minutes. NtpClient has no
source of accurate time.
 

* The text shown is for the most recent occurrence of this event. For more
information, see the Event log.
 

--------------------------------------------------------------------------------
For an updated version of this report, visit the North Carolina Remote Web
Workplace. You can also use Terminal Services to connect to the server and
view the report in the Server Management Console.

To get the latest news and updates about Windows Small Business Server, and
ask questions and collaborate with peers and experts, visit the Windows Small
Business Server Community Web site.

Below is the Performance report as of Tuesday morning at 6;00 am

Critical Errors in Application Log

Source Event ID Last Occurrence Total Occurrences
  Backup Exec 34113 9/14/2004 12:42 AM 1
Backup Exec Alert: Job Failed (Server: "BTSERVER1") (Job: "Backup 0013")
Backup 0013 -- The job failed with the following error: A failure occurred
querying the Writer status. For more information, click the following link:
http://eventlookup.veritas.com/eventlookup/EventLookup.jhtml
 

Source Event ID Last Occurrence Total Occurrences
  ESENT 2002 9/14/2004 12:00 AM 1
tcpsvcs (3928) Shadow copy 2 freeze starting error -2403.
 

Source Event ID Last Occurrence Total Occurrences
  Microsoft Firewall 11011 9/13/2004 5:35 PM 22 *
Microsoft Firewall failed. The failure occurred during Initialization of
Network Address Translation (NAT) because the system call PNATInit failed.
Use the source location 308.1151.3.0.1200.166 to report the failure. The
error code in the Data area of the event properties indicates the cause of
the failure. This failure may be due to the Internet Connection Firewall
(ICF) service being enabled. If it is enabled, please disable the service
named "Internet Connection Firewall (ICF) / Internet Connection Sharing
(ICS)" (SharedAccess). Then, restart the computer. For more information about
this event, see ISA Server Help. The error description is: Access is denied.
 

Source Event ID Last Occurrence Total Occurrences
  Active Server Pages 5 9/13/2004 1:10 PM 2 *
Error: The Template Persistent Cache initialization failed for Application
Pool 'DefaultAppPool' because of the following error: Could not create a Disk
Cache Sub-directory for the Application Pool. The data may have additional
error codes..
 

* The text shown is for the most recent occurrence of this event. For more
information, see the Event log.

Critical Errors in Directory Service Log

There were no critical events in the Directory Service Log in the last 24
hours.

Critical Errors in DNS Server Log

There were no critical events in the DNS Server Log in the last 24 hours.

Critical Errors in File Replication Service Log

There were no critical events in the File Replication Service Log in the
last 24 hours.

Critical Errors in Security Log

Source Event ID Last Occurrence Total Occurrences
  Security 537 9/13/2004 11:47 PM 3 *
Logon Failure:
  Reason: An error occurred during logon
  User Name:
  Domain:
  Logon Type: 3
  Logon Process: Kerberos
  Authentication Package: Kerberos
  Workstation Name: -
  Status code: 0xC0000133
  Substatus code: 0x0
  Caller User Name: -
  Caller Domain: -
  Caller Logon ID: -
  Caller Process ID: -
  Transited Services: -
  Source Network Address: 192.168.1.100
  Source Port: 0
 

Source Event ID Last Occurrence Total Occurrences
  Security 529 9/13/2004 5:11 PM 3 *
Logon Failure:
  Reason: Unknown user name or bad password
  User Name: administrator
  Domain: BTSS1
  Logon Type: 7
  Logon Process: User32
  Authentication Package: Negotiate
  Workstation Name: BTSERVER1
  Caller User Name: BTSERVER1$
  Caller Domain: BTSS1
  Caller Logon ID: (0x0,0x3E7)
  Caller Process ID: 1000
  Transited Services: -
  Source Network Address: 127.0.0.1
  Source Port: 0
 

* The text shown is for the most recent occurrence of this event. For more
information, see the Event log.

Critical Errors in System Log

Source Event ID Last Occurrence Total Occurrences
  W32Time 29 9/14/2004 1:43 AM 4 *
The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible. No
attempt to contact a source will be made for 30 minutes. NtpClient has no
source of accurate time.
 

Source Event ID Last Occurrence Total Occurrences
  adpu160m 5 9/13/2004 7:00 PM 1
A parity error was detected on \Device\Scsi\adpu160m1.
 

Source Event ID Last Occurrence Total Occurrences
  IPRouterManager 20193 9/13/2004 6:25 PM 2 *
An error occured while configuring IP packet filters over EXTERNAL. This is
often the result of another service, e.g Microsoft Proxy Server, also using
the Windows 2000 filtering services.
 

Source Event ID Last Occurrence Total Occurrences
  Service Control Manager 7024 9/13/2004 5:35 PM 22 *
The Microsoft Firewall service terminated with service-specific error 213005
(0x3400D).
 

Source Event ID Last Occurrence Total Occurrences
  TermServDevices 1111 9/13/2004 1:55 PM 6 *
Driver PDF Compatible Printer Driver required for printer Genesis PDF Maker
is unknown. Contact the administrator to install the driver before you log in
again.
 

Source Event ID Last Occurrence Total Occurrences
  examc 15 9/13/2004 8:22 AM 1
The device, \Device\Changer0, is not ready for access yet.
 

* The text shown is for the most recent occurrence of this event. For more
information, see the Event log.
 

--------------------------------------------------------------------------------
For an updated version of this report, visit the North Carolina Remote Web
Workplace. You can also use Terminal Services to connect to the server and
view the report in the Server Management Console.

To get the latest news and updates about Windows Small Business Server, and
ask questions and collaborate with peers and experts, visit the Windows Small
Business Server Community Web site.

Thanks
jack

"Chris Puckett [MSFT]" wrote:

> You have the nat/basic firewall loaded in RRAS. This will conflict with
> ISA.
>
> So long as you are not using VPN to access the server at the moment, try
> stopping the Routing and Remote Access Service. Then see if you can start
> the MS Firewall service.
>
> You can right-click nat\basic firewall and choose delete to remove it from
> RRAS.
>
> Chris Puckett, MCSE
> Microsoft Small Business Server Support
>
>
> This posting is provided "AS IS" with no warranties, and confers no rights.
> --------------------
>
>



Relevant Pages

  • Re: Event ID 529
    ... First is a hardware firewall that sits on the perimeter of your network and requires that your users give user names and passwords, different from those for the network. ... Sometimes the Logon Type is different, also the User Name can be ... Computer: <SERVER NAME> ... Caller User Name: $ ...
    (microsoft.public.windows.server.sbs)
  • Re: Another security question/issue.
    ... Time to audit your server and workstations with AV, Malware, and installed ... Logon Process: Advapi ... Caller User Name: servername$ ... Source Port: - ...
    (microsoft.public.windows.server.sbs)
  • Re: Logon 529 Errors
    ... Default SMTP Virtual Server properties-Access tab-Relay ... Connection filtering is different from what inna is attempting, ... These are almost surely SMTP logon attempts, ... Caller User Name: DELLSERVER$ ...
    (microsoft.public.windows.server.sbs)
  • Re: Logon 529 Errors
    ... connection has been found on the black list, my DNS server ... Connection filtering is different from what inna is attempting, ... These are almost surely SMTP logon attempts, ... Caller User Name: DELLSERVER$ ...
    (microsoft.public.windows.server.sbs)
  • ISA server authentication problem!!!!HHHEEEELLLLPPPPPPP!!!!
    ... We have a problem with firewall client on our domain.ISA Server cannot ... AUTHORITY\SYSTEM ISASERVER "Logon Failure: ... Caller User Name: - ...
    (microsoft.public.isaserver)