Re: Cannot connect through ISA Server to www.microsoft.com, but can connect via IP address



a) I ran the SBS BPA and the ISA BPA. No issues.
b) EDNS0 was disabled.
c) Shortly after the intial system setup 2 1/2 years ago I enabled the PMTU that ISA Server installation disabled. Internet connections are generally fine. I can browse successfully to MS web from IE on the server, but it almost always times out from some workstations.
d) ISA caching is disabled.
e) ISA rules haven't been touched in about 6 months. This problem only started about a month ago. There aren't many custom rules, and they look ok. ISA allows the connection, but it times out before completing succesfully.

"Les Connor [SBS MVP]" <les.connor@xxxxxxxxxxxx> wrote in message news:492887BB-C678-4C65-9809-8865B66EA3CD@xxxxxxxxxxxxxxxx
I haven't read much of the thread, but have we looked at these things:

a) SBS BPA (link in my signature, below).
b) EDNS0 (should be identified by BPA)
c) MTU (Black hole router detection, search MS KB for "black hole router"
d) Bad ISA cache
e) Custom rules/order in ISA? This can be hit with a big hammer - back up your ISA config, delete all rules, and run CEICW to rebuild. Or, it can be done more slowly, but start by disabling any custom rules.

--
Les Connor [SBS MVP]
________________________
Get the SBS BPA here:
http://support.microsoft.com/kb/940439/en-us


"J. M. De Moor" <papajoe.nospam@xxxxxxxxxx> wrote in message news:%2385FDencIHA.2688@xxxxxxxxxxxxxxxxxxxxxxx
Paul


Wow. If I go to MS, I get at least a dozen entries (both proxy and firewall). If you have the standard rules, the "SBS Protected Networks Access Rule" should have fired for DNS to work between your workstation and SBS (remember that ISA also protects itself from the internal network).

As it stands, the "SBS Microsoft Update Sites Access Rule" should NOT fail for www.microsoft.com, as it did here.

(Your log entries look different from what I am used to...but it sounds like you are completely patched. What ISA 2004 version info does your system show?)

Does this situation change whether or not you set your browser to use a proxy, or whether you use IE or another browser like Firefox?

If you have tried all these things, then it may be time to call PSS. It costs, but the MS ISA people have solved problems for me both times I have had to use them.

You might also consider posting on Shinder's isaserver.org. Pretty good help over there (although Shinder advocates that ISA should be on a separate box).

Joe

.



Relevant Pages

  • Re: RWW Timing
    ... If you have installed ISA, ... Expand the server node and highlight ''Monitoring''. ... In the following website you can find many useful resources related to SBS ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Cannot connect through ISA Server to www.microsoft.com, but can connect via IP address
    ... All workstations with a gigabit network adapter are affected, and none of the workstations with 100Mb. ... if workstation specific - all ISA clients at the same version level? ... Les Connor [SBS MVP] ... Get the SBS BPA here: ...
    (microsoft.public.windows.server.sbs)
  • Re: Switching IP address ranges
    ... ISA Server performs deep inspection of Internet ... inspection of all VPN traffic. ... Forth just because SBS is cheap it does not mean is bad. ... I used to believe on solid state firewalls (which SonicWall is not) but they ...
    (microsoft.public.windows.server.sbs)
  • RE: Remote Connection to SBS-2000
    ... It seems you have changed your SBS 2000 local area IP address. ... we need also to make sure that the ISA have been applied the setting ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: SBS PE - Unable to establish Outbound VPN
    ... configuration is same in the 2 SBS sites and also there is ISA 2004 in good ... Based on my experience, ISA 2004 will check Call ID of the VPN connection, ... | firewall client does not support this and secure NAT must be configured ... |> firewall client application and then sent to the ISA server. ...
    (microsoft.public.windows.server.sbs)

Loading