Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

10060 Timeout on Local Host

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 General] >> General >> 10060 Timeout on Local Host Page: [1]
Login
Message << Older Topic   Newer Topic >>
10060 Timeout on Local Host - 17.Dec.2007 4:01:08 AM   
TheDonMiguel

 

Posts: 13
Joined: 17.Mar.2003
Status: offline
Hello
I've a ISA Server 2006 Standard Edition where I can't connect to the Internet. The ISA Topoligy is a Back-Firewall with 2 NIC's:
  • Internal
    • IP: 172.25.0.111
    • Mask:255.255.255.0
    • GW: -
    • DNS: 172.25.0.101

  • DMZ
    • IP: 192.168.0.2
    • Mask:255.255.255.0
    • GW: 192.168.0.1
    • DNS: -

As described, I add a static rout for the Internal-NIC to the internal GW. This works fine! I also published a Exchange OWA which I can see from external. This works also. But I can't connect to the internet. I get this error:

10060 - A connection attempt failed because the connected party did not properly respond after a period of time, or the established connection failed because the connected host has failed to respond.

A Rule allows traffic "all outbound" from "Local Host" to "External", for test i've chosen "all outbound".I see DNS traffic in the ISA log, but the Site does not display. The external Firewall (astaro) does see requests on port 80. This traffic has also been allowed on this hardware firewall...

Does someone know, how I can solve this Interner Problem? Thanks in advanced

Bye,
Miguel

< Message edited by TheDonMiguel -- 17.Dec.2007 4:03:21 AM >
Post #: 1
RE: 10060 Timeout on Local Host - 17.Dec.2007 5:03:03 AM   
Jason Jones

 

Posts: 2216
Joined: 30.Jul.2002
From: United Kingdom
Status: offline
What network relationships do you have?

_____________________________

Jason Jones (MVP)

Silversands Limited http://www.silversands.co.uk
My Blog: http://blog.msfirewall.org.uk/

Get our NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to TheDonMiguel)
Post #: 2
RE: 10060 Timeout on Local Host - 17.Dec.2007 10:36:26 AM   
TheDonMiguel

 

Posts: 13
Joined: 17.Mar.2003
Status: offline
Hi Jason

The "network rules" has not been changed:

Local Host Access | Route | Local Host > All Networks
Internet Access  | NAT | Internal > External

(in reply to Jason Jones)
Post #: 3
RE: 10060 Timeout on Local Host - 17.Dec.2007 11:39:53 AM   
Jason Jones

 

Posts: 2216
Joined: 30.Jul.2002
From: United Kingdom
Status: offline
So, have you defined rules on the front firewall to allow traffic from 192.168.0.2?

_____________________________

Jason Jones (MVP)

Silversands Limited http://www.silversands.co.uk
My Blog: http://blog.msfirewall.org.uk/

Get our NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to TheDonMiguel)
Post #: 4
RE: 10060 Timeout on Local Host - 17.Dec.2007 12:04:18 PM   
TheDonMiguel

 

Posts: 13
Joined: 17.Mar.2003
Status: offline
Yes, on the Astaro Firewall (Front) is a rule active for 192.168.0.2. In the log are also request visible on port 80...

(in reply to Jason Jones)
Post #: 5
RE: 10060 Timeout on Local Host - 18.Dec.2007 10:11:37 AM   
tshinder

 

Posts: 47644
Joined: 10.Jan.2001
From: Texas
Status: offline
What about the ISA Firewall's network rules?

Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to TheDonMiguel)
Post #: 6
RE: 10060 Timeout on Local Host - 19.Dec.2007 3:34:35 AM   
TheDonMiguel

 

Posts: 13
Joined: 17.Mar.2003
Status: offline
Hi Tom

Thanks for your answer! First I want to thank you for your great work on the website(s) and board(s)!

Concerning the ISA Firewall rules. I checked "ISA Server > Configuration > Networks > Network Rules" and got this information:

Local Host Access | Route | Local Host > All Networks

VPN Clients to Internal | NAT | Quarantained / VPN Clients > Interneal
 
Internet Access  | NAT | Internal / Quarantained / VPN Clients > External

This was by default, I didn't changed anything.

Thanks
Miguel

(in reply to tshinder)
Post #: 7
RE: 10060 Timeout on Local Host - 21.Dec.2007 10:41:17 AM   
tshinder

 

Posts: 47644
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Miguel,

OK, I don't see any rules for the DMZ interface on the ISA Firewall. Just for Internal and VPN clients.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to TheDonMiguel)
Post #: 8
RE: 10060 Timeout on Local Host - 24.Dec.2007 10:22:41 AM   
TheDonMiguel

 

Posts: 13
Joined: 17.Mar.2003
Status: offline
Hi Tom

I thought, the "Local Host Access | Route | Local Host > All Networks " defines the rule for the DMZ (external Interface)?

Thanks and merry christmas
Miguel

(in reply to tshinder)
Post #: 9
RE: 10060 Timeout on Local Host - 26.Dec.2007 11:58:55 AM   
tshinder

 

Posts: 47644
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Miguel,

OK, I thought you had a DMZ interface. You actually have an external and internal interface.

So the problem is that internal clients aren't able to connect to the Internet?

Tom


_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to TheDonMiguel)
Post #: 10
RE: 10060 Timeout on Local Host - 27.Dec.2007 6:37:36 AM   
TheDonMiguel

 

Posts: 13
Joined: 17.Mar.2003
Status: offline
Hi Tom

Ich have an "internal" and "external" interface. The ISA server has been connected with the external-interface to the dmz, there will be a front-firewall (astaro). I do use the ISA server for publishing the exchange-services only. This works fine, but I do not get an Internet-access on the ISA server. This is a problem, when the ISA server should verify a ssl-rootCA.

Thanks
Miguel

(in reply to tshinder)
Post #: 11
RE: 10060 Timeout on Local Host - 28.Dec.2007 10:33:00 AM   
tshinder

 

Posts: 47644
Joined: 10.Jan.2001
From: Texas
Status: offline
Did you enable the System Policy Rule that allows the ISA Firewall to check for CRLs?

Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to TheDonMiguel)
Post #: 12

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 General] >> General >> 10060 Timeout on Local Host Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts