Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

2004 Enterprise - all policy changes require service restart

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> Access Policies >> 2004 Enterprise - all policy changes require service restart Page: [1]
Login
Message << Older Topic   Newer Topic >>
2004 Enterprise - all policy changes require service re... - 9.Dec.2005 5:37:12 PM   
robjhead

 

Posts: 5
Joined: 5.Oct.2005
From: Leeds
Status: offline
Hello,

I am having an issue with ISA 2004 Enterprise Edition.  Whenever any policy changes are made, no matter how minor they are, the change does not take effect until the firewall service has been restarted.  I have replicated my configuration on an ISA 2004 standard server, which I even had running on the same Windows 2003 server and this works fine.

After making changes I have confirmed that the configuration is updated from the array configuration server (which is incidentally on the same server as we are still at a testing phase).  It says that the configuration is synced, but the changes I have made do not take effect until I restart the firewall service, which is obviously not a suitable workaround.

The server has been rebuilt a couple of times to try to get rid of this issue, has three network cards on different subnets and has no alerts either in the ISA MMC or in event viewer.

Can anyone help please!!

Rob

< Message edited by robjhead -- 9.Dec.2005 6:36:27 PM >
Post #: 1
RE: 2004 Enterprise - all policy changes require servic... - 12.Dec.2005 3:48:27 PM   
tshinder

 

Posts: 47663
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Rob,

Remember that changes apply only to new connections. Established connections need to be disconnected or time out before the new rules are applied to them.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to robjhead)
Post #: 2
RE: 2004 Enterprise - all policy changes require servic... - 12.Dec.2005 3:54:58 PM   
robjhead

 

Posts: 5
Joined: 5.Oct.2005
From: Leeds
Status: offline
Tom,

Thanks for your response. 

When you say I need to disconnect and reconnect I'm not sure how this applies to a ping request as ICMP is connectionless as far as I know?  I am experiencing this problem with all protocols including simple ping requests.

Thanks again, any help is very very much appreciated.

Rob

(in reply to tshinder)
Post #: 3

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> Access Policies >> 2004 Enterprise - all policy changes require service restart Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts