Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Clients unable to access external locations

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 General] >> Installation >> Clients unable to access external locations Page: [1]
Login
Message << Older Topic   Newer Topic >>
Clients unable to access external locations - 25.Apr.2001 4:41:00 PM   
Dr.James

 

Posts: 8
Joined: 10.Apr.2001
Status: offline
Ok. Big problems. I have ISA on a PC with two NICS, presumably between the DMZ and the Internal network. So the PC that the ISA is on, has full access to all internet applications.

However, the machine which holds our active directory, (and DNS server) and all other internal clients are unable to get out of the internal network.

These can all get ping responses from each other... however, the DNS machine, and the client machine can not get a response when trying to ping outside of the internal network.

The machine that hosts the ISA can get response from anywhere.

Although, I'm really not sure if the ISA machine is configured properly, as even with the default settings, I have application capabilities (ie. MSN Messenger, http, )without having created those packet filters, or opening the ports!

I have tried with the DMZ IP address in the LAT and without... and still there is no luck with it!

What am I doing wrong and why is this not working??

[This message has been edited by Dr.James (edited 25 April 2001).]

Post #: 1
RE: Clients unable to access external locations - 26.Apr.2001 6:47:00 AM   
tshinder

 

Posts: 47663
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Dr. James,

I'm a bit unclear on how your configuration is set up. If you have two NICs, one should be the internal interface and the other the external interface. Put all your intenral IP addresses in the LAT and do *not* put your external address in the LAT.

You can create an "all open" Protocol Rule per the instructions in the "getting started" article at www.isaserver.org/shinder

This will allow SecureNAT clients to all protocols that have a Protocol Definition and all protocols for Firewall Clients.

HTH,
Tom

------------------
Tom Shinder
http://www.isaserver.org/shinder/


Get it Here!


(in reply to Dr.James)
Post #: 2
RE: Clients unable to access external locations - 26.Apr.2001 9:32:00 AM   
Dr.James

 

Posts: 8
Joined: 10.Apr.2001
Status: offline
Hi Tom,

I have an internal and external NIC set up. I don't have the external address in the LAT, but only tried that as a firefighting method. I only saw a change however in the ISA host machine.

I also have a packet filter and protocol rules which allows any protocol all the time. "Open Access" it seems. This however, is also only applicable on the ISA host, but not the clients.

Any other suggestions on potential configuration problems? Or whatever else I'm doing wrong?

I guess I should also let you know that the default gateway is set up as the ISA host Ip address, so we can eliminate that from potential causes of problems.

[This message has been edited by Dr.James (edited 26 April 2001).]

[This message has been edited by Dr.James (edited 26 April 2001).]

[This message has been edited by Dr.James (edited 26 April 2001).]


(in reply to Dr.James)
Post #: 3
RE: Clients unable to access external locations - 26.Apr.2001 1:48:00 PM   
Dr.James

 

Posts: 8
Joined: 10.Apr.2001
Status: offline
So... to continue with the saga. I have now installed everything again (the second time), including the active directory and including all ISA software. I have set up the ISA host as a stand-alone firewall, and as an array in the enterprise but have only recieved the same results. The host can see out, but no clients can get out of the network.

The clients can only see each other. (via ping response.) I have the ISA set up with a completely "open" policy. But my problems still exist. The clients should be able to see out of the network via ping regardless, as ISA default has ICMP open... right? However, as I mentioned before, I have set all protocols , and all packets to be passed.

I'm hoping someone can help me, or I'll be back to good ol' IPTABLES again sooner than later!

[This message has been edited by Dr.James (edited 27 April 2001).]


(in reply to Dr.James)
Post #: 4
RE: Clients unable to access external locations - 28.Apr.2001 6:54:00 AM   
tshinder

 

Posts: 47663
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Dr. James,

Let's get some basic information:

1. What type of connection are you using to connect to the Internet?

2. What are the IP configuration settings you are using on each NIC on the ISA Server?

3. What type of ISA clients are you using on the internal network (SNAT, FW, WProxy)?

4. What name resolution methods do you have on the internal network?

5. What protocol rules and Site and Content rules do you have active?

Thanks!

Tom

------------------
Tom Shinder
http://www.isaserver.org/shinder/


Get it Here!


(in reply to Dr.James)
Post #: 5
RE: Clients unable to access external locations - 30.Apr.2001 11:16:00 AM   
Dr.James

 

Posts: 8
Joined: 10.Apr.2001
Status: offline
The Basics

1. What type of connection are you using to connect to the Internet?

LAN via leased line. (2Mbit)

2. What are the IP configuration settings you are using on each NIC on the ISA Server?

DMZ =
IP: x.x.155.40/27
Gateway: x.x.155.129
DNS: x.x.155.131

Internal =
IP: 192.168.200.1/24
Gateway: none - it is the gateway
DNS/WINS 192.168.200.61


3. What type of ISA clients are you using on the internal network (SNAT, FW, WProxy)?

SNAT


4. What name resolution methods do you have on the internal network?

DNS and WINS


5. What protocol rules and Site and Content rules do you have active?

Site and Content -Allow any request always
Protocol Rules - All IP traffic, any request, always
IP Packets - any always in both directions
All ICMP's in ISA'S predifined list


... and thank you.

James


(in reply to Dr.James)
Post #: 6
RE: Clients unable to access external locations - 30.Apr.2001 4:44:00 PM   
Ultraman

 

Posts: 182
Joined: 20.Apr.2001
Status: offline
Dr. James,

Just an ISA novice's two cents worth, but I've gone over your configuration and ALL of my notes (approaching enough pages to write a book and give Tom some "competition" ), but have you turned on IP Forwarding in the filter properties?

Ultraman

[This message has been edited by Ultraman (edited 30 April 2001).]

[This message has been edited by Ultraman (edited 30 April 2001).]


(in reply to Dr.James)
Post #: 7
RE: Clients unable to access external locations - 2.May2001 9:23:00 AM   
Dr.James

 

Posts: 8
Joined: 10.Apr.2001
Status: offline
Ultraman,

Thanks a lot for your advice, but I'm still confused. Are you talking about the IP Forwarding in the Host machines NIC IP-filters options? We are running Win2K servers here, which means the forwarding options that were available under NT are not available; or....?

If you mean in the IP forwarding options within the ISA application itself, I would have to say; 'uhhhhh, IP forwarding in the filter options'

I have searched through the options I have seen available in the ISA and haven't seen anything like that. It would do me a great service if you could let me know where this 'switch' is.

Thanks

Dr.J


(in reply to Dr.James)
Post #: 8
RE: Clients unable to access external locations - 2.May2001 3:48:00 PM   
Ultraman

 

Posts: 182
Joined: 20.Apr.2001
Status: offline
Dr.James,

No problem. When you run ISA Management, simply click to open the tree for your ISA server (or all of them if you're running an array), open the tree for Access Policy, right click on IP Packet Filters and then click on Properties. You'll find the first page is two check boxes for turning on/off IP Forwarding and Intrusion Detection.

Hope this helps!

Ultraman


(in reply to Dr.James)
Post #: 9
RE: Clients unable to access external locations - 4.May2001 9:31:00 AM   
Dr.James

 

Posts: 8
Joined: 10.Apr.2001
Status: offline
Ultraman!

THANK YOU my friend! After a third re-install and hours of frustration. My problems are resolved.

I have no idea why it wasn't working before. We had tried it with these options on and off. Regardless, it is now working.

As a firewall only, the IP routing must be box must be enabled, and the Clients are now able to ping to the internet.

Thanks again.

DrJ


(in reply to Dr.James)
Post #: 10
RE: Clients unable to access external locations - 4.May2001 8:26:00 PM   
Ultraman

 

Posts: 182
Joined: 20.Apr.2001
Status: offline
Dr.James,

No problem. Glad to be of service and it's good to see you've got it rolling.

Ultraman


(in reply to Dr.James)
Post #: 11

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 General] >> Installation >> Clients unable to access external locations Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts