Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Firewall fails every couple of hours, no changes at all

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 Firewall] >> General >> Firewall fails every couple of hours, no changes at all Page: [1]
Login
Message << Older Topic   Newer Topic >>
Firewall fails every couple of hours, no changes at all - 16.Sep.2001 6:30:00 PM   
lybrand

 

Posts: 54
Joined: 2.Feb.2002
From: Dallas, TX
Status: offline
Hi,

I have resolved all issues I had so far with ISA by tweaking, using workarounds etc. But the last thing which completely drives me crazy is that firewall just stops working (not processing any rules) after everyt couple of hours.I go to services and restart firewall service and everything goes back to normal after that. Again, I don't do "any" changes to make it work, just start and stop. That's the huge problem becouse I'm not on site and use TS to administer box which of course fails as well.
Any ideas which might be causing it? I mean "ANY" becouse I would look at any possibility to solve the problem before they will cut my head off for that.

Greg

Post #: 1
RE: Firewall fails every couple of hours, no changes at... - 16.Sep.2001 6:43:00 PM   
tshinder

 

Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Greg,

Some people that have had similar issues have said that if they replace their NICs with Intel Pro 100+ and use the latest drivers from the Intel site, that they have had some success with similar problems.

HTH,
Tom

------------------
http://www.isaserver.org/shinder/



Get It Here!


(in reply to lybrand)
Post #: 2
RE: Firewall fails every couple of hours, no changes at... - 16.Sep.2001 6:56:00 PM   
Ben

 

Posts: 65
Joined: 24.Aug.2001
From: California
Status: offline
I don't have any advice with regard to a particular solution, but I would start looking for more clues. Is there any indications in the event viewer? or does the event viewer not log anything that would indicate a stoppage? Does the firewall service stop, or just begin to not work without actually indicating it's stopped?

If you can't find anything else, you might try starting from scratch. Obviously this should not be expected, but when you're facing possibly hours of forensics, an hour re-installing and configuring ISA from scratch might be an alternative. But if it doesn't solve the problem, you're not making progress.

I don't know what else to suggest other than more detective work, or take a shot at starting over and hope the mystery doesn't recurr.

Again, I don't like to advocate voodoo server administration, but it sounds like you've got no other clues and that making it work is more important than understanding why it doesn't.

Shortly after I put my ISA server in production, I began to have a problem where the server would just reboot itself. It got to be twice a day. It never happened in the lab, but there I was with a mysterious problem, no clues, and at risk of my solution failing and its reputation being trashed after I worked so hard on it.

After one long night in the lab, I discovered the 4th DIMM in the server was bad. It had been passing diagnostics but was actually the incorrect part. I guess the lab never stressed the server enough to cause the failure, but in production it would. I replaced the DIMM and the server hasn't been down since.


(in reply to lybrand)
Post #: 3
RE: Firewall fails every couple of hours, no changes at... - 16.Sep.2001 8:31:00 PM   
lybrand

 

Posts: 54
Joined: 2.Feb.2002
From: Dallas, TX
Status: offline
Thanks for replies. This is site is great. Support on Sundays?!
I use Dell server which DOES have Intel NICs (Dual embedded Intel Pro 10/100+ NICs) so I would try first solution first and then go to reinstallation path. Just wondering if I would be able to restore ISA server configuration from backup of uninstalled version.

Greg


(in reply to lybrand)
Post #: 4
RE: Firewall fails every couple of hours, no changes at... - 17.Sep.2001 9:06:00 AM   
tshinder

 

Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Greg,

If you have those NICs, make sure you use the Intel drivers from the Intel site. Reports are that it works wonders!

HTH,
Tom

------------------
http://www.isaserver.org/shinder/



Get It Here!


(in reply to lybrand)
Post #: 5
RE: Firewall fails every couple of hours, no changes at... - 18.Sep.2001 12:04:00 PM   
Jeroen

 

Posts: 7
Joined: 18.Sep.2001
Status: offline
I have a similar problem. After a few hours nobody on my network can access the internet anymore or mail or ping etc. etc.

When I restart my ISA server, everything works fine for a couple of hours. Then the problem occurs again. There are no errors in the eventlog and the ISA services are still running.

I use a W2k advanced server sp2 with a 3com905c and a rtl8029 NIC

I reinstalled the ISA server 3 (!) times, but no effect.....


(in reply to lybrand)
Post #: 6
RE: Firewall fails every couple of hours, no changes at... - 18.Sep.2001 12:04:00 PM   
Jeroen

 

Posts: 7
Joined: 18.Sep.2001
Status: offline
I have a similar problem. After a few hours nobody on my network can access the internet anymore or mail or ping etc. etc.

When I restart my ISA server, everything works fine for a couple of hours. Then the problem occurs again. There are no errors in the eventlog and the ISA services are still running.

I use a W2k advanced server sp2 with a 3com905c and a rtl8029 NIC

I reinstalled the ISA server 3 (!) times, but no effect.....


(in reply to lybrand)
Post #: 7
RE: Firewall fails every couple of hours, no changes at... - 18.Sep.2001 10:52:00 PM   
CDeMille

 

Posts: 10
Joined: 30.Jun.2001
From: Newton, MA, USA
Status: offline
I have a similiar issue, with the Firewall service stopping a few times a week. Error 14079 "Due to an unexpected error, the service Firewall service stopped responding to all requests". When you restart, things seem to be fine. I have the Intel Pro 100+ NIC on a Dell server. I used Intel drivers, but I am not sure of the rev. Any recommendations ??

(in reply to lybrand)
Post #: 8
RE: Firewall fails every couple of hours, no changes at... - 18.Sep.2001 11:13:00 PM   
CDeMille

 

Posts: 10
Joined: 30.Jun.2001
From: Newton, MA, USA
Status: offline
I just checked the MS Support site... They reference a couple of issues with the FW service: One with RTSP (Real-Time Streaming Protocol) and another with too many S-NAT clients. They mention an un-released fix for WSPSRV.exe from 3/19/2001. Has anyone had experience with this fix ??

How about a Serivce Pack 1 for this baby...


(in reply to lybrand)
Post #: 9
RE: Firewall fails every couple of hours, no changes at... - 19.Sep.2001 9:47:00 PM   
lybrand

 

Posts: 54
Joined: 2.Feb.2002
From: Dallas, TX
Status: offline
Issue was fixed by removing QOS service from both NIC interfaces and rebooting machines.
3 days without any any problems so far.

Greg


(in reply to lybrand)
Post #: 10
RE: Firewall fails every couple of hours, no changes at... - 6.Nov.2001 7:14:00 PM   
Abrahamb

 

Posts: 8
Joined: 29.Oct.2001
From: Ethiopia
Status: offline
Hi Greg ,

Here is what I have done and seems it works.

In your DNS server address for the external ip interface card :-
Put 1. In the DNS server of your ISP DNS server
2. In the alternate DNS server entry put, the local DNS server ip no, the one in your LAN.


(in reply to lybrand)
Post #: 11
RE: Firewall fails every couple of hours, no changes at... - 7.Nov.2001 10:58:00 AM   
JohnS

 

Posts: 71
Joined: 10.Aug.2001
Status: offline
Hi all,

Try to switch off power management option on Intel network card. It helps.

------------------
Regards,
John S.
isatest@altavista.com


(in reply to lybrand)
Post #: 12
RE: Firewall fails every couple of hours, no changes at... - 7.Nov.2001 8:00:00 PM   
Shahid Sheikh

 

Posts: 49
Joined: 7.Nov.2001
From: Fairfax, VA
Status: offline
Same problem here. Lasts anywhere from 2 ~ 8 hours. Its running on a Dell PowerEdge 2550, W2K SP2, dual 933, 512meg machine serving about 100 or so users in integrated mode. hf69 applied but problem is there with all version of w3proxy.exe. All users are either SNAT clients or WebProxy clients.

Using onboard NICs (Intel as external and Broadcom as internal)

Have an open PSS call with MS but no resolution yet.

Latest thing I tried after reading this thread was to disable QoS. Will see what happens. So far uptime is 01:55.

Is it normal for memory usage of W3PROXY.EXE to constantly keep increasing? It keeps increasing by about 4K or bigger increments ever 2 ~ 3 seconds. But it never seems to come down.


(in reply to lybrand)
Post #: 13
RE: Firewall fails every couple of hours, no changes at... - 7.Nov.2001 8:12:00 PM   
Jez

 

Posts: 367
Joined: 30.Jan.2002
From: Essex, England
Status: offline
Hey Shahid,
I think its a problems somwhere, as my W3PROXY service memory usage is now 1.3 gb (i have 4b memory in server). Rebooting is not an option, and for this week only, nor is restarting the W3 service (although this does take the memory usage back to about 10mb, which then steadily creeps up).

I imagine on a system with normal memory (256/512 mb etc) this could cause serious problems.

------------------
Regards,
Jez
email: jez@ateallthepies.com
www: www.ateallthepies.com


(in reply to lybrand)
Post #: 14
RE: Firewall fails every couple of hours, no changes at... - 7.Nov.2001 8:38:00 PM   
Shahid Sheikh

 

Posts: 49
Joined: 7.Nov.2001
From: Fairfax, VA
Status: offline
Thats what I though at first. But my server stops responding even when w3proxy's usage is like a 100 megs and there is more physical memory still free.

Actually it just died again while I was typing this post. About 02:15 uptime. QoS was turned off on the NICs, power management is all off. W3Proxy.exe usage was about 130 megs when it died.

Once it stops working, you cannot ping anything except all the local IPs of the ISA from ISA itself and nothing from the outside can ping it. No traffic comes in and out of the NICs. About 50% of the time you cannot do a graceful shutdown. Remaining 50% of the time you can. In fact you can even just stop and start the ISA services and it comes back online.

I think there are multiple problems. The memory usage of W3Proxy is one problem and this issue is probably another.

When W3proxy starts on my server, right off the bat its using about 88 megs.

Jez, I take it on your server there are no freezes at all. If there are how far apart are they and how heavily does the server get used?

thanks,

Shahid


(in reply to lybrand)
Post #: 15
RE: Firewall fails every couple of hours, no changes at... - 7.Nov.2001 9:38:00 PM   
Shahid Sheikh

 

Posts: 49
Joined: 7.Nov.2001
From: Fairfax, VA
Status: offline
And after changing (disabling QoS) its gotten much worse. Now it doesn't last more than 30 minutes. stopped working three times in last 2 hours.

(in reply to lybrand)
Post #: 16
RE: Firewall fails every couple of hours, no changes at... - 7.Nov.2001 10:40:00 PM   
lybrand

 

Posts: 54
Joined: 2.Feb.2002
From: Dallas, TX
Status: offline
quote:
Originally posted by Shahid Sheikh:
And after changing (disabling QoS) its gotten much worse. Now it doesn't last more than 30 minutes. stopped working three times in last 2 hours.

Well disabling QoS definetely stopped my problem with dying server. It's been running for several month now without any problem. I guess we had the different problem.



(in reply to lybrand)
Post #: 17
RE: Firewall fails every couple of hours, no changes at... - 8.Nov.2001 4:13:00 PM   
Shahid Sheikh

 

Posts: 49
Joined: 7.Nov.2001
From: Fairfax, VA
Status: offline
Probably. I think what is happening is many different kinds of problems that go un-logged have the same outcome. The ISA server stops serving requests.

During my troubleshooting I found out that it was just the internal network that the ISA server would quit talking to. The outside machines it could still ping and talk to fine. My internal NIC was the BroadCom NetXtreme gigabit (junk) that comes embedded on the PowerEdge 2550. Waited 5 hours last night for the server to halt but it didn't. Apparently it only happens when there are several users using it instead of just one users heavily browsing the web which explains why I didn't see the problem in the 1 week I was testing it with a few test users.

Finally I got tired of waiting, disabled the BroadCom, stuck a 3c905c in there as the internal NIC, re-enabled QoS on both NICs in use, and now the server has been running all night and so far today.

Until today it had been freezing every morning since its been put in production use. So fingers are crossed and lets see what happens.

As for W3Proxy.exe using large amount of memory, apparently it will use up upto the amount of physical memory available but should stop there and stay at that level. If at that point some other application starts up that uses large amounts of memory then you may start swapping but as long as its just proxy running, you should be fine.

[This message has been edited by Shahid Sheikh (edited 08 November 2001).]


(in reply to lybrand)
Post #: 18
RE: Firewall fails every couple of hours, no changes at... - 9.Nov.2001 6:10:00 AM   
Shahid Sheikh

 

Posts: 49
Joined: 7.Nov.2001
From: Fairfax, VA
Status: offline
Well, I've clocked more than 24 hours up time on this ISA server which is a first. Final resolution to the problem was to disable the onboard BroadCom NIC which was being used as the internal NIC and use a 3Com 3C905c in its place.

(in reply to lybrand)
Post #: 19
RE: Firewall fails every couple of hours, no changes at... - 10.Nov.2001 6:02:00 PM   
Dave14177

 

Posts: 6
Joined: 23.Apr.2001
From: Paso Robles, CA
Status: offline
For what it's worth...

We had the same issue and resolved it by changing DSL providers. Since then, we have'nt an issue!

What also changed is the router.


(in reply to lybrand)
Post #: 20

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 Firewall] >> General >> Firewall fails every couple of hours, no changes at all Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts