Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

PC can't ping or access any remote sites

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Firewall] >> VPN >> PC can't ping or access any remote sites Page: [1]
Login
Message << Older Topic   Newer Topic >>
PC can't ping or access any remote sites - 10.Jul.2008 11:55:27 AM   
gdcsupport

 

Posts: 5
Joined: 10.Jul.2008
Status: offline
Hello,

I am very close but missing something, hopefully you can see what is wrong.

I have 3 ISA 2006 Standard Edition SP1 servers
TRURO
10.0.1.242 (Internet)
172.16.3.1 (LAN)

WINDOWS 2003
172.16.3.10 (TRURO LAN)

DEBERT
10.0.1.240 (Internet)
172.16.1.1 (LAN)

VISTA
172.16.1.10 (DEBERT LAN)

AMHERST
10.0.1.241 (Internet)
172.16.2.1 (LAN)

MAC MINI
172.16.2.10 (AMHERST LAN)

Here is the situation:
1) All 3 ISA servers can ping all ISA servers and all devices
2) WINDOWS 2003 can ping TRURO but nothing else
3) VISTA can ping DEBERT but nothing else
4) MAC MINI can ping AMHERST but nothing else
5) All Devices can go to the Internet without any issue.

So what rule do I need to make so that all all sites can see all devices?
Thanks,
Post #: 1
Screen shots of rules - 10.Jul.2008 12:03:17 PM   
gdcsupport

 

Posts: 5
Joined: 10.Jul.2008
Status: offline
http://www.greendatacentre.ca/support/3.png
http://www.greendatacentre.ca/support/4.png
http://www.greendatacentre.ca/support/5.png
http://www.greendatacentre.ca/support/6.png
http://www.greendatacentre.ca/support/7.png

(in reply to gdcsupport)
Post #: 2
RE: Screen shots of rules - 10.Jul.2008 1:26:16 PM   
paulo.oliveira

 

Posts: 826
Joined: 3.Jan.2008
From: Amazonas, Brazil
Status: offline
Hi,

why are you allowing ping? PING is a problem.
From what I understand you want to be able to ping on all others ISA servers. To complete this task you have to edit the following system policy: Remote Management: Allow ICMP (PING) requests from selected computers to ISA Server and add the remote networks into the Remote Management Computers computer set.

Regards,
Paulo Oliveira.

(in reply to gdcsupport)
Post #: 3
PING issues - 10.Jul.2008 4:02:38 PM   
gdcsupport

 

Posts: 5
Joined: 10.Jul.2008
Status: offline
Hi Paulo,

I opened the ping rule so that I can test, it will be closed once I can verify everything is working.

I need to be able to access a PRINTER from TRURO in TRURO.
I need to be able to access the PRINTER in TRURO from AMHERST & DEBERT
I need all sites to be able to see each other and access their desktops via RDP from TRURO, DEBERT & AMHERST.

Basically I need all sites to see each site and all of its resources.

FYI: The ISA servers at each location can ping and see all resources. But none of the PC's at any location can see each other or ping.

(in reply to paulo.oliveira)
Post #: 4
RE: PING issues - 10.Jul.2008 5:34:27 PM   
paulo.oliveira

 

Posts: 826
Joined: 3.Jan.2008
From: Amazonas, Brazil
Status: offline
Hi,

are your clients PCs configured as secureNAT? How´s your ISA NICs configured?

Regards,
Paulo Oliveira.

(in reply to gdcsupport)
Post #: 5
RE: PING issues - 10.Jul.2008 7:59:49 PM   
gdcsupport

 

Posts: 5
Joined: 10.Jul.2008
Status: offline
I'm sorry but I don't understand your question regarding "configured as secureNAT"
The PC's are just regular Windows XP Professional SP2 and Vista Business 32 bit.
Be more specific "How's your ISA NICs configured?"
The server has 2 Intel Pro 100 PCI cards, 1 connected to Internet switch and the other connected to LAN switch.

Installation started with stock install of Windows 2003 R2 Standard Edition, and ISA 2006 with SP1. Used the Network Template (EDGE) then added the Remote Site-to-Site VPN with L2TP with passphrase on each ISA server.

(in reply to paulo.oliveira)
Post #: 6
RE: PING issues - 11.Jul.2008 3:36:10 PM   
gdcsupport

 

Posts: 5
Joined: 10.Jul.2008
Status: offline
Okay, I scrapped the whole thing.
I re-installed both ISA 2006 servers and made them both Active Directory servers with DHCP server installed then added ISA 2006 with SP1.
Configured the Site to Site VPN, and the ISA servers can see each other and ping each other. No device on the network can ping anything but the ISA server.
Strange thing though, the Vista PC on network DEBERT can view the Mac Mini on network AMHERST web page on port 80.
There is no rule in the firewall stating that is allowed, no other port works.
What is going on? Next step will be to abandon the product and buy a Cisco ASA which works right out the box. Any help is appreciated.

(in reply to gdcsupport)
Post #: 7

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Firewall] >> VPN >> PC can't ping or access any remote sites Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts