Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Secure Channel Problem

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Firewall] >> DMZ >> Secure Channel Problem Page: [1]
Login
Message << Older Topic   Newer Topic >>
Secure Channel Problem - 14.Jul.2008 10:46:18 AM   
antandrades

 

Posts: 3
Joined: 14.Jul.2008
Status: offline
Hi, I have a ISA 2006 installation in a DMZ. The server communicates with a DC on the LAN through a Checkpoint firewall with all the standard ports configured (53, 88, 123, 135, 389, 3268, 1025, 1026).

The problem we have is that from time to time the Secure Channel seems to break and as a result doesn't authenticate domain users. I have made the registry tweaks to RSS, TCPA and TCPChimney but I still get the loss of communication between the ISA box and the DC over the secure channel. It's intermittent, and as easily as it goes, it comes back. We have other ISA servers in different DMZ's and LAN sections, with the same configuration that do not have this problem.

Plus when I put the server back on the LAN, the problem doesn't occur.

Has anyone else experienced anything similar and troubleshot it?

The Checkpoint is performing NAT also.

Thanks for any feedback.  
Post #: 1
RE: Secure Channel Problem - 14.Jul.2008 10:56:01 AM   
Jason Jones

 

Posts: 1750
Joined: 30.Jul.2002
From: United Kingdom
Status: offline
I don't think Microsoft supports intradomain communications over NAT - can you move to routed?

_____________________________

Jason Jones
Silversands Ltd
http://www.silversands.co.uk
View My Blog: http://blog.msfirewall.org.uk/

Get Our NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to antandrades)
Post #: 2
RE: Secure Channel Problem - 14.Jul.2008 10:59:25 AM   
antandrades

 

Posts: 3
Joined: 14.Jul.2008
Status: offline
Hi,

You that the NAT performed by the Checkpoint firewall is breaking the Secure Channel?

(in reply to Jason Jones)
Post #: 3

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Firewall] >> DMZ >> Secure Channel Problem Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts