We have old NT+proxy2.0 working fine. I just installed win2003+isa2004. But the Firewall client pc could not ftp to outside. Whenever dir / put .. etc, it showed: can't assign requested address.
I know it might be sort of passive mode problem. But just dont know why the old NT+proxy2.0 works with these apps ok, but the new ones fails. AND could anybody show me how to fix it? The old proxy2.0 has one nic. And the new ISA server got one nic as well. I have only one access rule in my ISA server which allows any to any. Its FPT property has been unticked "Read only".
You cannot make firewall clients working with single-leg ISA server configuration. I'm not aware why those apps were working with Proxy 2, but with current ISA versions you need to configure the app to be a web proxy client of an ISA server. If your app won't support the web proxy configuration you should configure it to bypass the ISA server and access the internet directly via your internet gateway (whatever it is). Please take a read the "Configuring ISA Server with a Single Network Adapter Configuration" section of the "Troubleshooting Unsupported Configurations in ISA Server" document.
Thanks, Aklimkin. I dont understand why firewall client wont work with single-leg isa server. My company got a lot of branches and all our internet traffic goes to a datacentre colocated at ISP. We just want the isa server to process all internet-related request, of course a multi-homed firewall faces the public world. You see, in this case, Web client setting wont fix all sorts of applications / 3rd party programs/utilities, we need the "winsock proxy". And SecureNAT needs setting the local pc's default gw to the isa server, and that is impossible as isa server is on different segment.
Till now, we dont have any other problem with firewall client accessing outside, except this FTP command problem which affects some of our old applications sending files outside, we have to keep our old proxy2.0 (still single-leg) still running. If you can shed more lights on this issue, I will appreciate greatly.
From: Papua New Guinea
I have a similar problem. My company just purchase Windows Small Business Server 2003 and I installed ISA Server 2004 as our Web Proxy and Firewall.
Using FrontPage 2003 I created the company's website, but could not upload the website to my ISP. I tried edititing and even created my own FTP Access Rules, but could not upload from my Client PC inside the network. So I used the Server which is ISA was installed on to Upload.
I read your postings and will try out some of the things mentioned.
But I would really like to have upload from my PC instead of having to go to the sever. If you have any help and information for me, I would greatly appreciate it.