I have been using web publishing rules for 3 months, all working without any interference from me. I have two ISA 2006 Servers operating as outbound proxy servers and as an array for published web apps. I have approximately 6 applications (including OWA) being published with a local website running on the array members which simply provide an application list to click on.
This all worked swimmingly until yesterday morning when NONE of the applications where accessible. Every external request for a web app now drops though the firewall rules and is denied by the Enterprise Default rule???
Nothing has been changed on the ISA array and nothing has been configured on our other firewalls, no DNS changes have been made and there is nothing in the event log to indicate any issues.
I was intending to launch this in two weeks to a wider population of around 2,000 users but this will clearly not be possible until this is resolved. I am receiving plenty of grief over this at the moment and would appreciate ANY assistance on offer.
First step is to get IIS OFF the firewall. It's a firewall, not a Web server and you compromise security and stability by running a Web server on the firewall.
Check the Event Viewer to see if there are issues with the firewall or OS.
the IIS install is only temporary until the units go into production and an internal webserver is sourced. I have uninstalled IIS to try and resolve my issue. There DID appear to be a resource allocation conflict between IIS/ISA but even though I have got to the bottom of that there are still issues.
I have an ISA array with a listener using the VIP. It now correctly picks up the inbound request and presents the authentication page. Once authentication is complete the request for the internal web app seems to be routing the request to the internal VIP? (The logs display source IP as the internal VIP and destination IP as the internal VIP)
I have another listener which works perfectly well but even if I switch my app publishing rule to this listener it still fails. I have around 8 apps being published but only one of them is now correctly routing to the internal network? This has been functioning without issue for 3 months.