• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

ISA 2006 NLB problem

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 General] >> Installation and Planning >> ISA 2006 NLB problem Page: [1]
Login
Message << Older Topic   Newer Topic >>
ISA 2006 NLB problem - 7.Mar.2007 9:23:26 AM   
obelix

 

Posts: 5
Joined: 6.Mar.2007
Status: offline
Hi,

For testing purposes I have installed 3 virtual machines on MS VS2005R2: 2 ISA 2006 EE in array and one DC who acts as CSS as well, all machines are joined to the domain and everything works fine. I have enabled integrated NLB for internal and external nic and also a NIC for intra-array communication between ISA's with ip's in a different subnet.
It looks like this:
ISA 1
Internal nic: 192.168.1.50/24
virtual ip: 192.168.1.60/24
external nic: 172.28.2.24/16
external virtual ip: 172.28.2.25/16
intra-array nic: 192.168.10.80/24
ISA 2
Internal nic: 192.168.1.51/24
virtual ip: 192.168.1.60/24
external nic: 172.28.2.26/16
external virtual ip: 172.28.2.25/16
intra-array nic: 192.168.10.81/24
DC (CSS) server
Internal nic: 192.168.1.100/24 with gateway set as internal virtual ip 192.168.1.60/24
intra-array nic: 192.168.10.100/24

DC is primary CSS and ISA1 is secondary CSS.
sychronization is working fine, NLB is working fine and doesn't report any errors with configuration.

Now comes the problem:
I am testing failover functionality and when I start download on a DC and during the download I turn off one of the ISA's to simulate a failure, download remains active, but when I recover the ISA that has been turned off and turn off the other one, the connection is severed and download breaks up. I wait for 15 minutes before i turn off the other one.
My question is: shouldn't the other ISA (the one that has been turned off and turned back on) take over as it has been when the first one was turned off and the second ISA took over, if yes what do I need to do to make it work? Am I missing something and what?
For example: I am planning to provide failover functionality to one of the customers who needs to be online 24/7 and for that reason I am trying to simulate downtime for example due to maintenance of the servers, and by now NLB doesn't look promising.

Any hint or help is greatly appreciated.

Best regards,

Obelix
Post #: 1
RE: ISA 2006 NLB problem - 10.Mar.2007 10:47:38 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Does virtual server support NLB? I haven't heard that it did.  I know VMware doesn't.

Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to obelix)
Post #: 2
RE: ISA 2006 NLB problem - 13.Mar.2007 10:07:58 AM   
obelix

 

Posts: 5
Joined: 6.Mar.2007
Status: offline
Greetings Tom,

I suppose virtual server2005r2 supports nlb, otherwise I would't be able to setup 2xISA 2006 and enable NLB on them (these are virtual machines running server2003 standard edition with sp1) or do I get the wrong impression?
So, all machines are virtual machines (2xISA 2006 EE on w2k3 server standard edition, one DC on w2k3 server standard edition which is at the same time configuration storage server for ISA and they are all in "virtual" domain), all of them use configured "adapters" as internal network except for ISA's external adapter and configured external virtual ip that is connected to our corporate LAN which acts as the internet for ISA 2006 (defined in virtual machine setup as the physical adapter of the machine that acctually runs virtual server), it sounds very confusing when it's laid out like this, but it's not so complicated to set up.
I haven't used VMware so I would't know if I could do the same setup.
So there is a possibility that virtual server doesn't support nlb, how do I check this? Should I get any errors during the NLB setup?

Please if somebody has the will to check it out and help me solve the problem, I know it would be much easier to test on real hardware not virtual machines but unfortunately I don't have such possibility.

Best regards,

Obelix

(in reply to tshinder)
Post #: 3
RE: ISA 2006 NLB problem - 13.Mar.2007 6:56:09 PM   
mylo

 

Posts: 144
Joined: 26.Mar.2002
Status: offline
Obelix,

As Tom suggested, NLB is not without its pitfalls under 2k3 and VS2005...
http://blogs.msdn.com/virtual_pc_guy/archive/2006/03/21/556222.aspx

Regards,
Mylo

(in reply to obelix)
Post #: 4
RE: ISA 2006 NLB problem - 16.Mar.2007 10:13:08 AM   
ghort

 

Posts: 3
Joined: 16.Mar.2007
Status: offline
quote:

ORIGINAL: tshinder
Does virtual server support NLB? I haven't heard that it did.  I know VMware doesn't.


Hi guys,

just a notice (I believe you know it :) - VMware supports NLB, however only multicast mode -> so you cannot test ISA integrated NLB...

_____________________________

G.*

(in reply to tshinder)
Post #: 5
RE: ISA 2006 NLB problem - 18.Mar.2007 2:28:12 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Ghort,

You are correct and I should have been specific. VMware does support multicast mode and I've done articles on this site showing captures of multicast mode NLB in action. ISA EE uses unicast mode, and therefore you can't use it with VMware. As for Virtual PC and MS Virtaul Server, I'm not sure what the level of support is.

Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to ghort)
Post #: 6
RE: ISA 2006 NLB problem - 26.Mar.2007 10:31:55 AM   
obelix

 

Posts: 5
Joined: 6.Mar.2007
Status: offline
Hello again,

I've managed to setup lab with three machines (instead virtual machines) 2xISA2006EE and one CSS that is also DC. I was struggling to overcome flooding issue (using 2 hubs, one for external vip, one for internal vip both connected to the switch) and managed to make it work (be sure to have working NIC's if u try to do it yourself, I had 2 faulty  and lots of trouble to identifiy the "it's not working as it should" problem).
Now after putting everything together (with very limited hardware resources) one problem still remains, every time when I try to simulate "maintenance" of array members, download that is in progress breaks. (shut down one of the array members, turning it on, waiting for it to become available and operational, then shutting down the other one). Any ideas what might be wrong? (Same thing happened with virtual machines).

Thanks

Obelix

(in reply to tshinder)
Post #: 7
RE: ISA 2006 NLB problem - 26.Mar.2007 11:30:37 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Ob,

The example of the download breaking when you take one of the members offline -- that is what is expected. What did you think would happen?

Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to obelix)
Post #: 8
RE: ISA 2006 NLB problem - 28.Mar.2007 8:45:46 AM   
obelix

 

Posts: 5
Joined: 6.Mar.2007
Status: offline
Hi Tom,

I was mislead by the wrong information that the active session should remain active even in the event when the array member that "has" the session stops working (turns off, restarts), I was a bit suspicious about that and the testing revealed it completely and you have just confirmed it.

Thanks

Next thing is to configure VPN on the array, more articles to read :-))
If I get stuck I'll search for help here.

Regards,

Obelix

(in reply to tshinder)
Post #: 9
RE: ISA 2006 NLB problem - 29.Mar.2007 3:32:33 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Obelix,

Let us know how the VPN works for you.

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to obelix)
Post #: 10

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 General] >> Installation and Planning >> ISA 2006 NLB problem Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts