• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

proxy server loop

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Firewall] >> General >> proxy server loop Page: [1]
Login
Message << Older Topic   Newer Topic >>
proxy server loop - 26.Apr.2007 6:27:50 AM   
juankiarlos

 

Posts: 6
Joined: 11.Apr.2007
Status: offline
Hi everybody,

I'm testing ISA Server in my organization since a few days, and there are some problems and questions that I've found.

First of all, my ISA Server has 2 NICs in the same network 192.168.100.0/24
The IPs are 192.168.100.4 and 192.168.100.5, both adapters have set the  gateway to 192.168.100.1 because they are in the same net, and are registered in DNS with the same hostname.

Internal network is defined like the range 192.168.100.0-192.168.100.255 without exclusions.

I know that each NIC should be in a different network, but on this way... also works!!

I've installed Firewall Client in all clients, and I've set the gateway on each client to 192.168.100.4, although there are 4 clients that are set to 192.168.100.5 (the other NIC), does it matter? ... and... Do I really need to set the gateway in a computer that has installed Firewall Client? Can I leave it in blank???

Peridodically ISA begins to notify "Routing(chaining) failure. ISA Server detected a proxy server loop", and some computers lose their Internet connection, then I restart Microsoft Firewall and everything works again for 4 or 5 hours.

What's the cause of the problem? Two NICs in the same subnet? Should I exclude one ISA adapter IP in the Internal network definition? All clients should point to the same NIC?

Thanks


Post #: 1
RE: proxy server loop - 26.Apr.2007 8:41:16 AM   
elmajdal

 

Posts: 6022
Joined: 16.Sep.2004
From: Lebanese in Kuwait
Status: offline
Hi,

EACH NIC should be on a different subnet !!!

check this : http://www.isaserver.org/tutorials/Configuring_ISA_Server_Interface_Settings.html

and you can only have one NIC with Default gateway , and this would be the External NIC

HTH,
Tarek

_____________________________

Tarek Majdalani

Windows Expert - IT Pro MVP
Facebook : https://www.facebook.com/ElMajdal.Net

(in reply to juankiarlos)
Post #: 2
RE: proxy server loop - 26.Apr.2007 11:44:50 AM   
juankiarlos

 

Posts: 6
Joined: 11.Apr.2007
Status: offline
Thank you very much elmajdal,
That's a very interesting article. I've readed an followed all the steps but I can't locate each NIC in a different subnet because it would mean make some important changes in the network and nowadays therere's no time, surely we'll make them in a few months, but no for now.

But, with both NICS in the same network it's working!!! OK, it's less secure obviously, but it works... although I wonder if could be there strange behaviors?? unexpected errors?? Hasn't ISA been designed for support that possibility (two NICS - one network)??

And what about set the gateway in the computers with Firewall Client installed, is it useful???

(in reply to elmajdal)
Post #: 3
RE: proxy server loop - 26.Apr.2007 2:50:07 PM   
elmajdal

 

Posts: 6022
Joined: 16.Sep.2004
From: Lebanese in Kuwait
Status: offline
quote:

Hasn't ISA been designed for support that possibility (two NICS - one network)??

No, Not Supported

quote:

And what about set the gateway in the computers with Firewall Client installed, is it useful???


You can have the 3 different clients type on your client machine ( SecureNat, Firewall , Web Proxy )

HTH,
Tarek

_____________________________

Tarek Majdalani

Windows Expert - IT Pro MVP
Facebook : https://www.facebook.com/ElMajdal.Net

(in reply to juankiarlos)
Post #: 4
RE: proxy server loop - 27.Apr.2007 4:08:02 AM   
juankiarlos

 

Posts: 6
Joined: 11.Apr.2007
Status: offline
quote:

No, Not Supported

OK, thanks. I'll try to modify the network topology as soon as possible in order to have both NICS in different networks.

quote:

You can have the 3 different clients


Yes, I know. My choice is Firewall Client, because I need user authentication (SecureNAT is not capable), and I need support for more protocols than http and ftp (web proxy is limited).  So, if my ISA Server is in the same subnet than Firewall Clients, I can omit gateway configuration, don't I?

I wonder about it because when I take a look to the dashboard in ISA Server, and I see the sessions, there are Firewall client sessions, web proxy sessions, and SECURE NAT SESSIONS ALSO!!!! And I wonder if the reason is the gateway of the Firewall Clients, that I have configured to the ISA Server IP.

At this moment I have this sessions
Firewall Client   44
Web proxy       27
SecureNAT      28
and all the computers are Firewall Clients, why SecureNAT sessions???

I understand Web proxy sessions because as you know when Firewall Client is installed, proxy settings in IE are configured automatically, so...  Firewall Clients than need Internet browsing are also Web Proxy clients, so
 
Firewall Client + Internet browsing, implies Web proxy client
 
So If my choice is configure each computer as a Firewall Client and the ISA is in the same subnet than clients, do I need configure a gateway?????

Thanks

(in reply to elmajdal)
Post #: 5

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Firewall] >> General >> proxy server loop Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts