• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

MSA ISA Server 2006 Branch Edition Installation

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 General] >> Installation and Planning >> MSA ISA Server 2006 Branch Edition Installation Page: [1]
Login
Message << Older Topic   Newer Topic >>
MSA ISA Server 2006 Branch Edition Installation - 19.Jun.2007 6:46:26 AM   
anusumesh

 

Posts: 35
Joined: 19.Jun.2007
Status: offline
hi

i have installed MSA ISA Server2006 Enterprise Edition. and i want to install MSA ISA Server2006 Branch Edition and want to make a member of array in Enterprise edition.
MSA ISA is Celestix device. they have combined Windows2003 server OS and ISA Server2006 in one unit.
When i configure Enterprise edition default array is generated having same name of system. When i configure Branch Edition i opt for Joining Existing Array and give the name of array on Enterprise Edition and also Configuration Storage Server is on Enterprise Edition. These both Servers are in domain.
But  after cinfiguration default array is generated having same name of system on Branch Edition Server also 'n' on EE side no server is added under given named array.

Can u plz plz help me in this \? what can be the reason for this. i have followed the steps given in ISA quick setup guide.

I m very new to networking concepts.

Please help me.

Thanks a lot

Anu Garg
Chennai
Post #: 1
RE: MSA ISA Server 2006 Branch Edition Installation - 25.Jun.2007 11:04:13 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
What is MSA?

Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to anusumesh)
Post #: 2
RE: MSA ISA Server 2006 Branch Edition Installation - 18.Jul.2007 3:02:02 AM   
anusumesh

 

Posts: 35
Joined: 19.Jun.2007
Status: offline
hi

thanks for reply.
Actually its Multiple Security appliance designed by Celestix networks company which combines ISA firewaal, VPN 'n' cache in one box.

The configuration that i was following  is wrong. now i have configured ISA server 2006 Enterprise Edition for VPN connection successfully.
But when i m trying to configure Branch Edition as VPN connection and trying to join  array on Enterprise edition its failing.
After last step i.e. windows authentication its displaying error that "an attempt to authenticate to the configuration storage server computer failed. the server service may be stopped aton css computer"

But Server service is started on CSS computer.
'n' in log file its giving error
ISA SETUP CA INFO: GetAccountInfo failed with 0x800706ba trying to create a connection to the configuration server.
ISA SETUP CA Error: CAUTONETUSE::Connect:WNetAddConnection2w failed with 1203
ISA SETUP CA Warning: AutoNetUse.connect failed. hr=0x800704b2

Can u plz help me to solve this problem?
thanks
anu

(in reply to tshinder)
Post #: 3
RE: MSA ISA Server 2006 Branch Edition Installation - 18.Jul.2007 3:44:39 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Is the MSA box and the CSS members of the same domain?

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to anusumesh)
Post #: 4
RE: MSA ISA Server 2006 Branch Edition Installation - 19.Jul.2007 5:02:44 AM   
anusumesh

 

Posts: 35
Joined: 19.Jun.2007
Status: offline
hi
thanks for replying

yup Isa server Enterprise edition and branch edition are in same domain.
My question is:
My configuration is:
      One ISA Server 2006 Enterprise Edition(Main Office) with one array and one server under that array. I have configured VPN connection over there.
      One ISA Server 2006 Branch edition and i want to configure this also as VPN connection and i want to join this server to array on Enterprise Edition Side(Main Office)

Can Isa Server2006 branch edition join an enterprise array over site-to-site VPN connection?

thanks
anu

(in reply to tshinder)
Post #: 5
RE: MSA ISA Server 2006 Branch Edition Installation - 23.Jul.2007 8:54:04 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Yes! You need to use the site to site VPN wizard. All the details are in my article series on this site.

Also, make sure you join the branch office to a different array. You can't join it to the main office array because the IP addressing information at the branch office puts the internal and external interfaces on different network IDs from the main office.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to anusumesh)
Post #: 6
RE: MSA ISA Server 2006 Branch Edition Installation - 24.Jul.2007 12:40:15 AM   
anusumesh

 

Posts: 35
Joined: 19.Jun.2007
Status: offline
Hi Tom

thanks for reply. this solves my problem to sm extent.
Now  i have done configuration sucessfully but my problem is:


In Enterprise side MMC for Branch server Array error is : unable to retrieve data from server.
In Branch side MMC its working fine.
Also i m unable to ping their LAN IPs i.e.  branch LAN IP form Enterprise side and vice-versa.

What can be the problem?

Thanks in advance.

Anu

(in reply to tshinder)
Post #: 7
RE: MSA ISA Server 2006 Branch Edition Installation - 24.Jul.2007 10:30:26 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Are you using L2TP/IPSec?

Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to anusumesh)
Post #: 8
RE: MSA ISA Server 2006 Branch Edition Installation - 25.Jul.2007 1:06:01 AM   
anusumesh

 

Posts: 35
Joined: 19.Jun.2007
Status: offline
hi

No, i m using IPsec with preshared key.
Now its working but sometimes RPC failed connection is comming in logging tabs.
'n' even though vpn connection is successful now but i m unable to ping their LAN IPs from either side.

Plz assist me
thanks.

anu

(in reply to tshinder)
Post #: 9
RE: MSA ISA Server 2006 Branch Edition Installation - 25.Jul.2007 3:20:55 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Try L2TP/IPSec with a preshared key. Why?

1. More secure

2. DOUBLE the throughput

3. Easier to configure and supports routing

Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to anusumesh)
Post #: 10
RE: MSA ISA Server 2006 Branch Edition Installation - 26.Jul.2007 7:09:58 AM   
anusumesh

 

Posts: 35
Joined: 19.Jun.2007
Status: offline
hi

i ll try for this also.
My configuration is:

2 ISA Server 2006 for Enterprise and Branch server
Branch server is connecting to CSS on Enterprise side and joining second array on
enterprise side only.
For all this we r providing WEB UI for VPN connection and through UI preparing answer file that is used by APPCFGWZD.exe.

The problem is-  first time when this runs, it shows the following problem:

time ISA setup CA INFO   : Verifying that account: celestixtest.com\CELESTIX-Branch$ can be authenticated by storage server: celestix-ent.celestixtest.com
time ISA setup CA WARNING: AccountToSid(Local) failed. hr=0x800706FD
time ERROR: CustomAction 'VerifyDomainTrustWithStorageServer' failed, result=1603.
time ERROR: (TaskID=7, TaskName='VERIFY_DOMAIN_TRUST_WITH_CSS')->Run() failed, hr = 0x80004005(=E_UNEXPECTED).
time ERROR: An attempt to use Windows authentication to authenticate the request sent to the Configuration Storage server computer failed. Refer to Getting Started Guide for help on setting up Windows authentication.

But when i run this appcfgwzd.exe file agian with the same answerfile then its successfull and connection is created.
Enterprise server is running successfully on bpth sides.
But then on Main side - for branch Server the message is - "unable to retrieve data from server(branch)". On Branch side- there is no problem, server is in synchronization with CSS.

Plz help me in this.

thanks
anu

(in reply to tshinder)
Post #: 11
RE: MSA ISA Server 2006 Branch Edition Installation - 26.Jul.2007 11:02:59 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Is the CSS installed on a machine behind the ISA Firewall array?

Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to anusumesh)
Post #: 12
RE: MSA ISA Server 2006 Branch Edition Installation - 27.Jul.2007 1:26:46 AM   
anusumesh

 

Posts: 35
Joined: 19.Jun.2007
Status: offline
hi
thanks for replying.
ISA server 2006 Enterprise(Main Side)  and CSS are installed on same machine.

thanks
Anu

(in reply to tshinder)
Post #: 13
RE: MSA ISA Server 2006 Branch Edition Installation - 27.Jul.2007 9:25:35 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
That may be the problem. Install the CSS on a machine behind the ISA Firewall (ISA Firewall security best practice).

I've never been able to make the site to site VPN work when the CSS is on the ISA Firewall.

Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to anusumesh)
Post #: 14
RE: MSA ISA Server 2006 Branch Edition Installation - 30.Jul.2007 7:54:06 AM   
anusumesh

 

Posts: 35
Joined: 19.Jun.2007
Status: offline
Hi

Thanks for ur help.

My doubt is: Why is it successfull when we run APPCFGWZD.EXE second time?
Can u plz explain me the concept behind this?
And also what does it mean from "Windows Authentication"
I want to solve this problem: it should be successfull first time only.
I am a programmer and working on this issue only.

And one More Problem is: After successful configuration
Through WebUI(on Main Machine only): Branch Server is showing error "Unable to retreive data from server". and No Problem with Main server.
But in WebUI(on Branch side)- there is no such error (for both Main & Branch).

What can be the possible cause for this?

I got stuck at this point.
I have to solve these two issues programmatically. But i m unable to understand the possible causes of these problems..

Please help me in this.

Can i discuss this issue online with u? If possible then plz tell me the time 'n' procedure to be online on this site(or some where else).

Thanks
Anu

(in reply to anusumesh)
Post #: 15
RE: MSA ISA Server 2006 Branch Edition Installation - 6.Aug.2007 9:33:52 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Study this series and maybe you'll see what's not working:

http://www.isaserver.org/tutorials/Creating-VPN-ISA-2006-Firewall-Branch-Office-Connection-Wizard-Part1.html

Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to anusumesh)
Post #: 16
RE: MSA ISA Server 2006 Branch Edition Installation - 6.Aug.2007 11:16:48 AM   
anusumesh

 

Posts: 35
Joined: 19.Jun.2007
Status: offline
Hi

Thanks for reply.

i have gone through all these documents.

But my problem get solved. Actually we are using vbscript in which we r running two exe files(Isaaappinit.exe and Appcfgwzd.exe) continuously. Now  we have given sleep for some time after executing isaaappinit.exe. Now Appcfgwzd.exe is running successfully.

But still i am unable to identify the actual cause of the problem
Can u help me in this?(Isaappinit.exe is enabling some ISA services and starting CSS also.)

Thanks
Anu

(in reply to anusumesh)
Post #: 17

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 General] >> Installation and Planning >> MSA ISA Server 2006 Branch Edition Installation Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts