• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Can't connect to CSS on array install

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 General] >> Installation and Planning >> Can't connect to CSS on array install Page: [1]
Login
Message << Older Topic   Newer Topic >>
Can't connect to CSS on array install - 16.Dec.2008 12:30:38 PM   
skoog

 

Posts: 3
Joined: 16.Dec.2008
Status: offline
Iím aware of the general consensus on this site to have the array joined to domain, but Iím not looking to discuss that here.   That being said, I'm attempting to install ISA array in a workgroup, but the install fails to connect to CSS (in domain).  There is a firewall between CSS and array.

I can resolve all servers each way and I've successfully imported root and server certs.  My main question is what ports are required to/from CSS and array members. I currently have open,
-port 2172 from array to CSS
-port 636 from array to DC
-port 80 from array to CA (I was having problem with CRL lookup).  May move replica CRL and close this port

Do I need port 2171 from CSS to array open for this scenario or does 2172 need to be open both ways?
Post #: 1
RE: Can't connect to CSS on array install - 17.Dec.2008 11:54:50 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
System Policy will indicate what protocols are allowed.

However, the workgroup configuration is a bit unsecure -- join it to the domain to get the highest level of security.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to skoog)
Post #: 2
RE: Can't connect to CSS on array install - 17.Dec.2008 12:47:38 PM   
Jason Jones

 

Posts: 4663
Joined: 30.Jul.2002
From: United Kingdom
Status: offline
...with limited CSS high availability

_____________________________

Jason Jones | Forefront MVP | Silversands Ltd
My Blogs: http://blog.msedge.org.uk/ and http://blog.msfirewall.org.uk/

(in reply to tshinder)
Post #: 3
RE: Can't connect to CSS on array install - 17.Dec.2008 3:15:24 PM   
skoog

 

Posts: 3
Joined: 16.Dec.2008
Status: offline
I appreciate your responses, but I figured out the answer to my question.  Port 2171 is required open on firewall, one way from array to CSS, for install to complete.  I don't believe you need this port open after the  install is complete as ISA should be using 2172 going forward (have not verified this) in a workgroup scenario.  Iíll verify and close port if true.  Thanks.

(in reply to Jason Jones)
Post #: 4
RE: Can't connect to CSS on array install - 17.Dec.2008 3:19:58 PM   
skoog

 

Posts: 3
Joined: 16.Dec.2008
Status: offline
RE: domain v. workgroup.  I'm assuming you have a blog or article that discusses this.  Please link it, as I'd like to read it.  Thanks, again.

(in reply to skoog)
Post #: 5
RE: Can't connect to CSS on array install - 17.Dec.2008 4:59:07 PM   
Jason Jones

 

Posts: 4663
Joined: 30.Jul.2002
From: United Kingdom
Status: offline
http://www.isaserver.org/tutorials/Debunking-Myth-that-ISA-Firewall-Should-Not-Domain-Member.html

Please share the details when you figure it all ok...

Cheers

JJ

_____________________________

Jason Jones | Forefront MVP | Silversands Ltd
My Blogs: http://blog.msedge.org.uk/ and http://blog.msfirewall.org.uk/

(in reply to skoog)
Post #: 6

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 General] >> Installation and Planning >> Can't connect to CSS on array install Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts