• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Web Listener Wont pass packets on to internal interface

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Publishing] >> Web Publishing >> Web Listener Wont pass packets on to internal interface Page: [1]
Login
Message << Older Topic   Newer Topic >>
Web Listener Wont pass packets on to internal interface - 7.Jan.2009 2:07:29 PM   
Pete89

 

Posts: 21
Joined: 20.Aug.2008
From: Granada Spain
Status: offline
Hello,

Here is a diagram of my network. The nAppliance mISA box had a hardware failure so I had to put in a spare server in its place. So, in the diagram where you see mISA 1200 there is now a IBM server running ISA 2006 on Windows 2003 sp2. I have everything working OK except the Web Listener for the mIAG portal. I can see HTTPS packets getting to the public IP of the ISA box but they dont get forwarded to the 192.168.1.0 network. Not one packet.

In ISA Server Management I can run Test Rule it checks out ok and I see https packets flying.

I have two public IPs on the external interface because we are using two certificates. This same setup was working on the mISA box but for some reason I cant get it to work on this temporary server.

Thanks for any ideas and help,

P.
Post #: 1
RE: Web Listener Wont pass packets on to internal inter... - 7.Jan.2009 2:20:49 PM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
Check your networks for the correct IP ranges mentioned in the ISA console

Check for any relevant alerts

Make sure you have NAT relationship between ISA external and ISA's IAG connected network

Since you are using two IPs with two certs and if you are using two web listeners then make sure they are pointing to their resp IPs under networks tab in web listener

Try to take a network trace on the public and the IAG connected NIC on ISA to identify issues

< Message edited by inderjeet -- 7.Jan.2009 2:22:58 PM >


_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to Pete89)
Post #: 2
RE: Web Listener Wont pass packets on to internal inter... - 7.Jan.2009 2:53:41 PM   
Pete89

 

Posts: 21
Joined: 20.Aug.2008
From: Granada Spain
Status: offline
OK this officail got real wierd after a reboot. The web listener now works and I can get to the Portal on the mIAG box but:

VPN client no longer worked
Site-to-site VPN no longer worked
Remote Desktop to the ISA Server no longer worked
RPC no longer worked (Remote Management etc.)

This forced me to go to the console of the ISA server and restart the MS Firewall service and BOOM ... everything is working again. Like everything mIAG, VPNS, Remote Desktop, RPC.

What is going on here???

(in reply to inderjeet)
Post #: 3
RE: Web Listener Wont pass packets on to internal inter... - 7.Jan.2009 3:46:34 PM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
Telling just based on behavior is always hard. The behavior can be becz of so many reasons.

Run ISA BPA and see if there are any configuration errors. This will help you troubleshoot alot many things

ISA BPA can be downloaded and installed from the following location:
http://www.microsoft.com/downloads/details.aspx?FamilyID=d22ec2b9-4cd3-4bb6-91ec-0829e5f84063&DisplayLang=en



_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to Pete89)
Post #: 4
RE: Web Listener Wont pass packets on to internal inter... - 7.Jan.2009 4:18:46 PM   
Pete89

 

Posts: 21
Joined: 20.Aug.2008
From: Granada Spain
Status: offline
One critical error in the report:


"07/01/2009 20:51:46 - The Web Proxy filter failed to bind its socket to 62.81.208.12 port 80. This may have been caused by another service that is already using the same port or by a network adapter that is not functional. To resolve this issue, restart the Microsoft Firewall service. The error code specified in the data area of the event properties indicates the cause of the failure.
The failure is due to error: Only one usage of each socket address (protocol/network address/port) is normally permitted."
 
The .12 address is the second address on the WAN interface. Its the address for the portal. So from this error message I can see I did the right thing by restarting the MS Firewall Service but what is the long term fix?

(in reply to inderjeet)
Post #: 5
RE: Web Listener Wont pass packets on to internal inter... - 8.Jan.2009 11:36:18 AM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
Do you have IIS running on the machine? If yes, you have to release the port 80......

Also, type NETSTAT -ano on the command prompt to see if you have an entry as 0.0.0.0:80

If you does then there is a conflict of port 80 with an application such as IIS

If you have IIS, stop all websites in it and turn on one by one, then whenever u start a website, run the above command each time and see which website is in conflict

_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to Pete89)
Post #: 6
RE: Web Listener Wont pass packets on to internal inter... - 8.Jan.2009 12:07:03 PM   
Pete89

 

Posts: 21
Joined: 20.Aug.2008
From: Granada Spain
Status: offline
Thanks for gettign back to me. I appreciate it very much.

No IIS running on this spare server.I ran the netstat -bano command and the only thing I saw was:

TCP  62.81.208.11:80   0.0.0.0:0   LISTENING      2092    [wspsrv.exe]

Also there were two more messages in the analysis that I didnt notice at first that had to do with RPC:


Strict RPC compliance is enforced in the access rule vpn, which allows traffic to or from the Local Host network. This message can be safely ignored if this is your intention. To allow non-strict RPC traffic, expand the Firewall Policy node, right-click the rule vpn, click Configure RPC protocol, and clear the Enforce strict RPC compliance check box.

There was another one like this for another rule, but I dont know what to make of it.

(in reply to inderjeet)
Post #: 7
RE: Web Listener Wont pass packets on to internal inter... - 8.Jan.2009 12:41:19 PM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
Can you send me the below screenshots on isaissues@yahoo.com

1. For all websliteners > network tab
2. ISA console with middle window expanded to show maximum on the rules
3. Alerts

run netstat -ano >c:\netstat.txt

send me the text file as well

_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to Pete89)
Post #: 8
RE: Web Listener Wont pass packets on to internal inter... - 23.Jan.2009 9:49:05 AM   
Pete89

 

Posts: 21
Joined: 20.Aug.2008
From: Granada Spain
Status: offline
OK first of all I want to give big Thanks to inderjeet for helping me on this one. We ran the best practice tool on this box and tried several things, but what ultimately I did was put in new hardware. The one thing I think that may have been a problem was I had two listeners on one IP. One was a test listener I had forgotten about.

I imported everything into the new server and there were NO issues after rebooting the new box.

Again without Inderjeet I might still be pounding my head on the table.

Gracias Amigo!!

(in reply to inderjeet)
Post #: 9
RE: Web Listener Wont pass packets on to internal inter... - 23.Jan.2009 9:54:22 AM   
inderjeet

 

Posts: 463
Joined: 25.Nov.2008
Status: offline
Thanks for your feedback. I am happy that you have resolved the issue. These kind of issues are hard to figure out.

_____________________________

Inderjeet (MSFT)
My Blog: http://isingh.spaces.live.com

If you are a Microsoft Gold Partner, Contact us for Advisory/Consulting Services, Check https://partner.microsoft.com/US/supportsecurity/40012316

(in reply to Pete89)
Post #: 10

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Publishing] >> Web Publishing >> Web Listener Wont pass packets on to internal interface Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts