• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Branch office array unable to connect to CSS in main office

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Firewall] >> Branch Office >> Branch office array unable to connect to CSS in main office Page: [1]
Login
Message << Older Topic   Newer Topic >>
Branch office array unable to connect to CSS in main of... - 30.May2009 11:24:40 AM   
matt.jones

 

Posts: 72
Joined: 16.Aug.2007
From: Poznan, Poland
Status: offline
Hello,

I have set up a lab using ISA 2006 Enterprise Edition consisting of a single Enterprise with two arrays to simulate a main office/branch office site to site VPN scenario. I have configured the CSS in the main office to be located on the same box that is running ISA 2006 EE. No replica CSS has been deployed in the branch office and therefore the array member in the branch office is configured to connect to the CSS/ISA in the main office. The VPN connection is active and the branch ISA can communicate with a DC at the main office.

The problem that I'm experiencing is that the ISA 2006 EE array member in the branch office array is unable to connect to the configuration storage server in Main office. Also, the main office CSS/ISA is failing to connect to the branch office array member as the mgmt console of the ISA/CSS shows that it's unable to retrieve information from the server in the branch array.

When the branch office ISA tries to connect to the main office CSS/ISA, the logs on the main office array show that connections are being denied for the MS Firewall Storage and Control protocols. The source address is shown as the Branch ISA IP address assigned from the DHCP server on the main office internal network and the destination is the internal IP address of the CSS/ISA. When the main office CSS/ISA tries to retrieve information from the branch office array member, the logs show that connections are being denied to 'RPC (All Interfaces)'. In this case, the main office array logs show that the source address is the main office CSS/ISA IP address assigned from a static address pool configured on the branch ISA and the destination address is the internal IP address of the branch ISA.

Can anybody please help?

Thanks in advance.

_____________________________

Matthew Jones
MCSA/MCSE:M+S/VCP/CCA/CCNA
Post #: 1
RE: Branch office array unable to connect to CSS in mai... - 3.Jun.2009 4:29:46 PM   
Johnneke

 

Posts: 3
Joined: 17.Feb.2009
Status: offline
Yeh Matt, same problem as me indeed, Since I'm only playing around in a test enviroment I managed to get a fully functional vpn tunnel when creating it with a standard edition as opposed to the enterprise edition.

I have DHCP Relaying btw enabled at both sites and both are using dhcp for it's assigning although I just noticed that the branch site had a apipa address again. Odd.

(in reply to matt.jones)
Post #: 2
RE: Branch office array unable to connect to CSS in mai... - 3.Jun.2009 4:37:10 PM   
matt.jones

 

Posts: 72
Joined: 16.Aug.2007
From: Poznan, Poland
Status: offline
This worked for me http://www.isaserver.org/tutorials/2004dhcprelay.html

However, if you still have problems, it might be worth checking that the DHCP server on the main office network is working. I had a similar issue and it turned out the DHCP service on the DC at the main office had stopped.



_____________________________

Matthew Jones
MCSA/MCSE:M+S/VCP/CCA/CCNA

(in reply to Johnneke)
Post #: 3

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Firewall] >> Branch Office >> Branch office array unable to connect to CSS in main office Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts