• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

ISA 2004 SP3 Repeatedly Prompts Users for Credentials

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> Access Policies >> ISA 2004 SP3 Repeatedly Prompts Users for Credentials Page: [1]
Login
Message << Older Topic   Newer Topic >>
ISA 2004 SP3 Repeatedly Prompts Users for Credentials - 27.Jan.2010 8:49:43 AM   
Vorkuta

 

Posts: 7
Joined: 15.Nov.2007
Status: offline
Hello.  Don't post here often, so I'm not sure if this is in the right sub-forum or not.

Some background:

We have an ISA 2004 SP3 server set up in a single-armed (proxy) configuration.

Internal users -> ISA 2004 -> Cisco ASA -> Internet

Only members of a specific AD group can traverse it.  For some reason, random users at random times will get re-authentication popups and need to put their credentials back in.  Sometimes that results in the page being rendered, other times it does not... with the credentials re-popping up for every inline page element (graphics, etc).

We've tried clearing browser caches and rebooting and the like.  Sometimes recreating the user (over the top) seems to work.  I suspect it's something in the caching of credentials between ISA and the AD server, but I can't be sure... the ISA server logs don't seem to indicate anything (event logs, anyway).

I thought this issue might be resolved in SP3, but that didn't seem to help.  I can't find rhyme or reason to the pattern of prompts, either...

Any ideas?
Post #: 1
RE: ISA 2004 SP3 Repeatedly Prompts Users for Credentials - 27.Jan.2010 12:29:14 PM   
hrsanchez

 

Posts: 146
Joined: 30.Nov.2007
From: Argentina
Status: offline
Hi,

First check if you dont have comunication, authentication problems between Isa server and Domain controllers.
Check Isa server event viewer. Is your Isa server a domain member ?
Another thing to check is your isa server dns configuration.

http://elmajdal.net/isaserver/Internal_DNS_Forwarding.aspx

Probably these are the first issues to check.
Regards,

_____________________________

Eng.Hector Sanchez
MCSE + Security 2000/2003
MCTS Isa 2004/Isa 2006

(in reply to Vorkuta)
Post #: 2
RE: ISA 2004 SP3 Repeatedly Prompts Users for Credentials - 27.Jan.2010 12:41:53 PM   
Vorkuta

 

Posts: 7
Joined: 15.Nov.2007
Status: offline
1)  I have communication, as 99.9% of username/password lookups work fine.  As mentioned in the initial post, the problem appears random, and cannot be recreated at-will.
2)  Event log on the ISA server contains no errors.  (Aside from a couple of "decompress" errors for specific sites)
3)  Yes, the ISA server is a domain member.
4)  I'll set up a anyone-to-anywhere DNS rule and see what happens.

(in reply to hrsanchez)
Post #: 3
RE: ISA 2004 SP3 Repeatedly Prompts Users for Credentials - 27.Jan.2010 1:06:21 PM   
hrsanchez

 

Posts: 146
Joined: 30.Nov.2007
From: Argentina
Status: offline
The followings doc could help you:
http://www.microsoft.com/technet/isa/2004/plan/systempolicy.mspx#EIF and you may try the NO selection of Enforce strict RPC compliance.

Check your ISA interface configurations and make sure they configured per the article below.

http://www.isaserver.org/tutorials/Configuring_ISA_Server_Interface_Settings.html

Please make sure that Windows Networking (NetBIOS) is enabled in the ISA system policy and the rule is applied to the proper network.

If your server is running Windows server 2003 Service Pack 2, could be related to RSS issue with ISA blocking RPC. Please see: -> http://support.microsoft.com/default.aspx?scid=kb;EN-US;927695

http://blogs.technet.com/isablog/archive/2007/05/16/rpc-filter-and-enable-strict-rpc-compliance.aspx
Regards,

_____________________________

Eng.Hector Sanchez
MCSE + Security 2000/2003
MCTS Isa 2004/Isa 2006

(in reply to Vorkuta)
Post #: 4
RE: ISA 2004 SP3 Repeatedly Prompts Users for Credentials - 27.Jan.2010 2:11:26 PM   
Vorkuta

 

Posts: 7
Joined: 15.Nov.2007
Status: offline
Update:  Adding the DNS rule did not help.  Just had a user with the pop-up.

I'll check into removing the "strict" RPC flag...

(in reply to hrsanchez)
Post #: 5
RE: ISA 2004 SP3 Repeatedly Prompts Users for Credentials - 27.Jan.2010 2:26:40 PM   
hrsanchez

 

Posts: 146
Joined: 30.Nov.2007
From: Argentina
Status: offline
This is useful troubleshooting client Authentication article:

http://technet.microsoft.com/en-us/library/cc302664.aspx

Regards,

_____________________________

Eng.Hector Sanchez
MCSE + Security 2000/2003
MCTS Isa 2004/Isa 2006

(in reply to Vorkuta)
Post #: 6
RE: ISA 2004 SP3 Repeatedly Prompts Users for Credentials - 27.Jan.2010 2:45:47 PM   
Vorkuta

 

Posts: 7
Joined: 15.Nov.2007
Status: offline
Working my way through the list:

- "Require users to authenticate" is and has always been "off", so that's not it...
- Windows Media Player is not involved in my cases...
- Browser is IE, so that's not it...
- The users in question DO belong to the approprate groups...
- ISA server is not chained, so that's not it...
- No intranet involved... both client and servers are in the "internal" group (single-homed, as mentioned above)
- IIS not an issue... these are the same sites they access without issue at other times...
- Basic AND Integrated authentication are turned on, not just the first...
- Not a cached credentials issue... as the site worked fine 30 sec before...

Still working my way through a few others from that list.

(in reply to hrsanchez)
Post #: 7

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> Access Policies >> ISA 2004 SP3 Repeatedly Prompts Users for Credentials Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts