From: Sydney, Australia
Last night the firewall service on my ISA2004 box crashed when it was trying to create the new days log file. Message from the Application log is below. There were no other messages logged before this message, and only messages relating to shutting down the Firewall service after ('sent a stop control', 'shutdown gracefully', etc). I can not find any information about this error anywhere. This is a new server, it's only been in production for about 2 weeks. The "ISALogs" is only about 900MB, and there is 33 GB free on the disk. Can anyone help me find out what actually happenned, so I can make sure it doesn't happen again.
Event Type: Error Event Source: Microsoft Firewall Event Category: Log Event ID: 21192 Date: 4/03/2005 Time: 12:00:10 AM User: N/A Computer: ******** Description: The Microsoft Firewall was unable to connect to MSDE database. The MSDE Error description is: Device activation error. The physical file name 'D:\Program Files\Microsoft ISA Server\ISALogs\ISALOG_20050305_FWS_000.ldf' may be incorrect., CREATE DATABASE failed. Some file names listed could not be created. Check previous errors..
From: Chicago area
More on the order of adding to the fire - not putting it out.
When I installed SP1 to ISA04, it blew up. Couldn't start the firewall service. THIS was one of the many error messages in event logs. Tried permissions on different reg keys, temporarily moving logs, and misc "fixes." The issues seemed to be ISA confusion over write permissions and/or registery permissions.
I never did figure it out. The goods news is that it didn't require a bare-metal restore. Just uninstalled ISA and reinstalled. The second time around SP1 went in "cleanly."
Reporting is still broken. The "sessions" tab returns the report tab.
Oh well - maybe it will take a bare-metal restore.
Moral: Make sure you have your configuration backed up !
Anyone have any ideas on the MSDE database issue??
Last night the ISA server seemed to stop working with events showing that the were denied access. Server was rebooted this morning and the firewall service did not start: Event Type: Error Event Source: Microsoft Firewall Event Category: Log Event ID: 21192 Date: 13/04/2005 Time: 8:09:01 AM User: N/A Computer: Server Description: The Microsoft Firewall was unable to connect to MSDE database. The MSDE Error description is: Could not find database ID 320. Database may not be activated yet or may be in transition., Multiple-step OLE DB operation generated errors. Check each OLE DB status value, if available. No work was done., Property value is invalid. Make sure the value is typed correctly..
i have the same problem last two weaks. It happent 4 time in this time frame. I'm traying to resolve this issue. Do you have MSSQL server installed on this machine? (not MSDE, MSSQL). Do you have any job exectuting at this time (0:00)
From: Sydney, Australia
ISA is logging to MSDE, which I'm running on the same box as ISA. No MSSQL involved. There are no scheduled jobs running at this time.
The service failure is still happenning regularly, however I now have a scheduled job to restart the firewall service at 2 minutes past midnight. This is an effective bypass, but I would like to know what the original issue is, and how to fix it.
open MSDE logs folder and see if you have something like this repeating over and over agin... "starting up database 'database name'"... This is something i get in my logs, and i think it could be related to this problem. I will try to solve this and see if it fixes the problem
From: Sydney, Australia
Well, I do get that message, but only one each time the database is started (by the automated process) and only after it has crashed. No multiple repeats of the message. At the time of the crashes, there are no log messages at all... perhaps I need to turn the logging level up. Not sure how to do this with MSDE though.
my firewall has some interesting crashing interval. It crashes 2 days in a row, and then it works 5 days without problem, then interval repeat. Does your firewall crashes every day or it also has some strange interval?
After some testing i got the following answers: 1. I changed log location to see what will happen 2. Something interesting come out - it created some logs in old location 2 days after it ! It also left one log few months old in old logs folder 3. Try to delete old logs - but MSDE hold them locked 4. Change log type to text, stopped msde, delete old logs, started MSDE, changed log back to MSDE. 5. ISA works like a baby since this action (two wheeks). 6. Left Alert action that starts Firewall if it stopped - yust in case .
I have a followup on this.... I have same error on another server, and i the problem was different . Server crashes exactly the same way ! But the problem was different. It was a "multipurpose" firewall So... it was file server, and firewall. It crashes in strange intervals, once a wheek exactly at 2AM. The problem was backup Somebody put firewall logs in backup job, when backup do his job firewall has a problem accessing those files - and it crashes. I could reproduce this error when ever i wanted whit this backup job. After removing firewall database and log files from backup scenario - it works like a baby