• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

SecureNAT Client can't access published servers

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 General] >> Server Publishing >> SecureNAT Client can't access published servers Page: [1]
Login
Message << Older Topic   Newer Topic >>
SecureNAT Client can't access published servers - 9.Sep.2003 3:20:00 AM   
turbo510

 

Posts: 3
Joined: 2.Sep.2003
Status: offline
I've published a couple of services via the Server Publishing including PCAnywhere and Web. Note that for one address, I'm publishing a web server via the Server Publishing, and for another IP address, I'm publishing a different web server via Web Publishing.

To test it out, I try to connect with my workstation, which is a SecureNAT client to the public ip address of the published web servers. I can access the published website that is using the Web Publishing from a SecureNAT client, but I can't access any services that are published using the Server Publishing unless the web client is from a completely different external ip address. I just can't access any Server Publishing services from my SecureNAT client.

Why is this the case?
Post #: 1
RE: SecureNAT Client can't access published servers - 9.Sep.2003 7:48:00 PM   
spouseele

 

Posts: 12826
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi turbo510,

that's perfect normal behaviour. You should always test the publishing rules from an external host. Check out http://www.isaserver.org/articles/14120_Errors_Discussion_and_Solution.html for more info. As a consequence, an internal host must always access internal resources directly, *not* the published instance.

HTH,
Stefaan

(in reply to turbo510)
Post #: 2
RE: SecureNAT Client can't access published servers - 19.Sep.2003 5:19:00 PM   
PepperdotNet

 

Posts: 7
Joined: 19.Sep.2003
Status: offline
I'm having a similar problem, I have an exchange 2003 on the internal network and have published smtp (a different server) for my customers on an external ISA address, I get NDR's when trying to send mail to my customers.

The customer is setup like this:

MX -> mail.thecustomer.com
mail CNAME incoming.mydomain.com

I have separate DNS for mydomain.com, so incoming.mydomain.com has its internal address on the internal dns, and the published external ISA address on the external dns.

Exchange is configured to use only the internal dns, which resolves external queries through the root-servers. I would have thought it would (1) go to root-servers to find mail.thecustomer.com then (2) return its authoritative address (internal) for incoming.mydomain.com when it saw the cname. I have even gone so far as to create HOSTS file entries on Exchange and ISA pointing to the internal address for that name and Exchange still tries to deliver to the external published address.

I am only able to send mail to my customers by having a 2nd MX record pointing to a backup server on a different network. It receives the mail from Exchange, then sends it right back to the ISA published address.

I have read and somewhat understand the article referred to by spouseele but it's kind of frustrating, why does the same scenario work fine with a $30 linksys or dlink router but not with ISA?

(in reply to turbo510)
Post #: 3
RE: SecureNAT Client can't access published servers - 19.Sep.2003 10:39:00 PM   
spouseele

 

Posts: 12826
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Pepper,

you can't loop through the ISA external interface and the reason why is very well explained in the mentioned article http://www.isaserver.org/articles/14120_Errors_Discussion_and_Solution.html . This is by design! [Big Grin]

Now, if I understand your configuration correctly, you have 2 internal mailservers A and B, and only B (for the customers) is server published on the ISA. Your problem seems to be you can't sent from server A to server B because an MX record lookup for the domains served by server B gives you the external IP address on ISA where you have published server B on. On the other hand, server A must be able to send to the external world too. Right?

I assume you know the domains who are served by server B. Therefore server A don't need to do an MX record lookup for those domains because server B is an internal resource. Therefore, just configure server A to route/relay those domains directly to the internal IP address of server B.

BTW --- I believe that according to the RFC's an MX record should always point to an A record, not a CNAME record.

HTH,
Stefaan

(in reply to turbo510)
Post #: 4

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 General] >> Server Publishing >> SecureNAT Client can't access published servers Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts