• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Can ping from ISA server but not SNAT client

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 Firewall] >> SecureNAT Client >> Can ping from ISA server but not SNAT client Page: [1]
Login
Message << Older Topic   Newer Topic >>
Can ping from ISA server but not SNAT client - 19.Apr.2002 5:31:00 PM   
Guest
Problem

I can ping external sites from ISA Server but not a SNAT client - client returns timeout.

Config

ISA is in integrated mode
I have ticked force packet filtering on array
I have ticked enable ip routing in the IP Packet filter properties
I have created a packet filter enabling ICMP ping query (Default external, Any, ICMP, Outbound, 8, 0)
I have an ping response in filter as well.

Logs
The Packet Filter log has the following error:
<date>,<time>,SNAT IP,dest IP,ICMP,8,0, BLOCKED Dialout

This seems to imply that the packet filter is preventing the ping leaving the ISA server but I cannot see why. Any ideas?

Mark
  Post #: 1
RE: Can ping from ISA server but not SNAT client - 19.Apr.2002 5:51:00 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Mark,

check out http://www.isaserver.org/shinder/tips/tip_ping_pptp.htm and don't forget the client must also be a SecureNAT client for that.

HTH,
Stefaan

(in reply to Guest)
Post #: 2
RE: Can ping from ISA server but not SNAT client - 19.Apr.2002 6:19:00 PM   
Guest
spouseele,

Thanks for the quick reply. I read the article you pointed to, this seems to concentrate on ensuring that I have enabled ip routing, as noted in my first post this is enabled. So unfortunately I am none the wiser, any other ideas?

Thanks in advance

Mark

(in reply to Guest)
  Post #: 3
RE: Can ping from ISA server but not SNAT client - 19.Apr.2002 6:30:00 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Mark,

I don't think you need to define yourself the ICMP packet filters. Just make sure that the default ICMP packet filters (Access Policy) are enabled.

HTH,
Stefaan

(in reply to Guest)
Post #: 4
RE: Can ping from ISA server but not SNAT client - 19.Apr.2002 6:50:00 PM   
Guest
spouseele,

I disabled my own customer filter but unfortunately no change in status.

Mark

(in reply to Guest)
  Post #: 5
RE: Can ping from ISA server but not SNAT client - 19.Apr.2002 10:32:00 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Mark,

you are sure the default packet filters are enabled (see also KB article Q274568)? Have you already checked the Event viewer for errors and warnings? Also, check de LAT and that no default gateway is set on ISA internal interface.

If the ISA packet filter log still shows the packets being blocked, then there must be something wrong with the ICMP packet filters or the ISA setup?

HTH,
Stefaan

[ April 19, 2002, 10:45 PM: Message edited by: spouseele ]

(in reply to Guest)
Post #: 6
RE: Can ping from ISA server but not SNAT client - 20.Apr.2002 2:02:00 PM   
gvineet53

 

Posts: 7
Joined: 17.Apr.2002
Status: offline
Hi Stefaan,

Even I'm facing the similar problem as Mark.
I AM able to ping & tracert & NSlookup from ISA box
With SNat clients Nslookup is working FINE, however tracert and ping is NOT working on SNat clients.
I have tried all the things that have been discussed above in this topic and other topics. Still I fail to figure out what's wrong with the configuration.
Also the Application Log in Event viewer on my ISA box shows 14120 error.

Is that why my mail server(Exch 2000) is not able to send and receive mails to and from outside my local network???

How can I resolve this problem??

Thanks,

-Vineet

(in reply to Guest)
Post #: 7
RE: Can ping from ISA server but not SNAT client - 20.Apr.2002 11:27:00 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Vineet,

check out http://support.microsoft.com/default.aspx?scid=kb;en-us;Q288396 for the Event log 14120 error.

It sounds to me that your ISA server may not have been setup correctly. Check out http://www.isaserver.org/pages/tutorials/setting_up_machine_before_isa_installtion.htm .

HTH,
Stefaan

(in reply to Guest)
Post #: 8
RE: Can ping from ISA server but not SNAT client - 23.Apr.2002 11:35:00 PM   
jgisler

 

Posts: 56
Joined: 10.Apr.2001
Status: offline
on these client machines that you are trying to ping/traceroute from, what is the DNS & gateway pointing at? Make sure the Gateway is the ISA box. You can try the DNS as that as well. I had similar problems when I had the clients configure through a different gateway & not the isa server.

(in reply to Guest)
Post #: 9
RE: Can ping from ISA server but not SNAT client - 24.Apr.2002 8:25:00 AM   
gvineet53

 

Posts: 7
Joined: 17.Apr.2002
Status: offline
Hi Stefaan, Mark & Jgisler,

I finally was able to get this working. I re-installed the ISA server and re-cofigured all the Access Policies and filters etc. However the problem I guess was with LAT. I could see a different enteries in the LAT after and before re-installation. [Big Grin]

Thanks All of You,

Regards,

-Vineet

(in reply to Guest)
Post #: 10
RE: Can ping from ISA server but not SNAT client - 24.Apr.2002 3:58:00 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Vineet,

glad you got it working and thanks for the follow up. [Smile]

Regards,
Stefaan

(in reply to Guest)
Post #: 11

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 Firewall] >> SecureNAT Client >> Can ping from ISA server but not SNAT client Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts