1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

ISA Server 2004 WAN Dropout

Discussion in 'Windows Server System' started by kiomega, 2008/08/24.

  1. 2008/08/24
    kiomega

    kiomega Inactive Thread Starter

    Joined:
    2007/07/09
    Messages:
    44
    Likes Received:
    0
    Hi,
    First I will explain my set up. I have two servers. SRV-001 is running AD, DNS, DHCP, IAS and is the Enterprise CA. SRV-002 is just running ISA 2004. SRV-002 has two NICs: one for the LAN and one for the WAN. I have set up ISA to be an 'Edge Firewall'.

    I can browse the internet fine on SRV-002 without ISA installed. When I install ISA, all is good for about 24 hours, and then the WAN drops. It tries to get an IP address on the WAN interface and it cannot. If I uninstall ISA, it can instantly get an IP address, and when I reinstall ISA, it works for about another day, and then drops again. I have tried a different NIC, a different modem, even a different network cable! But I figured it can't be any of them because it works fine without ISA, so it is something ISA is doing.

    Can anyone help?

    Thanks,
    Michael
     
  2. 2008/08/25
    ReggieB

    ReggieB Inactive Alumni

    Joined:
    2004/05/12
    Messages:
    2,786
    Likes Received:
    2
    What are the IP addresses of the two NICs in SRV-002?
     

  3. to hide this advert.

  4. 2008/08/25
    kiomega

    kiomega Inactive Thread Starter

    Joined:
    2007/07/09
    Messages:
    44
    Likes Received:
    0
    The LAN NIC has a static IP address of 10.160.0.1/255.255.255.0 and the WAN NIC has a dynamicaly assigned address. I noticed it is when I try to renew my IP address on the WAN that I get problems, so I am assuming that the reason it lasts for 24 hours is because my lease with Telstra expires and it tries to renew the IP address.

    Very weird.

    Thanks.
     
  5. 2008/08/26
    ReggieB

    ReggieB Inactive Alumni

    Joined:
    2004/05/12
    Messages:
    2,786
    Likes Received:
    2
    On the contrary. It seems very straight-forward to me. You've diagnosed the problem yourself.

    If that isn't the cause of the problem, I'll eat my hat. Changing your external IP is going to have a huge impact on an ISA server. It's going to have to recalculate all its proxy and firewall functions, as all the relative paths will change.

    I'd recommend you don't connect the server directly to your internet connection. Instead, use a router to connect to your server to the network. Use NAT across the router so that the server is presented with an static private IP address. The 192.168.0.0 address space would be ideal for the network between your router and the server.

    The arrangement will be this:

    10.160.0.0==Server==192.168.0.0==router==Internet

    As this will mean that the address the server sees doesn't change every 24 hours, it shouldn't be confused every day. The router should be able to handle the changing IP address.
     
  6. 2008/08/26
    kiomega

    kiomega Inactive Thread Starter

    Joined:
    2007/07/09
    Messages:
    44
    Likes Received:
    0
    Thanks Reggie!
     
  7. 2008/08/26
    kiomega

    kiomega Inactive Thread Starter

    Joined:
    2007/07/09
    Messages:
    44
    Likes Received:
    0
    Actually, now I have another problem.

    I have set up the SRV-002 to require users to authenticate using 'Integrated' authentication before they can access the internet. However on one of the clients, if they click cancel at the username-password prompt, it just lets them through!!!

    Im pulling my hair out at this one.

    Thanks,
    Michael
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.