ISA Clients >> Cannot access only one website

by SlA » Sat, 31 Jan 2009 03:19:06 GMT

I cannot access www.tradestation.com from our network.

I do not see any ISA rules blocking it.

Tried several PC's in the office (in and out of local AD domain).

Tried from the ISA server.

Tried FireFox.

Tried access via IP Address.

I "can" access outside the ISA server.

Any suggestions?

Thx JP







ISA Clients >> Cannot access only one website

by Phillip Windell » Sat, 31 Jan 2009 04:36:11 GMT


What IP Range do you use on the LAN?

How do you handle DNS on your LAN?

I know you tried via IP# but that really doesn't prove anything,...due to a
flaw in IE most of the time that will fail even when everything is perfect.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------

ISA Clients >> Cannot access only one website

by SlA » Mon, 02 Feb 2009 23:10:07 GMT

Hi Phillip!

The LAN IP addressing for the internal NIC is in the 192.168.119.xxx range.

The domain controllers (DC) host the DNS service. The DNS has fowarders to
external DNS (of ISP).

I followed an ISA technote for setting up DNS on the ISA. Internal NIC
points to Internal DNS server on DC (A couple advanced settings in IP DNS -
per the technote. Append primary & register this connection)

Bascially no DNS settings on the external NIC.

Did this answer your question?

Thanks for any feedback.
JP

ISA Clients >> Cannot access only one website

by Phillip Windell » Mon, 02 Feb 2009 23:45:08 GMT


I would have a clue what "an ISA technote" tells you,...some of those I
don't even agree with.

You point the ISA's internal Nic to the AD/DNS,...external nic
blank,...create anonymous allow rule to allow AD/DNS to make outbound DNS
queries,..AD/DNS uses ISP as Forwarder,...that is it.
Sounds like you've done that.

I don't see anything wrong with anything.

Start using the ISA monitoring log...

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html




--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Technet Library
ISA2004
http://technet.microsoft.com/en-us/library/cc302436 (TechNet.10).aspx
ISA2006
http://technet.microsoft.com/en-us/library/bb898433 (TechNet.10).aspx

Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.mspx

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------

ISA Clients >> Cannot access only one website

by SlA » Thu, 05 Feb 2009 03:09:44 GMT

Phillip,

Curious about this comment:
<<<create anonymous allow rule to allow AD/DNS to make outbound DNS

Can you elborate on creating an "anonymous" rule?

I will look into the suggestions/technotes you provided.

Thx JP

ISA Clients >> Cannot access only one website

by SlA » Thu, 05 Feb 2009 03:12:01 GMT

Phillip,

The first article you referred helped me figure out a partial fix. I can
now access the website but I do not have the functionality needed. Another
person had created a network set for specific ip addresses to allow a unique
access to this site. In the end, the network set kept the site from being
accessed. Now I have the original task of setting up a specifc type access
to this location. Possibly I can tell you what I need to accomplish and you
can recommend a config?

The instructions call for the following:
Incoming/Outgoing TCP/IP connection through port 11000,11001,11002 and 11020.

Incoming/Outgoing TCP/IP connections to the following address ranges:
63.99.207.xxx, 63.99.254.xxx, 64.74.235.xxx and 75.5.192.xxx.

Thx JP

ISA Clients >> Cannot access only one website

by Phillip Windell » Thu, 05 Feb 2009 05:51:26 GMT


"All Users" = anonymous

From: <Computer Set for the AD/DNS Servers>
To: <Computer Set for the ISP's DNS, or just use External>
Protocol: DNS
Users: "All Users"

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Technet Library
ISA2004
http://technet.microsoft.com/en-us/library/cc302436 (TechNet.10).aspx
ISA2006
http://technet.microsoft.com/en-us/library/bb898433 (TechNet.10).aspx

Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.mspx

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------

ISA Clients >> Cannot access only one website

by Phillip Windell » Thu, 05 Feb 2009 05:55:38 GMT


1. There is no such thing as "opeing a port" in ISA. You create Protocol
Definitions, then build Access Rules or Publishing Rules to make use of the
Protocol Definitions.

2. There is no such thing as Incomming/Outgoing with ISA. It is either
Incomming or it is Outgoing,...they are treated separately and represent
different Protocol Definitions.

3. Outgoing traffic uses Access Rules

4. Incomming traffic uses Publishing Rules.


--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Technet Library
ISA2004
http://technet.microsoft.com/en-us/library/cc302436 (TechNet.10).aspx
ISA2006
http://technet.microsoft.com/en-us/library/bb898433 (TechNet.10).aspx

Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.mspx

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------

ISA Clients >> Cannot access only one website

by SlA » Sat, 07 Feb 2009 00:49:02 GMT

Phillip,

OK - no problem setting up a protocol for outgoing.

How would you recommend setting up the IP addresses for outgoing? Would you
use a Computer Set?

Thx JP

ISA Clients >> Cannot access only one website

by SlA » Sat, 07 Feb 2009 00:55:26 GMT

Phillip,

<<> 2. There is no such thing as Incomming/Outgoing with ISA. It is either

Though I not smart enough to question your reply, I'm not sure I agree with
you on this one... What about secondary connections?

Thx JP

ISA Clients >> Cannot access only one website

by Phillip Windell » Wed, 11 Feb 2009 02:02:20 GMT


Those are a specific type of connection. Off the top of my head I cannot
name any single Protocol in ISA that actually uses them. Protocol that use
"secondary connections" quite often are very complext protocols that ISA
uses an Application Filter in combionation with,...the the Application
Filter compensates and handles these "secondary connections" and so the
secondaries are never actualy "defined" in the protocol definition. The
most common of these is the FTP Protocol which can have "gobs" of other
ports and connections involved. However when you look at its Properties it
only show "Inbound 21",...the FTP Access Filter" handles the rest.

The direction of a Protocol is defined by the direction of the Initial
Connection,...whatever happens after that is kind of irrelevant.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Technet Library
ISA2004
http://technet.microsoft.com/en-us/library/cc302436 (TechNet.10).aspx
ISA2006
http://technet.microsoft.com/en-us/library/bb898433 (TechNet.10).aspx

Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.mspx

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------

ISA Clients >> Cannot access only one website

by Phillip Windell » Wed, 11 Feb 2009 02:03:42 GMT


Yea, either that or an IP Range Object or a Subnet Object,...whichever
applies best tot he situation.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Technet Library
ISA2004
http://technet.microsoft.com/en-us/library/cc302436 (TechNet.10).aspx
ISA2006
http://technet.microsoft.com/en-us/library/bb898433 (TechNet.10).aspx

Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.mspx

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------

Similar Threads

1. Website cannot be accessed from internal workstations. - ISA Configuration

2. Cannot access a website through ISA 2004

3. Cannot access particular website

4. Cannot access internal website - 502 proxy error

Dear All,

Our users use default SecureNat (client's default gateway point to Internal
NIC of ISA 2k4) and I config proxy on their IE. The problem occurs after
they have proxy, they cannot access internal website anymore ! If i uncheck
web proxy then they can.I tried configure Direct Access by adding URL, IP of
internal wesite in ISA server\Configuration\Network\Internal\Web browser but
still have the problem. I also try to unbind the Web Proxy application
filter from the Hypertext Transfer Protocol (HTTP) but still the problem.
The error message is
Technical Information (for support personnel)
  a.. Error Code: 502 Proxy Error. The ISA Server denied the specified
Uniform Resource Locator (URL). (12202)
  b.. IP Address: x.x.x.x
  c.. Date: 2/13/2006 10:22:38 AM
  d.. Server: aaa.xyz.com
  e.. Source: proxy
Please help. Thanks very much.


5. Cannot access website on port 81

6. Cannot access website via ISA 2004

We use ISA 2004 Standard edition with the latest service pack.  Its running 
as a web proxy only and has only one nic, which is fine for what we need.

The problem is we sometimes have issues where we cannot access certain 
websites via the proxy which can be accessed fine when we bypass the proxy. 
We have one specific website which we cannot access via the proxy but works 
fine when bypass the proxy.  I have checked the ISA logs, and they read the 
following error status codes:

12209 The ISA Server requires authorization to fulfill the request.  Access 
to the web proxy service is denied.

5 Access is denied.

I have checked all the rules, DNS settings and also in IT use http1.1 with 
proxy is checked.  I have tried to disabling all the application filters and 
increasing the connection time outs but still no luck.  Is there anything 
else I can try.

What other methods can I use to troubleshoot this proxy error as we need to 
access this web site. 


7. Cannot access website internally - ISA Server

8. Cannot access websites after setting up schedule download

I had about 5 websites set up for scheduled download in ISA 2004 standard 
SP1, along with a large cache of 2GB.  This has worked fine for several 
months.

Last week two of the websites became unresponsive, timing out on IE on any 
workstation behind the ISA server.  The rest of the scheduled website URLs 
still work.  The website URLs work when I try them on a workstation directly 
connected to the internet, bypassing ISA server, so I concluded the problem 
was in ISA.

I removed the sites from the download schedule, still failed with a timeout. 
Then I disabled caching, still failed.  I deleted the ISA cache, still 
failed.  (I restarted ISA Server after each attempt.)

Then I added a cache rule to explicitly not cache those two URLs.  Still 
times out from behind the firewall.  I can ping the site addresses, so DNS 
is okay.

The host OS for ISA Server is WIndows 2003 Standard, SP1 not installed but 
all other updates current.  Server has been rebooted, no affect on the 
problem.

So I have to assume it's related to ISA caching, but I'm not sure what else 
to try.  My working premise was that something in the ISA 2004 caching was 
corrupted, but after deleting the cache and all scheduled downloads I don't 
know where else to look.  There are no access rules specific to those 
websites or IP numbers.  I wasn't able to locate anything on corrupted cache 
in Technet.  Any suggestions?
  Jack Peacock