Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ISA server suddenly blocks web publishing

Status
Not open for further replies.

shaferbus

MIS
Dec 7, 2002
130
0
0
US
Let me apologize in advance if I've made a rookie mistake, but I find ISA server really confusing and I'm completely lost.
I have a local domain with a Win2000 Small Business Server box running Exchange 2000, IIS 5.0, and ISA Server (Integrated). The LAN is behind a Netgear router/Firewall, which is also the DHCP server.

I created a small website for employees to check their schedules remotely. It runs on a Win2000 Pro workstation running IIS 5.0 (locked down) and uses Integrate Authentication. I directed Port 80 to the IP address of this workstation, and everything ran fine for about 2 weeks (Except URLscan was blocking a few users, but that's a different issue).

Yesterday afternoon, there was suddenly no access to the website from the internet. Some users recieve an IE error "Cannot find server or DNS Error" page, while others recieve an ISA server error "10061 - Connection refused" page. According to the latter "The server you are attempting to access has refused the connection with the gateway. This usually results from trying to connect to a service that is inactive on the server."

Does anyone have any idea why, if I've mis-configured ISA server, the site ever worked in the first place? What steps do I have to take to get ISA to allow me to publish? I created a web publishing rule that applies to any request and directs it to the IIS workstation, but that seems to have no effect.

Why the two different error pages on different machines?

Do I even need ISA server in this scenario? I only installed in "integrated" mode because I didn't know any better at the time. I realized after that that with only one NIC it's kind of useless and generates a zillion web proxy events in the application log, but it hasn't really caused any problem until now. Since I have a hardware firewall, should I reinstall in cache mode?

I hope this makes some kind of sense to someone out there LOL. Thanks
 
Did you open the firewall up on the hardware router (let the isa server be the DMZ host)? Just a suggestion I am not familiar with the netgear boxes but typically those routers have DMZ capabilities.
 
That's a good suggestion rsurovick, and I had tried putting the machine in the DMZ... didn't help at the time, but I came to the conclusion that it was indeed a router issue.

Turns out the router itself was at fault. Although it was set to direct Port 80 requests to the web server, and the logs said that's what it was doing, it was in fact directing them to the ISA server machine! (That's right, it was lying LOL)

I reinstalled the router's firmware and reconfigured, and it appears to have cured the problem (I'm still going to do some monitoring before I call it fixed.)

Thanks for the relevant suggestion though :)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top