Advertisement

08.27.2007 at 09:23AM PDT, ID: 22789413
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

6.6

ISA not auto failing over

Asked by Silverthorn21 in MS Forefront-ISA, Network Software Firewalls, Windows Networking

Tags: , , ,

Hi All,

ISA server not auto failing over to the other.

I have two ISA servers ISA1 and ISA2.  I have a deticated DC that is running DHCP, WINS, DNS & now the CSS service for the ISA servers.  Each ISA server has two nic's; one external, one internal.  Both servers are 2003 server enterprise with ISA 2006 Enterprise.  All service packs & critical & recommended updates have been installed for the W2K3 OS.  No updates (i haven't found any as of yet) for the ISA 2006 servers.  

Both servers are in the array BC-HO-Firewall
bc-ho-ISA1 - 10.10.10.253 int  64.251.65.202 ext T1
bc-ho-ISA2 - 10.10.10.252 int  208.181.243.157 ext DSL
    NLB to 10.10.10.251 (Used ISA 2006 wizard to do this) Internal only

Two rules:
      Allow all outgoing network traffic
      Block all incoming traffic

Everything works and it is NLB'ing (I think) until I unplugg one of the external connections to simulate a failure.  If I unplug ISA2 external connection when I browse any sites that have previously gone through that server I get the following message

Technical Information (for support personnel)
      Error Code: 502 Proxy Error. An address has not yet been associated with the network endpoint. (1228)
      IP Address: 72.14.253.103
      Date: 8/27/2007 4:07:37 PM [GMT]
      Server: bc-ho-isa2.internal.natursfare.com
      Source: proxy

I'm using a firewall client.

Intra array communication is occurring on the 10.10.10.25x IP (tried using a 192.168.10.x but it kept losing communication)

here is the routing table for ISA1

IPv4 Route Table
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...02 bf 0a 0a 0a fb ...... Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC - Network Load Balancing Filter Device
0x10004 ...00 17 9a 05 0b c0 ...... D-Link DFE-530TX PCI Fast Ethernet Adapter (rev.C)
===========================================================================
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0    64.251.65.201    64.251.65.202     20
       10.10.10.0    255.255.255.0     10.10.10.253     10.10.10.253     20
     10.10.10.251  255.255.255.255        127.0.0.1        127.0.0.1     20
     10.10.10.253  255.255.255.255        127.0.0.1        127.0.0.1     20
   10.255.255.255  255.255.255.255     10.10.10.253     10.10.10.253     20
    64.251.65.200  255.255.255.248    64.251.65.202    64.251.65.202     20
    64.251.65.202  255.255.255.255        127.0.0.1        127.0.0.1     20
   64.255.255.255  255.255.255.255    64.251.65.202    64.251.65.202     20
        127.0.0.0        255.0.0.0        127.0.0.1        127.0.0.1      1
        224.0.0.0        240.0.0.0     10.10.10.253     10.10.10.253     20
        224.0.0.0        240.0.0.0    64.251.65.202    64.251.65.202     20
  255.255.255.255  255.255.255.255     10.10.10.253     10.10.10.253      1
  255.255.255.255  255.255.255.255    64.251.65.202    64.251.65.202      1
Default Gateway:     64.251.65.201
===========================================================================
Persistent Routes:
  None

Here is the routing table for ISA2

IPv4 Route Table
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...02 bf 0a 0a 0a fb ...... NVIDIA nForce Networking Controller - Network Load Balancing Filter Device
0x10004 ...00 17 9a 3b 4d dc ...... Realtek RTL8139 Family PCI Fast Ethernet NIC
===========================================================================
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
       10.10.10.0    255.255.255.0     10.10.10.252     10.10.10.252     20
     10.10.10.251  255.255.255.255        127.0.0.1        127.0.0.1     20
     10.10.10.252  255.255.255.255        127.0.0.1        127.0.0.1     20
   10.255.255.255  255.255.255.255     10.10.10.252     10.10.10.252     20
        127.0.0.0        255.0.0.0        127.0.0.1        127.0.0.1      1
        224.0.0.0        240.0.0.0     10.10.10.252     10.10.10.252     20
  255.255.255.255  255.255.255.255     10.10.10.251            10004      1
  255.255.255.255  255.255.255.255     10.10.10.252     10.10.10.252      1
===========================================================================
Persistent Routes:
  None

Am I missing something???? new to ISA server and NLB so i'm not sure what is the issue.  Also I would like to use VPN failover (my other sites have only 1 server in the array) Please help ASAP


DanStart Free Trial
[+][-]08.27.2007 at 11:41AM PDT, ID: 19777585

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08.27.2007 at 11:57AM PDT, ID: 19777696

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.27.2007 at 12:01PM PDT, ID: 19777744

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.27.2007 at 12:17PM PDT, ID: 19777881

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08.27.2007 at 01:22PM PDT, ID: 19778367

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.27.2007 at 01:30PM PDT, ID: 19778430

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08.27.2007 at 01:40PM PDT, ID: 19778500

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.27.2007 at 02:22PM PDT, ID: 19778793

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08.27.2007 at 02:51PM PDT, ID: 19778963

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.27.2007 at 02:53PM PDT, ID: 19778973

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08.29.2007 at 08:39PM PDT, ID: 19797306

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.30.2007 at 02:02AM PDT, ID: 19798405

View this solution now by starting your 14-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: MS Forefront-ISA, Network Software Firewalls, Windows Networking
Tags: address, associated, been, isa
Sign Up Now!
Solution Provided By: keith_alabaster
Participating Experts: 1
Solution Grade: A
 
 
[+][-]08.30.2007 at 04:13PM PDT, ID: 19804910

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.03.2007 at 04:54PM PDT, ID: 19822575

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.06.2007 at 04:39PM PDT, ID: 19844478

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.14.2007 at 09:05AM PDT, ID: 19892767

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.14.2007 at 09:28AM PDT, ID: 19892951

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09.14.2007 at 09:29AM PDT, ID: 19892967

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.14.2007 at 09:31AM PDT, ID: 19892993

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 14-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.14.2007 at 09:32AM PDT, ID: 19892998

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 14-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20081112-EE-VQP-43 / EE_QW_1_20070628