Solved

ISA 2004 Publishing Multiple Websites

Posted on 2004-10-18
4
1,227 Views
Last Modified: 2013-11-16
I'm new to ISA 2004, and need to publish multiple websites behind it.  I have run through the publish wizards, and for some reason I'm not able to get to either website from outside of my network.  Current setup looks like:

 - ISA sits behind existing firewall as part of private network (not the best scenario, but..)
 - Existing firewall is NATing all incoming HTTP and HTTPS traffic to ISA
 - Used ISA publishing wizards to publish websites (one is Exchange 2003 w/ OWA and Moble Sync, etc.  Have turned off Forms authentication, and have published both the web site for OWA and the mail server itself).  Second server listens on port 80 as well.  This one requires orginal header to function correctly (server.domain.com).
 - Internal DNS has been configured, and both sites work fine behind our firewall.  External DNS has been setup, and traffic gets to external firewall and then to ISA.

Any ideas, suggestions, etc. would be greatly appreciated.

Thanks,
Todd
0
Comment
Question by:toddnoe
  • 3
4 Comments
 
LVL 1

Author Comment

by:toddnoe
ID: 12381789
Anybody?
0
 
LVL 3

Accepted Solution

by:
thaller earned 500 total points
ID: 12414185
What browser error is reported?  (404, etc?)  Can you post snippets from the log files for the firewall?  If ICMP is allowed through the existing firewall and permitted on the ISA server, can you ping the address(es) of the external IPs?  Can you verify with netdiag that HTTP requests are hitting the adapter?  What is the addressing scheme of the private network and your network?  Can I throw any more rapid-fire questions at you?  ;)
0
 
LVL 1

Author Comment

by:toddnoe
ID: 12476020
Sorry for the delay - I almost lost hope.

Internal is Class C.  Nic1 on ISA is .2, Nic2 is .14.  Pinging the external ip will always get a response - all sites are the same public ip.  Public router kicks all http requests to firewall, which then kicks them to ISA, which is then supposed to route based on published server rules.

Snippet of Log File: (Ip's changed to protect the innocent...like it does much good, though - ha ha)

Original Client IP,Server Name,Transport,Result Code,Error Information,Log Time,Destination IP,Destination Port,Protocol,Action,Rule,Client IP,Source Network,Destination Network

68.126.XXX.XXX,SERVER1,TCP,0xc004000d FWX_E_POLICY_RULES_DENIED,0x0,11/2/2004 10:10,192.168.XXX.2,80,HTTP,Denied Connection,Default rule,68.126.XXX.XXX,External,Local Host

68.126.XXX.XXX,SERVER1,TCP,0xc004000d FWX_E_POLICY_RULES_DENIED,0x0,11/2/2004 10:10,192.168.XXX.2,80,HTTP,Denied Connection,Default rule,68.126.XXX.XXX,External,Local Host

68.126.XXX.XXX,SERVER1,TCP,0xc004000d FWX_E_POLICY_RULES_DENIED,0x0,11/2/2004 10:10,192.168.XXX.2,80,HTTP,Denied Connection,Default rule,68.126.XXX.XXX,External,Local Host

I just saw something - I'm thinking that incoming requests are hitting .2 instead of .14.  I'm going to redirect to .14 and cross my fingers.  Looks like the default rule (block everything) is killing incoming requests on .2, and sites are published on .14.
0
 
LVL 1

Author Comment

by:toddnoe
ID: 12477961
Alright, got that all figured out...  incoming requests were hitting .2 instead of .14 - made the firewall kick all http traffic to .14.  Also had to create a rule that allowed all external http traffic to certain machines (ASSumed that when you published a site, the rules were already created...).    A couple tweaks here and there...2 of 3 are working now.  Just have to get OWA and ISA to play nice now.

Thanks for your help, thaller.  You got me back on track and pointed in the right direction.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange OWA - failed logins and brute force monitor 7 262
SONICWALL tz100 PASS THROUGHT TO SBS 2 60
suspending the anti virus 6 128
ipsec tunnel comme not up 10 102
If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question