Adding Routes to ISA 2000

Ok, a new IP range has been added to our network. DHCP and DNS work fine in these computers but the computers with these new IPs (172.16.20x.xxx) cant PING my ISA server which is 172.16.101.xxx (internal). I am new to ISA so I am kind of stumped as of what to do. I added an entry in the LAT table in ISA management but doesnt seem to work. I added them recently, would I have to restart the services?

Thanks in advance.
NaujAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

SaineolaiCommented:
You may need to add a static route to that subnet via the local internal router, if your ISA box has its default gateway pointing to a local external router.

the route add command from a dos prompt will allow you to do this.
Keith AlabasterEnterprise ArchitectCommented:
no, should not have to restart the services. (It should have prompted you when you saved the configuration if this was a requirement).
On the isa box, drop into a cmd windows.
type in
route print
Does this show your new network listed?
Can you ping a client on the new network subnet from the ISA box?

As above, there has to be tcpip connectivity between the ISA and all clients.
NaujAuthor Commented:
When I do a route print the new entries I made in the LAT do not show up.

When I try to ping the client (or its gateway) I get Request Timed Out.

Does ISA 2000 prompt for configuration saving? I thought that was only in 2004.

Thanks again.
Discover the Answer to Productive IT

Discover app within WatchGuard's Wi-Fi Cloud helps you optimize W-Fi user experience with the most complete set of visibility, troubleshooting, and network health features. Quickly pinpointing network problems will lead to more happy users and most importantly, productive IT.

Keith AlabasterEnterprise ArchitectCommented:
No 2000 will ask for a services restart as and when needed. 2004 does the same but in a different way. if you do not have connectivity from the ISA box anyway then adding the subnet to ISA itself will make no difference; the connectivity must be there to start with.

So, if this is a new subnet, how does it get to the ISA (from a networking perspective? What is between the ISA server and this new subnet? As per Saineolai , is there a router/layer3 switch in between?

NaujAuthor Commented:
Ok, there are basically 3 domains (w trust relationships and all that) each with a "core switch" that is connected by fiber to the other domains. The ISA is in my domain (I use the ISA fine and can ping the clients machine that is having problems with the ISA) and the client is in mine too but it has an IP belonging to the other domain (long story short, it had to be connected to a switch that goes to the other domain).

I dont know if all of that is clear but basically I (from my workstation) can ping both the ISA and the client and they can ping me but not each other.
SaineolaiCommented:
Can you post an IPCONFIG from your ISA server and the two PCs you are testing from?

This issue is most likely a routing issue between the ISA server and the PC on the other network segment.

SaineolaiCommented:
If there is an external address in the IPconfig you may want to change the first three octets of the addresses before posting.
Keith AlabasterEnterprise ArchitectCommented:
I agree. This is not an ISA issue from what you are telling us but a more fundamental networking problem. We can help you sort it but I think your problem will be outside of ISA.
Regards
Keith
ISA MCT
NaujAuthor Commented:
My station's IPCONFIG
Windows IP Configuration

Ethernet adapter Local Area Connection:

        Connection-specific DNS Suffix  . : x.local

        IP Address. . . . . . . . . . . . : 172.16.101.125

        Subnet Mask . . . . . . . . . . . : 255.255.255.0

        Default Gateway . . . . . . . . . : 172.16.101.1

ISAs IPCONFIG

Windows IP Configuration

Ethernet adapter External:

 Connection-specific DNS Suffix  . :

   IP Address. . . . . . . . . . . . : xxx.xxx.xxx.145

   Subnet Mask . . . . . . . . . . . : 255.255.255.0

   Default Gateway . . . . . . . . . : xxx.xxx.xxx.1

Ethernet adapter Internal:

Connection-specific DNS Suffix  . :

   IP Address. . . . . . . . . . . . : 172.16.101.123

   Subnet Mask . . . . . . . . . . . : 255.255.255.0

   Default Gateway . . . . . . . . . :

The other stations IPCONFIG I cant get to right now (that office already left for the day) but it should look like:

Windows IP Configuration

Ethernet adapter Local Area Connection:

        Connection-specific DNS Suffix  . : x.local

        IP Address. . . . . . . . . . . . : 172.16.203.xxx

        Subnet Mask . . . . . . . . . . . : 255.255.255.0

        Default Gateway . . . . . . . . . : 172.16.203.1

I really appreciate the help
Keith AlabasterEnterprise ArchitectCommented:
So, how does the 172.16.203.0 network connect to the 172.16.203.0 network?
SaineolaiCommented:
I suggest that you add the following static route on the ISA server to the 172.16.203.0 network via 172.16.101.1

in a command prompt on the ISA server

route add 172.16.203.0 mask 255.255.255.0 172.16.101.1 -p

The -p makes it presist through reboots.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
NaujAuthor Commented:
Im currently out of the office, ill try it when I get back and let you know.

Thanks again.
NaujAuthor Commented:
That worked perfectly Saineolai. The ISA and the users computer can now ping eachother.

I thank you both greatly for the help.
Keith AlabasterEnterprise ArchitectCommented:
Ok, You're welcome anyway
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.