Website on SBS with ISA2004 sometimes available and sometimes error code 403: Forbidden

Hi, I just installed ISA 2004 on our SBS server, everything works as it's supposed to be except our website.
I created with help of the "publish website wizard" a rule that publishes our website to the anywhere computer group.

When we test the website from the local network it works fine but when a client tries to connect to it, most of the time
it works but regularly the client gets the 403 error code.

If I log the ISA Server I get the following entries:

Action                        Client ip            username    source network  destination    http method   url                                                               destination ip     port

denied connection     81.82.197.24      anonymous      localhost          empty              GET     http://sbs/website/images/contact_3.jpg             81.82.197.24    80
Allowed connection   81.82.248.149    anonymous        external          empty              GET    http://sbs/website/images/contact_3.jpg              81.82.197.24   80


81.82.197.24 is the servers WAN ip.

This is what the ISA Server logs, it is very strange that ISA blocks the request with client ip it's own WAN ip because the rule made by the wizard has in the from field "anywhere".

This is what appears when I visit the webste from a remote location with WAN ip 81.82.248.149.
It is strange that in client IP the wan address  81.82.197.24 of the sbs server appears.
This is an urgent matter since the website is our live website.

Any help would be more than welcome.
techneitsolutionsAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Keith AlabasterEnterprise ArchitectCommented:
Couple of things.

Firstly, the screenshots you have posted are from your internal web pages so we will not be able to see them.
Second, by putting an allow list into place on the incoming connections to your web site you are potentially blocking the local host (the ISA server itself) from connecting. The Anywhere group is a built-in group that by definition means it has no restrictions.....

If you want to place a block like this, create a new group from within the publishing rule and add the IP's that you want but include the IP address of the ISA/SBS server's external NIC.
If you have done all of this already let me know, else Job Done!

Regards
keith
ISA MCT
0
Keith AlabasterEnterprise ArchitectCommented:
PS.
Have you got 2 NIC's in your server or just the one?
If two, when you published the rule, did you put the internal nic IP address of the SBS serveras the destination?
0
techneitsolutionsAuthor Commented:
Hi keith,

You're able to see the the images since most of the times it works fine. In the rule made by the "publish a web server" wizard the server translates external paths to internal paths. The translation is done by Host headers

Host headersBy

default, when Microsoft Internet Security and Acceleration (ISA) Server 2004 receives an incoming Web request, it determines whether the request is allowed, and then routes the request to the appropriate location on the Web server as defined in the Web publishing rule. ISA Server does not pass the host header (for example, Host: example.microsoft.com) included in the client request to the published server. Instead, ISA Server substitutes the original host header in the request with the name of the server specified in the Web publishing rule. As a result, all requests that are routed to a particular Web server are sent to the same (default) Web site on that Web server.

You can configure ISA Server to pass the original host header information, thereby allowing client requests to be routed to a particular site on the Web server. For example, when you are publishing more than one Web site on the same Web server, the original host header is required for the request to be routed to the intended Web site.

This is the live ip 81.82.197.46 of the server hope this helps

And yes we use 2 NIC's and no I didn't use the internal ip address as destination.

Greetings,

Walter
0
Introducing the "443 Security Simplified" Podcast

This new podcast puts you inside the minds of leading white-hat hackers and security researchers. Hosts Marc Laliberte and Corey Nachreiner turn complex security concepts into easily understood and actionable insights on the latest cyber security headlines and trends.

techneitsolutionsAuthor Commented:
Problem Solved !

There's apparently a problem with DNS.
If I use the internal ip-address fot the publish a webserver wizard everything works fine.

Thx for the help.

Now how can I close this question?

0
Keith AlabasterEnterprise ArchitectCommented:
As above  <<<If two, when you published the rule, did you put the internal nic IP address of the SBS server as the destination?>>

You MUST publish with the internal IP address
However....

http://www.experts-exchange.com/help.jsp#hs5

0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
techneitsolutionsAuthor Commented:
We used the internal name and not the ip-address that was the problem.
Apparently a previous administrator created a wrong reverse dns record and that caused some errors when the server
tried to resolve the path.

If my thinking is correct.

Thx anyway.

Grtz,

Walter
0
Keith AlabasterEnterprise ArchitectCommented:
Thanks :)
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.