Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Scan to shared folder using SMB - ISA 2004

Posted on 2008-10-07
5
Medium Priority
?
1,022 Views
Last Modified: 2010-04-21
Hi all,

I have a client who uses an OCE TDS400 plotter/scanner. The scanning function is configured to use SMB to forward scanned files to a shared folder on a W2K server. The domain controller is a W2K3 SBS with ISA 2004 installed.

This all worked fine until Friday, when I was working with Microsoft Professional Support to try to figure out why Outlook Web Access wouldn't work. As part of the troubleshooting they uninstalled and reinstalled ISA 2004. I expressed concern at the time about the custom rules, but they assured me that they had saved them using the backup function of ISA 2004 and that we'd reimport them. Unfortunately, after reinstalling ISA 2004, they discovered that for some reason they were unable to reimport the saved rules.

So the connection here is that scanning to the shared folder worked fine -- right up to momemnts before we uninstalled ISA 2004. Now the scanning component is unable to connect to the server. Microsft has pretty much washed their hands of it, saying that all internal network communications on the same LAN would be open by default anyway, so it couldn't be ISA 2004.

Bottom line question...is there anything in ISA I need to configure to allow the scanner to save files onto the server?

Thanks in advance for the help.

Tom
0
Comment
Question by:tgreendyk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 22664027
I have never heard of them tacking that tack before. All internal communications are NOT open by default by dint of the fact that this is an SBS server, not a standard windows server implementation. Secondly, the dafault scenario's expect to have authenticated users performing the activities. I don't know much about plotters but I expect it is not logged in an an SBS domain user - maybe you could confirm?

Does the plotter have a fixed Ip address that it uses?
I assume you have reapplied all of the ISA service packs that were applied prior to the config backup being taken? SP3 is the latest.
After you ran the ceicw (after the service packs) what rules has this left in the firewall policy for From internal TO internal? What is the authentication method assigned? All SBS Users? All Users?

Open the isa gui - select monitoring - logging - click start query.
What do yousee in the logs when you try to save a file to the server?

Keith

0
 
LVL 1

Author Comment

by:tgreendyk
ID: 22664149
Keith,

To answer your questions...

The scanner has a dedicated PC in the cabinet under it that acts as a controller, but when it boots up, it takes you right into a proporetary interface without logging on or anything, so I have to also assume that this PC is not authenticating. I don't think it's any different than newer-generation high end scanners other than the controller being a separate PC as opposed to being imbedded in the unit. The scanning configuration screen has a place to enter the IP address of the server, a user and a password, and the path. The user and password are present in Active Directory, so it's using a valid AD login to connect.

Yes, the plotter has a fixed IP address -- again, even though it's a PC, I believe it's really just like any other network printer.

Yes, when they reinstalled ISA, they installed SP3. I should note that prior to them working on it remotely, SP3 was NOT installed. They said it should be and applied it.

The others I'll have to get back to you on tomorrow.

Thanks!

Tom
0
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 1500 total points
ID: 22664224
No probs - it is 11PM here so my bedtime anyway but I can carry on tomorrow after work.
What I would suggest though (as a test) is creating a 'computer' object in the gui - firewall policy and giving it the ip address of the plotter/pc. Create a new firewall access rule - allow 'all outbound' FROM comp_object & local host TO comp_object & local host - all users. put this rule at the top and apply the policy - watch what traffic passes.

Keith
ISA MVP MCT

0
 
LVL 1

Author Closing Comment

by:tgreendyk
ID: 31504019
After talking to the printer manufacturer I realized that the printer was NOT configured to use SMB, but was using FTP -- which was blocked by ISA.

Thanks for the help!
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 22764545
lol - well done :)  (and thanks for the update)
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Small Business Server 2011. NOTE: This guide has been written using the preview version of SBS2011 therefore some of the screens may …
So the following errors occurs in 2 ways that I am aware of at this stage, and you receive one of the following error messages: ERROR 1. When trying to save a rule: No Web listener is specified for the Web publishing rule Autodiscovery Publishin…
Video by: ITPro.TV
In this episode Don builds upon the troubleshooting techniques by demonstrating how to properly monitor a vSphere deployment to detect problems before they occur. He begins the show using tools found within the vSphere suite as ends the show demonst…
In this video, Percona Director of Solution Engineering Jon Tobin discusses the function and features of Percona Server for MongoDB. How Percona can help Percona can help you determine if Percona Server for MongoDB is the right solution for …
Suggested Courses

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question