Solved

ISA between VLAN's

Posted on 2008-10-13
3
1,534 Views
Last Modified: 2012-05-05
Hello guys,
I have a weird problem with a certain software (Bloomberg), Bloomberg needs internet connection to pass through, certain ports has to be opened, all of that seems normal, when i try to connect through ISA it never connects and it keeps looking hopelessly for connection.... I have 2 Vlans as follows:

192.168.1.x (lets call it Vlan 1)
192.168.2.x (lets call it Vlan 2)

Isa has 3 NIC's, one connected to Vlan 1, second connected to Vlan 2, Third NIC is for Intra-Array communication...

The Cisco Firewall (my gateway) and all servers (DC's, application servers, exchange, etc..) are connected to Vlan 1
all users are connected to Vlan 2

ISA has an access rule that allows network traffic from internal to External for that user am logging in with, i can access internet freely with no restrictions at all, except this software.....the software requirements is that i should be able to reach some servers like pdir.bloomberg.net, i can't even ping those addresses from Vlan 2 and actually i cannot ping any other name or IP in internet, can resolve names though, i used firewall client and it didn't work too...

Where does the problem occur ?
Why when i tried this software on a pc on VLAN 1 it connected without problems at all ( i had the cisco's IP as my gateway and didnt go through ISA server) ?
Is it ISA or routing between VLAN's?
Shouldn't the ISA pass the traffic from VLAN 2 to VlAN 1 where my gateway is ?

Please assist me with that critical problem since business is depending on that Bloomberg software.
0
Comment
Question by:AMFOP
3 Comments
 
LVL 16

Expert Comment

by:btassure
ID: 22706126
If the ISA server is not doing NAT (and it probably shouldn't be) you will need a route statement in the firewall that points to the second VLAN's subnet via the ISA.
something along the lines of
192.168.2.0 255.255.255.0 {ip of ISA}
My guess is that you can browse OK as ISA will be acting as a proxy server at the moment and is trying to route the rest of the traffic but there is no return route.
0
 
LVL 12

Expert Comment

by:Pugglewuggle
ID: 22708636
That sounds right to me. The only other consideration is that you have some sort of firewall filter on VLAN 2 that's restricting packet flow on certain protocols (you did say DNS lookup works).
Cheers! Let us know!
0
 

Accepted Solution

by:
AMFOP earned 0 total points
ID: 22709080
Ok guys i figured out where the problem was, the software can use a socks5 proxy server and since the ISA 2006 doesn't by default support socks5, i had to google for something and i found that socks5 3rd party tool for ISA 2004/2006:

http://www.securesocks5.com/download.aspx#unregistered_restrictions

Once installed it the Bloomberg software connected directly :))

thanks for your responses guys.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now