Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


Access website through ISA 2004

Posted on 2009-07-14
Medium Priority
Last Modified: 2013-11-16
Hi I have a weird issue with one web site and ISA 2004.

Web browsing works without faults until someone tries to access http://www.norfolkline.com/ or any of its registered domains.  Instantly we receive a standard 403 error below:

          Error Code: 403 Forbidden. The server denied the specified
          Uniform Resource Locator (URL). Contact the server administrator. (12202)

I have monitored ISA and can see the requests for the website and they do not get blocked.  The Packets I see are:

   Initiated Connection
   Log type: Firewall service
   Status: The operation completed successfully.
   Source: Local Host (
   Destination: External (

   Allowed Connection
   Log type: Web Proxy (Forward)
   Status: 403 Forbidden
   Rule: Allow all HTTP traffic from ISA Server to all networks (for CRL downloads)
   Source: Local Host (
   Destination: External (
   Request: GET http://www.norfolkline.com/ferry/
   Filter information: Req ID: 1da11fff

   Closed Connection
   Log type: Firewall service
   Status: A connection was gracefully closed in an orderly shutdown process with a
                three-way FIN-initiated handshake.
   Source: Local Host (
   Destination: External (

I can see that ISA shows 403 Forbidden on the allowed connection but i am not sure why. It isnt an issue with the web site as it works from other sites and ISPs.

Does anyone have any ideas why ISA would be doing this?

Thanks in advance

Question by:Supportteam
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
LVL 21

Expert Comment

by:Hendrik Wiese
ID: 24848486

Have a look at your rule called: "Allow all HTTP traffic from ISA Server to all networks (for CRL downloads)", as looks like it gets the 403 Forbidden from this rule, you could try to delete this rule and set it up from scratch.

Expert Comment

ID: 24848572

Look here: http://forums.isaserver.org/m_2001999787/mpage_1/key_/tm.htm#2001999787

Seems you'll need to consider making the internal computers Web Proxy Clients instead of relying on NAT.

Author Comment

ID: 24849193
Hi All,
Cheers for the quick responses, I am unable to do anything with the "Allow all HTTP traffic from ISA Server to all networks (for CRL downloads)" policy as its a system policy.  Though I have disabled it to see what happens at which time final policy "SBS Internet Access Rule" (yes its an SBS 2003 Server) stopped the packet with the same 403 error.
As for the webproxy comment all of the clients are using the latest ISA Firewall Client and the web site is external of our network and its not using any ssl on the home page.
Any other ideas guys?

Accepted Solution

Supportteam earned 0 total points
ID: 24877328
Hi All,
After more investigation we have found that the company hosting www.norfolkline.com use an ISA server and its actually their ISA server that is blocking our access not ours.
Thanks for the help.

Featured Post

Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Have you ever tried to find someone you know on Facebook and searched to find more than one result with the same picture? Perhaps someone you know has told you that they have a 'facebook stalker' or someone who is 'posing as them' online and ta…
I recently had to create a utility which aim is to update McAfee's Virusscan and that had to be launched from a command line. I thought I’d share my experience with you. Why is it useful to be able to update an Antivirus from the command line?…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question