Solved

ISA 2006 multiple addresses on external nic unreachable from internet

Posted on 2010-09-19
6
600 Views
Last Modified: 2012-05-10
I have an ISA 2006 server on windows server 2003.

I have an acces rule that allows pings from external to local host (and internal).

I have multiple addresses on the external nic card.

I can ping those multiple address from another computer on the same switch as that external card.

I can only ping the first of those ISA 2006 external addresses from the internet.

Please see attached drawing.

I suspect the FIOS provider is having a problem but they tell me the problem has to be in my ISA server.

I'd really be interested in opinions and suggestions regarding this.

Thanks in advance.

multipleIP.bmp
0
Comment
Question by:gateguard
  • 3
  • 3
6 Comments
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 33714038
Unless told otherwise, ISA listens on ALL external ip addresses for traffic. This means that if you publish an internal web site on port 80, by default, ISA listens on port 80 of ALL external ip addresses.

Open the publishing rule in the gui - when you select the listening nic (normally external) you will see a small tab in the window for addresses. Open this and select ONLY the single ip address you want associated with this listener.

repeat for every publishing rule. If you have done this correctly, you can now have different external ip addresses listening for different (or the same) ports but being pushed to different internal servers.
0
 

Author Comment

by:gateguard
ID: 33714762
Thanks, Keith, for taking a look at this.

Yes, I understand the concept of listeners on specific ports and am quite used to going through the procedure you have just outlined for me.

But in this specific case, I can't even PING the external addresses from the internet and, based on the drawing I have provided in this question, I'm looking for someone to say either yes, Verizon is wrong, they have a problem, or no, I am wrong, I must have some kind of hardware problem on my switch or nic card or something associated with the ISA server.

And for the record, I have changed out both the switch AND the external nic card on the ISA server.

So what do you think?  I can't PING those external address from the internet (though I have an access rule that allows all pings) but I can ping them from a nearby local computer on the external network.

Doesn't the problem HAVE to be in the Verizon equipment coming into my office (or beyond)?

Please tell me if I'm wrong.

Thanks.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 33715364
Not necessarily a fault but a configuration issue on the Verizon by the sound of it. In the ISA GUI - logging - monitoring - start query - do you see the external icmp requests appear in the logs for the different ip addresses?
0
New! My Passport Wireless Pro Wi-Fi Mobile Storage

Portable wireless storage to offload, edit, and stream anywhere.

High-capacity, wireless mobile storage designed to accompany professional photographers and videographers in the field to easily offload, edit and stream captured photos and high-definition videos.

 

Author Comment

by:gateguard
ID: 33716451
No, I don't see those requests appearing.  I don't see the packets appearing with the Ethereal packet sniffer.  I don't have any evidence at all that Verizon is sending any packets addressed to any address except the first in the series.
0
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 500 total points
ID: 33717560
Then that is your evidence. If their configuration/equipment was configured to forward the icmp traffic to the ISA external nic then it would appear in the logs - either as an attack/ wrongly targeted or even allowable traffic but whatever, it would appear
0
 

Author Closing Comment

by:gateguard
ID: 33720761
Thanks a lot, Keith.  I agree with you completely.  It's good to get confirmation from you.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Enterprise networks where VoIP phones have been deployed frequently use port configurations that allow both a computer and an IP phone to be plugged into the same switch port but use different VLANs. On Cisco equipment I'm referring to the "native V…
Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
Delivering innovative fully-managed cloud services for mission-critical applications requires expertise in multiple areas plus vision and commitment. Meet a few of the people behind the quality services of Concerto.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now