ISA Firewall Lockout, Ceases internet traffic

Posted on 2011-02-10
Medium Priority
Last Modified: 2012-05-11
Hi Experts,

I have an intermitant issue with our firewall that ceases internet traffic. I can RDP into my firewall but cant find anything in the logs.

when I check my External NIC it is not sending or recieving any packets. if I try to disable/enable the nic that doesnt work either.

then I try to restart my ISA services through services mmc but it gets stuck at the windows firewall and takes about 20 mins to stop that service but still after that I cannot enable my nic back. this is the time I need to restart my server and then everything starts running, internet is back.

I understand it wont be an easy fix and some monitoring needs to be done but I need ideas on how to approach this.

it only happens once in 2 weeks to 4 weeks.
Question by:Key2IT
LVL 51

Accepted Solution

Keith Alabaster earned 1200 total points
ID: 34868415
The fact that it is intermittent suggests that it is an underlying OS/hardware issue on the the ISA Server machine rather than an ISA Server application issue. The only time ISA will actually stop traffic completely is if something has triggered an alert regarding TCP connections and you would have seen this in the alerts section if this had been the case.

Is the ISA Server host fully patched up and ISA 2006 SP1 deployed?
Is the host hardware fully updated - bios/firmware/drivers?

What is on the outside of ISA? Router? Another firewall? Anything alerting on that box? Are all conecctions forced to use the correct speed/connection type or are things left to the autonegotiate state?
LVL 12

Assisted Solution

by:Amit Bhatnagar
Amit Bhatnagar earned 800 total points
ID: 34885279
I would agree with Keith. I worked on a similar issues for about 3 weeks before realizing that it was a faulty NIC issue. Is the ISA dropping \Not responding to packets on both interfaces or just one?

Author Comment

ID: 34921419
Sorry guys havnt been able to reply. I'm waiting for it to crash again so I can do some more testing but hasnt dies since 9 days.
will keep you posted.


Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Forefront Threat Management Gateway 2010 or FTMG comes with some very neat troubleshooting tools built-in when trying to identify what is actually happening behind the scenes within the product when traffic is passing through its interfaces. To the …
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
Did you know PowerShell can save you time with SaaS platforms? Simply leverage RESTfulAPIs to build your own PowerShell modules. These will kill repetitive tickets and tabs, using the command Invoke-RestMethod. Tune into this webinar to learn how…

619 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question