Link to home
Start Free TrialLog in
Avatar of Bicesterlad
Bicesterlad

asked on

Forefront TMG Server 2010 Connection Problem

App running through the proxy server is having connection failure problems, only thing logging on TMG is below can anyone help? It doens't seeem to have any failure message just closing the connection? I have left the user name out intentionally.S/W vendor said all ok and I have correct outgoing ports open.

Thanks,
Steve

Software Error Message
The Server is not available - try again later
Connection failure for host 77.86.49.225 port 2009252814 transport TCP (9407) Application server connect failure (5468)

TMG Log
Initiated Connection GHG-TMG-01 14/06/2011 09:00:02
Log type: Firewall service
Status: The operation completed successfully.  
Rule: TEST
Source: Internal (10.1.20.66:1223)
Destination: External (77-86-49-225.rdns.host-it.co.uk 77.86.49.225:50126)
Protocol: Unidentified IP Traffic (TCP:50126)
User:
 Additional information
Number of bytes sent: 0 Number of bytes received: 0
Processing time: 0ms Original Client IP: 10.1.20.66
Client agent: prowc.exe:3:5.1


Closed Connection GHG-TMG-01 14/06/2011 09:00:22
Log type: Firewall service
Status: A connection was gracefully closed in an orderly shutdown process with a three-way FIN-initiated handshake.  
Source: Internal (10.1.20.66:1195)
Destination: Local Host (10.1.10.40:1745)
Protocol: Forefront TMG Client (TCP)
 Additional information
Number of bytes sent: 6208 Number of bytes received: 3855
Processing time: 500000ms Original Client IP: 10.1.20.66

 
Closed Connection GHG-TMG-01 14/06/2011 09:02:36
Log type: Firewall service
Status: A connection was closed because no SYN/ACK reply was received from the server.  
Rule: TEST
Source: Internal (10.1.20.66:1223)
Destination: External (77-86-49-225.rdns.host-it.co.uk 77.86.49.225:50126)
Protocol: Unidentified IP Traffic (TCP:50126)
User:  
 Additional information
Number of bytes sent: 384 Number of bytes received: 0
Processing time: 153484ms Original Client IP: 10.1.20.66
Client agent: prowc.exe:3:5.1

Avatar of Suliman Abu Kharroub
Suliman Abu Kharroub
Flag of Jordan image

Can you test it directly ( without ISA) ?

what if you create a rule to allow all (just for test) protocols from internal to external ? make it in the top and test please
Avatar of Bicesterlad
Bicesterlad

ASKER

working fine through a seperate ADSL line.

Also tried adding a rule allowing all outgoing protocols but still no joy :-(
do you have in the test rule "all authenticated users" or "all users" under users tab ?
all users
ASKER CERTIFIED SOLUTION
Avatar of Bicesterlad
Bicesterlad

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
worked!
Great...

Glad to hear that.
Hi all,

I have the same problem but i can't find where i can change "UDP ports as send, changed to send&receive" that the user Bicesterlad say.

Can you help me
Thanks a lot
Marco
I the protocol properties.

click edit in the selected protocol