?
Solved

ISA 2006 keep asking user name/password

Posted on 2012-03-10
9
Medium Priority
?
1,032 Views
Last Modified: 2012-04-14
Hi All
I have windows 2008 domain and there is a windows 2003 R2 server Ent. member server in which isa server 2006 is installed.
My ISA2006 is not at the backend on my network, it is behind a Hardware firewall. and I have one network card in ISA server.
Even though i was created access rules for particular domain users by browsing in the active directory , but now user cannot access internet.
they are getting a login screen always and it is not authenticating even if the user supplies the correct credentials.

it was work fine before few weeks a go and now in the ISA i'm not able to see my local domain when i'm trying to add new user's in to access rule it's showing ISA server computer only in the location

I restart the ISA Server, then working fine for another some time then I shuld restrat it again?

please I need help to resolve this problem
untitled2.JPG
untitled.JPG
0
Comment
Question by:AymanOZ
  • 3
  • 3
  • 3
9 Comments
 
LVL 41

Expert Comment

by:als315
ID: 37706170
Try to check blocked connections in monitoring. It looks like DNS problem. Try to resolve domain controller during this lock, check access to proper DNS server.
0
 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 37706246
Try to dis-join  and rejoin the ISA to domain.
0
 

Author Comment

by:AymanOZ
ID: 37706427
Dear als315
I just Reed more in intenet ...

they ask me to add in host file

172.16.1.1           DNS1.domain.com         DNS1
172.16.1.2           DNS2.domain.com         DNS2

i will try it and come back to you

Dear Sulimanw
I try last week to
dis-join  and rejoin then reinstull ISA
0
Easily Design & Build Your Next Website

Squarespace’s all-in-one platform gives you everything you need to express yourself creatively online, whether it is with a domain, website, or online store. Get started with your free trial today, and when ready, take 10% off your first purchase with offer code 'EXPERTS'.

 
LVL 41

Expert Comment

by:als315
ID: 37706603
What DNS is in your network card's settings? Have you internal DNS server in ISA computer? Have you any VPN connections to this ISA server?
0
 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 37706629
make sure that the external NIc does not point to any external DNS servers.
0
 

Author Comment

by:AymanOZ
ID: 37706704
My domain local DNS IP address is
172.16.1.1
172.16.1.2
My ISP DNS is
202.93.39.4
202.93.39.5

ISA Server is only Server with ISA Software, I did not add any other serves in ISA like DNS or fileserver or anything
I don’t have VPN connected to ISA server.

I have only one NIC in ISA server
configured like this
IP:   172.16.1.4
SM:  255.255.0.0
GW: 172.16.1.254
DNS1: 172.16.1.1
DNS2: 202.93.39.4

If I remove external DNS from ISA Server, I cannot get Internet :(
If I remove Internal DNS I cannot get Username and domain :((
0
 
LVL 41

Assisted Solution

by:als315
als315 earned 1000 total points
ID: 37706740
Remove ISP's DNS from list, add your second DNS. Your internal DNSs should have forwarders to ISP's DNSs
Mask is 255.255.0.0 - you have so many computers in your network?
0
 
LVL 23

Accepted Solution

by:
Suliman Abu Kharroub earned 1000 total points
ID: 37706747
Remove the 202.x.x.x from the dns ip list in the internal adapter.

create a rule to allow dns traffic from your internal dns server to the external network. last thing add the 202.x.x..x dns into the forwarders list in your internal dns server.
0
 

Author Comment

by:AymanOZ
ID: 37708918
OK ,
I Add this in DNS1,DNS2
202.x.x.x you can see the attachment
I will remove external DNS IP in NIC in ISA Server After 6:00 PM only
untitled.PNG
0

Featured Post

The 14th Annual Expert Award Winners

The results are in! Meet the top members of our 2017 Expert Awards. Congratulations to all who qualified!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

This installment of Make It Better gives Media Temple customers the latest news, plugins, and tutorials to make their VPS hosting experience that much smoother.
There are a few different ways to preview your site before DNS resolves it to your (mt) Media Temple server.  The Plesk platform makes it easy.  See the following guide to learn how.
The video will let you know the exact process to import OST/PST files to the cloud based Office 365 mailboxes. Using Kernel Import PST to Office 365 tool, one can quickly import numerous OST/PST files to Office 365. Besides this, the tool also comes…
Through the video, you can check the migration process of Outlook PST file to PDF. Kernel for Outlook to PDF tool can convert Outlook emails with all attributes like Subject, To, From, Cc, Bcc and other folders such as Inbox, Outbox, Sent Items, Jun…

589 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question